More Virtual Promote ... Search Engine Forums · Webmasters Toolkit · Free Website Templates · Scumware.com
.
Virtual Promote Gazette Home Subscribe/Unsubscribe Archives  
.

gazette



Issue # 201 (07/21/2003)

Net Economics & Ethics

Looking inward at the effects of the Internet on the Economy, as well as tackling some issues related to security, fraud, theft, and generally "being bad" online...

Hosting Hotsheet
Your secure site

Maintaining a secure web site requires a team effort between you and your web host. Each has their role and must maintain vigilance to ensure that your site is available and your customers can safely visit.

First of all, your web host should maintain a firewall or packet filtering system to prevent unwanted connections to your web site. Only connections that are necessary toward the functionality of your site should be permitted to access your web server. This is analogous to traffic that may flow into a room. Packet filtering technology basically keeps the windows in your room locked so that visitors can only access your room through the doorway. Your web host must also keep their system software up-to-date. The same way that you need to keep your home computer up to date with security patches, your web host must remain aware of security holes and risks as software updates are released to fix them. A good web host will also have regularly scheduled maintenance periods to install these updates with minimal impact to your site availability and performance.

Your responsibilities to keep your site secure and safe are no less challenging. Your web site may run scripts that perform functionality vital to your site. These scripts can include such things as recording visitor information from a form submission or requesting information from a database. Unfortunately these scripts can also provide a way for hackers to illegally access your site or steal private information. Use the same caution when downloading scripts that you use to download software to your computer. It is recommended that you the time to review the scripts to make sure they are safe. If you write your own scripts, have a peer review them to make sure that they are secure. When you require your visitors to submit data on your site, make sure that the data fields are "bounds checked." This is the practice of ensuring that data fields, such as a phone number, can only be numbers or a street address field is limited to 30 characters in length. By checking these data fields, you can help prevent improper data from crashing your script and allowing unwarranted access to your site. Check out this site, http://www.w3.org/Security/Faq/wwwsf4.html, for some good information on how to secure your scripts.

If you maintain sensitive data on your web site, you must protect it. Ensure that access to this information is password protected and that the passwords used are difficult to guess. Require a combination of numbers and letters at least six characters long. Do not create protected areas with general passwords that are given to multiple users. Set up unique passwords for each user. It is also good practice to remove data from your web site when it is no longer needed. If your site has an order form, make sure that once an order is placed, the credit card information is no longer stored on your web server. Move that information to a non-public system if it is necessary to retain. When moving data from your web site, be sure to use a secure protocol, such as SSH, which encrypts the while it is being moved from one machine to another. FTP does not encrypt data. If it is necessary to keep sensitive data on your web site, you should also encrypt that data and decrypt it only when it is needed.

At SimpleNet, we've created an architecture and data center that provide you with the cleanest, most protected and effective path to your web site. Couple that with our incredible products and you'll find that your site uses the same infrastructure and scalability of the big sites, but at a much more affordable cost. No other host can provide this same level of service! And, since we've recently re-launched our shared hosting service, now is the time to see what SimpleNet can do for you. Please visit, http://www.simplenet.com/jimworld.html


Read the Hosting Hotsheet section from the Last Issue or in the Following Issue


JimWorld Member comments and feedback ...

Posted On: 04/19/2006 04:35
Posted By: alfie1848
Thank you for your review, I will benefit from your suggestions. I have one
question though. You said "In the source, you really need a meta description
for each page just as you do with any web site." How do I do this with blogger?

Posted On: 04/19/2006 04:43
Posted By: alfie1848
Thank you for your review, I will benefit from your suggestions. I have one
question though. You said "In the source, you really need a meta description
for each page just as you do with any web site." How do I do this with blogger?

Posted On: 04/19/2006 04:57
Posted By: alfie1848
Thank you for your review, I will benefit from your suggestions. I have one
question though. You said "In the source, you really need a meta description
for each page just as you do with any web site." How do I do this with blogger?

Posted On: 04/19/2006 04:10
Posted By: alfie1848
Thank you for your review, I will benefit from your suggestions. I have one
question though. You said "In the source, you really need a meta description
for each page just as you do with any web site." How do I do this with blogger?

Posted On: 01/04/2008 08:04
Posted By: boltonuv
This "Scumbag of the Week" article is irresponsible. I had not trouble at all in receiving the following response from SpamArrest:

"Hi James,

Thank you for your email.

James, what you see there is absolutely wrong and is done to misguide our users and our new customers from Spam Arrest. We have over 1.5 million customers with us including you. You have been with us for a very long time, James. You can check with any of your contacts whether they have received any junk emails from us. We never do such a thing and its completely against our ethics! We hate spam as much as you do and so, along with stopping it, we make sure that none of our customer's emails are noted as spam. We warn our customers from sending bulk emails about the fact that their contacts might misunderstand their bulk emails as spam and will turn against them and Spam Arrest. A company following only such healthy practices can never do such a thing like spamming. What we value the most is our customer's trust and we will make all efforts to retain that in the best way possible. We never admit your personal information to any third party under whatsoever circumstances. You will find a whole lot of misleading things like this in Internet, James. We have friends and foes like anyone else in this planet.

I hope you will understand us the best way possible, James. Please do let me know if you need any further clarifications regarding this.

Best Regards,
Peter
Technical Support Specialist
Spam Arrest"

In the 3 years that I have used SpamArrest, I personally have never received one complaint from anyone that has been 'spammed' from any theoretical 'spam list' that SpamArrest may have created. I think that their statement above makes it clear that they would not do this.

I behooves you to publish a retraction.

Jim Bolton

Add your own comment ....

We accept comments to Gazette Articles only by registered JimWorld.com members. If you are not yet a member, please join now. Membership is free, and entitles you to not only post comments here, but also to participate in our discussion forums, as well as other areas of the JimWorld.com network.

If you are currently a JimWorld member, your userid and password will allow you to login with the form below.

Login
Forget your password?
Password

 

 

Sponsored Links

Search for a Free Domain
The Virtual Promote Toolkit is hosted by the experts at SimpleNet. You should be, too! Whether building a new site or transferring one, there is no other hosting platform comparable to SimpleNet’s; hosting for less than $5/month.
Search for the following tlds: .com, .net, .org, .info, .biz, & .us
Already have a domain or site? Move it to SimpleNet


Hyperseek Search Engine
Member Spotlight
Buy and Sell Text Links
No fees to the buyer or seller. Sites is genuinely 100% free. Increase tha (bsl)
spacer

 

 

   

© 1995 - 2004  ·  iWeb, Inc DBA JimWorld Productions