Knowledge base
1000 FAQs, 500 tutorials and instructional videos. Here, there are only solutions!
Avoid website hacking
This guide explains how to prevent cyber attacks and how to avoid a website hack for the website you manage.
WordPress Users: refer to this dedicated article.
The role of the host
Infomaniak's job is to provide quality hosting, so it is crucial to respond extremely quickly to the various attacks that any Internet actor may be subject to. Infomaniak therefore does everything possible to take the maximum precautions against hacking, notably by keeping the different versions of the technologies used up to date.
In the event of a proven hack, if it is possible to trace back to the author and the machine has been compromised due to a security flaw on Infomaniak's part, if the integrity of the servers is at stake, Infomaniak takes matters into its own hands.
The role of the site owner and the webmaster
If the hacking of your site is your responsibility (an outdated script, a security patch that has not been applied, etc.), Infomaniak contacts you to warn you of a problem that will need to be resolved quickly. Certain organizations such as Saferinternet may also suspend the domain name upstream, which will deactivate the site as well as the messaging.
Infomaniak cannot counter exploits related to a bug in your PHP code or other. If the hacking is not detected, you will generally notice the intrusion quite quickly through suspicious elements in your pages or by receiving numerous error emails.
It is therefore your responsibility to take care of the evolution of your website over time and not to let it "die" in a corner, even if it means calling on a webmaster whose job it is.
Infomaniak's recommendations
- Regularly update all your web applications (WordPress, Joomla, Drupal, ownCloud, etc.).
- Keep the PHP version of your site on Infomaniak's servers up to date.
- Keep your site up to date by migrating to new offers when they are proposed to you.
- Add a protection system on your contact forms (captcha, etc.) and on any "recommend to a friend" tools (tell-a-friend...).
- Regularly run an antivirus analysis of the hosting.
- Monitor the vulnerability detection tool.
- Remove anything you have not developed yourself and for which the author has not provided an update/correction for several months.
- Make a regular backup of your site (refer to this other guide if you use WordPress) when everything is fine and keep it in a safe place (since automatic backups are only kept for a few days and this is sometimes not far enough back to go back after you notice an intrusion).
- Consult ibarry.ch.
If a problem has occurred...
- Change the passwords of your Web applications, your FTP accounts and your databases by first checking that no virus is on your computer.
- Restore a backup but update immediately everything that can be updated as soon as the restoration is complete.
- If necessary, local partners referenced by Infomaniak can handle these procedures: launch a free call for tenders; they take care of everything, freeing you from technical details — also discover the role of the host.
Be aware of these additional recommendations!
Link to this FAQ:
Has this FAQ been helpful?