Skip to content
DnsLister Forum

Where domain hunters compare notes

Important security tips for web hosting beginners

I have been in the web hosting industry for more than 10 years and have dealt with a lot of different issues. Some absolutely important ones are what many people miss and I hope this helps at least some of you.

1) If you are planning to purchase a new domain and host it, always create a free cloudflare account and add the domain name to cloudflare, keep the proxy (orange cloud) enabled by default. Even if you have not purchased the domain yet, cloudflare still allows you to add a new domain. Once added and proxy enabled, update your nameservers to point to cloudflare directly.

This way, when you update the dns records to point for your server, your actual server IP becomes private/hidden from day 1 and the no of bot/spam traffic coming to your site will be significantly reduced.

Some bots directly access your site using your server IP by checking for historical dns entries and try to perform attacks and such instances will be reduced significantly.

There are still other ways a determined attacker can get your server IP from your mx or spf record but most spammy bots do not go to that extent, so the attack surface is very low.

2) Always use cloudflare and its cdn/proxy from day one when your site goes online. This way, cf can learn about the incoming traffic and block malicious and spammy bots regularly. This would prevent you from enabling their under attack mode when an actual ddos attack happens on your site in the future.

3) never rely completely on server side backups even if you are paying more money for a better server. Sometimes even if there is no fault from the hosting provider, the backup/restore softwares they use can sometimes act up and your data may not be backed up successfully all the time. Always take your own backups regularly and store it safely in your pc or an external hard drive/google cloud etc.

4) If you accidentally deleted some dns records, you can almost always find the historical dns entries for your domain in sites like security trails, dnshistory dot org etc. just search google for "historical dns check" and you'll see many sites who had scraped your dns records in the past. This is one way an attacker can get your IP as explained in step 1.

5) For better email deliverability of emails from your site's contact forms/e-commerce order related email notifications to your customers, always use a proper SMTP service instead of using the default php mailer as most receiving email servers reject or mark those emails as spam if the sender doesn't use SMTP.

6) if your site's data and its backup is completely deleted, most of the times you can find snapshots of your site at archive.org. You can refer to different snapshots and rebuild your site. Even though this is a tedious task, you will start with at least something instead of nothing. This is why regular offline backups are important (read step 3).

7) Always keep your site's plugins, themes, scripts updated to support their latest versions. Site compromises almost always happens due to an attacker finding vulnerabilities on outdated softwares.

8) Don't install nulled/cracked plugins from sites offering them for a very cheap price. You never know what's hidden in them and many times, they are the root causes of site compromises. If you cannot afford to pay for premium plugins or themes, ask claude to help you build your own plugin and theme specifically designed for your site and ask it to make it as secure as possible to prevent from any attacks.

Build this plugin or theme in a seperate project and regularly ask claude to check for any vulnerabilities based on latest news and ask it to keep updating them and then install the updated version to your site.

Cheers!

submitted by /u/Safe_Mission_3524 to r/cpanel
[link] [comments]

Source: r/cpanel · by /u/Safe_Mission_3524

Leave a Reply

Your email address will not be published. Required fields are marked *