Category: WordPress Security

  • 10 Best WordPress SECURITY plugins review

    Want to know the best WordPress security plugins to protect your site?

    Read on because I’ve done a review on them and tested their most important features. I’ve had some client sites get hacked recently and simply didn’t have the time to thoroughly compare files so I fired up the usual security plugins and was surprised by what I found. Some were designed quite intuitively and extremely helpful whereas others were IMO a collection of garbage of common htaccess tweaks.

    Let’s cover their differences…

    What features are most important in a WordPress security plugin?

    I generally don’t bother with WordPress security plugins (having previously complained that security plugins “sucked”) but will admit their convenience for quickly detecting issues and guessing where the rest of the dirt might be. They do have useful functions for others if not even for myself.

    The MOST IMPORTANT security function to me is SCANNING (blocking malware, code injection, backdoors, file changes). The typical malware hacks where your website files and code is changed. Those are the most common website defacements that immediately affect your website appearance. Malware scanning is absolutely the most important security function in a plugin because it’s so much more efficient than manually scanning with your own eyes and comparing files for changes. With that said, scanners are very helpful but not 100% perfect. You may still have to manually check access logs and scrutinize entire directories (and subdirectories) to make sure you get everything out.

    The SECOND MOST IMPORTANT security function to me is FIREWALL (blocking entry attacks, flooding, brute force). Brute-force into login pages, XML-RPC spam, DDOS (levels 3, 4, 7), or constant flooding into other services and ports and what not. The problem with these attacks is that while they often don’t get into your site, they quickly overwhelm your server with requests and take it down or cause outtage to actual users. So in a way, firewall scans are more a performance more than anything. They prevent hackers not only from getting in but also from taking down your server. The reason why it isn’t the most important function is that it should be done from the server already

    The THIRD MOST IMPORTANT security function are the CHECKLISTS (file permissions, pass strength, login page). These are what I call the ‘common-sense checklists’. I hate to see these in plugins for the most part. Most of them are nothing more than little lines of code put into htaccess that you could do on your own without a plugin. Sure, it’s great for newbies but annoying when you’re a tech-savvy user and just want a plugin for scanning protection and maybe firewall protection. Nonetheless, they are still helpful from time to time when you have a hacked site and don’t know where to begin.

    Different categories of WordPress security plugins:

    • FULL FEATURED plugins – these have everything (scanning, firewall, and checklists). Basically, everything is built-in. Of course, some features may be locked into their paid version. Like maybe they can scan and tell you which files are affected but they won’t clean it unless you pay. Or maybe they’ll only allow manual scans in the free version, and scheduled scans are only be allowed in the paid version.
    • SCANNING & FIREWALL plugins – these do only scanning & firewall. IMO, this is all you really need if you know what you’re doing. They’re just there for hack prevention and also to provide a convenient log of where your attacks are coming from so you can beef up your server security. They can also be used for the occasional clean-up. Some plugins may even be only scanning or only firewall. There are also plugins that do only one aspect of the firewall like maybe disabling only XML-RPC or only disabling bot traffic. Etc.
    • CHECKLIST plugins – these provide a list of basic security tweaks you should do for your site. Some are more helpful than others. Some try to over-inflate the importance of certain aspects. And I really hate when checklist plugins masquerade as “security scanners” when they actually aren’t scanning for malware.

    Additional notes:

    • Many plugins claim to have a “scanner” but they don’t actually scan your files for malware. They simply scan for basic security stuff…like a “checklist scanner”.
    • Many scanners will falsely detect other security plugins as potential security issues. Hahaha.
    • Many security plugins are not worth the price.
    • You can STILL get hacked even if you do have a security plugin installed.

    Best WordPress security plugins

    1. Wordfence Security – Firewall & Malware Scan (FREE & PAID)

    If you’ve been hacked or trying to prevent getting hacked, WordFence is easily my #1 pick. It has a good range of functions to help secure your site against the 2 most common and most devastating hacks (brute force & code injections). All the other million security features are just a bonus.

    The malware scanner is full-functioning, intuitive as hell, and so helpful in comparing code differences and letting you repair them easily from their interface. It is by far the most helpful scanner out there. I’m willing to bet it’s even better than their competitors’ paid versions. The firewall features are comprehensive enough and can block a wide range of attacks.

    You know why I think this plugin is so good? It’s because it’s used by many people so they probably have the largest collection of hack signatures and what not. This is probably your best bet against zero-day attacks. I also like the cool email function letting you know about admin login attempts.

    The UI could be designed a little cleaner and not look so much like a busy travel booking site, or with such constant upsells for their (paid) PRO version. I also hear some people complaining that it uses more server resources. I’m pretty sure you can configure this in the settings to be less resource-hungry.

    2. Cerber Security, Antispam & Malware Scan (FREE & PAID)

    In places where WordFence failed to detect hacks or was hacked itself. My very next go-to plugin was Cerber Security. I heard raving reviews about these guys when they first released their Appsumo deal and now I see why. A very clean and unstyled interface that is friendly for admins, although may appear less friendly for users. I love that you can see many options without having to scroll. I love the helpful guides explaining why each optimization is important and additional tips for newbie users to read.

    Their malware scan is #2 in my book (although I never tried all the paid scanning services out there). The firewall and checklist features are descriptive enough without taking over my screen. Really great UI, really. I don’t think I could have designed a better UI for a security plugin, myself.

    3. Sucuri Security (PAID)

    The best 3rd-party interface plugin. Usually, I hate it when plugins take over the WordPress site design with their own colors and styling…making it feel like another website within your website. But Sucuri does it well. It totally makes you feel like a premium security service is protecting your site.

    I love that they focus on 2 things…SCANNING and FIREWALL. They don’t waste your time with the silly ‘common-sense checklists’ (have a good password, file permissions, etc). This plugin is good if you’re a responsible tech-savvy user who only needs scanning and a firewall.

    My only issue is that I think their automated scanning is probably still not as good as WordFence. Their firewall, however, should be better since it goes through their proxy. The issue is that their firewall isn’t free. You have to pay.

    I think their plugin is great if you get their paid service and use their human-assisted cleanup services ($200/year is pretty cheap compared to paying a developer to clean up your hacked mess several times). Otherwise, I think their standalone plugin isn’t much help. I do like that it’s simple and doesn’t nag you too hard to pay up. Enter an API key and you’re good to go!

    4. Single-function plugins

    If you know exactly what you’re doing, I’m a big fan of those security plugins that only do one thing. Like as only changing the WP-admin login URL, blocking certain bots, or blocking certain protocols. These plugins are great because they allow you to have exactly the security functions you really need/want and not overlap with security mechanisms already implemented by other plugins or by your web server.

    WordPress security plugins (I didn’t like)

    1. SecuPress

    really great design. reminds me of WP Rocket with the super sexy-simplified interface that lays out many options in a friendly way. Unfortunately, the malware scanner is locked off behind a paid service which means the free version offers very little beyond simple protection rules in htaccess. For all I know this plugin might not be all that good but I give it some benefit of the doubt.

    2. Defender

    Why do I bother? (It’s WPMU.) Hahahah. ok. let’s be fair. WPMU is not known for good themes/plugins/service but I gave this plugin a try. It’s designed well and looks user-friendly. but has the similar issue as many other free security plugins, the most important features are castrated from the free version. so no malware scanner unless you pay. sorry, no thanks.

    3. All-in-One Security

    Malware scan requires offsite signup. Ugh, no thanks. All the other security features like blocking specific traffic were great. Ultimately, I just felt this plugin felt kinda outdated. I didn’t like the styling. The ribbons in the UI look so early 2000’s “web 2.0”.

    4. iThemes Security

    I don’t know this plugin ever gets raving reviews. It’s too bad because I did like their UI. I liked the one simple page where you could see all the options to enable or not. The sad part is that if you know what you’re doing, you’ll quickly realize many of these “security features” are simple htaccess rules, nothing more. Then again, maybe it’s unfair of me to say that since newbie users do find tremendous value in it and it’s great that they aren’t over-cluttering their plugin.

    5. MalCare Security (FREE & PAID)

    Many people love this one but I wasn’t such a fan. Don’t like the UI taking over my screen and looking completely non-WordPress. The first-time setup was quite slow. It advertises quick scanning but was slower than other top plugins. I do like that it advertises not overloading your server.

    I find it amusing when a malware-scanning plugin itself looks and functions like malware. Even their website feels like malware as well. Something between an unfinished website and an advertisement. Kind of like those parked domains that you visit by accident when misspelling a website URL. Also looks like those damn CNET download pages where you couldn’t tell which download button was real or an ad.

    Oh look, the scanner finished and didn’t find any of the ones that WordFence found. I totally get the allure of a simple set-and-forget security plugin that promises low server resource usage but this is not a good one. Having no options is almost the same as having no features, IMO. There’s simplicity and then there’s just blindly trusting a plugin to work exactly how you want it to work.

    Then there was another site that was hacked (I already found it via scanning system processes from the server and what not but decided to test Malcare on it). Malcare DID find the hack BUT put a red button that said “AUTO CLEAN”. I click on it and it wants me to “upgrade” to a paid plan in order to clean the malware. Just for the heck of it, I click UPGRADE and then hit an error page that said “error, report this” and also other option that I forgot. I click to go back and sure it enough, it won’t even tell you where the hack is so you can clean it off yourself.

    So basically…this thing is like one of those free software you find online that looks like it’s fully functional but then asks for money before running its critical function. I’m just fed up, I feel tricked and don’t even see the point of this plugin. They might as well just be upfront and tell you that it only scans but doesn’t remove any malware unless you pay. Ok…I put Wordfence on and sure enough it finds it.

    6. WebARX – Web Application Security

    Heard some good reviews about this one but didn’t bother to try since they only have a paid version. Luckily enough, a generous reader gave me his account access and I got to try it for myself. The UI and overall design is really nice. Feels premium, feels like you’re really protecting your site with state-of-the-art security.

    The actual experience and overall protection of the plugin was something else. The UI and settings were really nice. Options and settings were laid out comprehensively and explained well with helpful descriptions. But those settings only covered the firewall and typical checklist security features. The malware scanner (OR LACK OF) was a totally different experience. There is no malware scanner?!

    I don’t even get how they make any money at all as a PREMIUM-only plugin. There is no free version and yet the paid version itself feels like trial software. So what the heck are we paying for? You’re paying for a firewall, nice user interface, and fancy report charts that show what attacks are being blocked by their firewall. Sorry but this plugin gets a total thumbs down from me. Totally overrated and incomplete as a security plugin. If all you wanted was a fancy firewall plugin, this is it…but then again, the best firewall is probably best done from your server (protecting the entire server instead of only one site).

    7. Security Ninja

    I’m a little torn. On one hand, the functions and features were laid out in a simple organized manner. On the other hand, the UI made you feel like this plugin wasn’t so native with WordPress. The interface seemed to link out to their website incessantly. 80% of the things you clicked on lead out to their website where you guessed it…and upsell to their PAID VERSION!

    The plugin was simple enough but seemed like you had to pay for anything to really work. Sorry, no thanks! This isn’t even trialware or adware. It’s just a catalog plugin of their security features. Hahaha. With that said, the scan is nice if you want to see a quick checklist of which common sense things to fix on your site.

    8. Bulletproof Security

    Cool name but I’m not a fan. Really clumsy outdated UI right off the bat. Seriously, the UI is a MAJOR turnoff. They make even basic functions look super complicated. The “features” layout is so confusing and unorganized. And why the heck am I seeing CSS styling options throughout security settings? Oh and the scan didn’t find anything whereas other plugins did.

    9. VaultPress

    Worthless and annoying. 2 big flags for me. One is that it requires JETPACK…uggh, stop forcing that on us! The other disqualifier is that it’s a PAID plugin. So you’re gonna make me PAY to use Jetpack?! Sorry, but no. I didn’t continue any further. I also saw bad reviews of it not being able to detect hacks. Why am I not surprised?! I simply don’t like/trust those Automattic guys.

    So basically…it’s built by Automattic/Jetpack and requires a paid subscription to do anything. As with many things by those guys, there’s complaints about it being slow, not working well, and not worth the price they’re demanding. I didn’t bother to pay or try it out at all. Nope, not when they got that reputation.

  • WordPress security plugins SUCK!

    Do you really need a WordPress security plugin?

    My personal opinion? Yes and no. Most of them suck. Most of their features suck.

    • They slow down your site.
    • They can’t secure/detect everything.
    • They cost money.
    • They give a false sense of security (BIGGEST OFFENSE).
    • (I’ll also cover which features DON’T suck.)

    Don’t worry, I’ll explain.

    Introduction to WordPress security

    To talk about WordPress security, you have to understand what you’re actually securing your site from! Attacks come in various forms and with different motives behind them. And the attacks target different aspects of your site. Without understanding this, you’ll never know how to secure your website. At best, you’ll be a paranoid web-owner installing every random security option without knowing if it has any impact against what you’re trying to secure!

    I could make a full-blown WordPress security guide later, but not today!

    Common WordPress attacks (and how they work)

    Brute-force

    • Bot trying rapidly trying different passwords on your login page (usually WP-admin).
    • They are a problem even if they can’t get in since their constant effort still overwhelms your server with requests and slow down your website.
    • They can also hammer your XML-RPC protocol on WordPress.

    Code injection

    • Using vulnerability in your website software (usually theme/plugins) or server software (operating system, modules) somewhere to inject code into your site.
    • This code can cause unwanted site behavior, typical malware like ads or redirect links to other sites, display prank-style messages.
    • The code is also used to open backdoors and access information in your website and database, stealing sensitive content and passwords. Once they have your passwords, they’ll also try it on other sites…like your email, PayPal, and eBay accounts. (Backdoors are basically files that allow the hacker back into your site even if you correct the original vulnerability.)
    • The code can also change existing data, such as redirect your links to theirs or changing your PayPal address to their account instead.
    • The way these code injections usually get in is from vulnerable code in themes or plugins. This is why it’s important to choose your themes and plugins carefully and to always keep them updated.

    DDOS (distributed denial-of-service)

    • Using multiple servers to bring your server down by flooding it with massive requests. They don’t steal any info, they just want to make your site go down.
    • Commonly used against government, religious sites, or business competitors. Also used for targeting individuals/organizations for other personal reasons.

    So there you go! So simple, right? Most website attacks generally boil down to those 3 basic categories. And basically, all the attacks are either to 1) gain entry into your site/server, 2) steal sensitive information, 3) alter the site for their own benefit.

    The problem with WordPress security plugins

    1. They slow down your site.

    This should be public enemy #1. Why?! Because many security attacks are very much a performance issue. Look at the TSA lines at the airports. Super long wait times and they almost never ever catch anyone, right?! That’s what you’re doing to your website. Making it slow as heck for the 99.99% of legitimate users that are never going to hack your site. This is terrible UI by design.

    The other problem with a security method that slows down your site is that you’re potentially helping some hackers to attack you better. If their main goal is to overwhelm you with requests and you use a plugin that makes your website slower, and requiring more processing time, well guess…now it’s even easier for them to overwhelm your server with DDOS attack!

    2. Security plugins can’t secure/detect everything.

    Hear me out for a second. Maybe you think because a plugin can detect 98% of the hacks out there, that means it’s 98% effective…well I say “NO!” Here’s why…most people get hacked because of vulnerable themes and plugins. Security plugins CANNOT secure an insecure plugin. Pretend I kept building new room additions to my house but they had insecure windows and doors…well, I could have a security guard walking around the house but it doesn’t mean those windows and doors are now suddenly locked. So yeah…security plugins can’t prevent most attacks!

    The hackers will STILL get into your site. Ok fine, but you have a security guard who will get all the junk files out, right? WRONG! Because they can’t detect all the bad guy. So they’ll clean up maybe 98% of them, but the ones still left will KEEP LETTING THEIR FRIENDS BACK IN!

    Ok, fine. So how do we completely clean out a site once it’s been hacked? If you want my honest opinion of having personally cleaned hundreds of sites over the years…you have to do it manually. That’s the only way. If you use any automated tool or security service out there…they catch only a chunk of it but still leave some behind. And then it’s up to you to pray that the small chunk left behind isn’t enough to allow the hacker back in. Sure, some services out there guarantee a 100% clean-up and will go in and manually repair your site. It’s a great deal if they actually honor it but how much money have you lost by now?

    Just FYI…here’s a common timeline of how sites get hacked.

    1. Theme or plugin has a vulnerability.
    2. Hackers (or their bots) scanning websites eventually find yours and exploits it, creating a hole.
    3. The site is now vulnerable but the hacker doesn’t get to it until a month later. The hacker’s probably busy with hundreds of vulnerable sites around the world; it’ll be a while before he gets to yours.
    4. 2 months hacker finally gets in and starts all kinds of crazy things. Messing with the site and information.
    5. You wake up the next morning and realize something is wrong. You start to fix the damage, usually either by trying a free plugin-scan or asking your “web guy” who will also probably try a free plugin-scan. The problem is your web guy also probably don’t know how he got in. And the access logs that show his traces are already deleted since the system doesn’t save logs past a certain number of hours/days.
    6. From here you take blind guesses. You’ll update plugins, restore from backups. Then you’ll run a security plugin and try scanning to remove all the hack files. The scans complete.
    7. From here you basically pray nothing happens.
    8. A week goes by and then BOOM, you’re hacked again. All the bad files are back and it’s like nothing was ever cleaned. You’re scared as heck. You’ve done everything right and now realize you have no idea how he’s getting in.
    9. Yes, perhaps the vulnerable theme/plugin was patched but he probably left some backdoors in your site to allow himself back in. Your plugins can’t detect them because they’re written to be somewhat unique and not like the common hack scripts out there in the wild.
    10. You get desperate, contact a security expert or ask your security plugin to honor their guarantee. The person does a half-assed job mostly, running a typical scan and looking at only the most common folders and files. The mere $100-200 that you paid them doesn’t cover the hours it takes for them to actually scan every little corner of your site.
    11. You get hacked AGAIN. A 3rd time and again, all the hacks are back! And this time, your security person has the sense to look at the logs and know exactly where the hack is coming from. By now, you’ve been hacked 3 times and lost a time of sleep. Also have pissed off visitors and customers, probably lost a good chunk of revenue as well.

    3. Security plugins cost money.

    Why does this suck? Well…it’s because it means most of them will be designed and marketing in a way that increases revenue rather than increasing security. Lots of fear-based marketing that prey on ignorant users. And lots of bloated features to justify their cost. The worst part of all is that naive users will stay naive and never learn what it takes to secure their site. They’ll continue to focus on all the wrong things further increasing their trust in all the wrong security measures that don’t actually improve security.

    4. Useless feature bloat

    This is especially annoying since plugins will try to out-do each other for marketing purposes by loading every possible feature. Even features that are only marginally related to security and really don’t even need to be part of a plugin. Sure, it’s convenient for users but at the same time also confusing and can distract them from the most important security functions.

    Common security features (and why they fail)

    Let’s go over some common security methods and how they fail against the most common hacks!

    • Firewall blocking malicious traffic – they can only block known malicious traffic. Will they be able to block NEW malicious traffic? Probably not if your server is among the first ones to get hit. But sure, the plugin will probably catch it 3-6 months later when the hack is already outdated and “caught”. By then, the hacker’s already got a new script out.
    • IP blacklist – do you really think any hacker worth his salt would waste his efforts without using a proxy from a “trusted” IP?
    • Malware signature defense – all malware scans are designed to detect PAST malware signatures, not new ones. If a new one is similar enough to an old one, it may be detected. If it’s not, then it won’t!
    • Malware scanner – isn’t this funny? Why the heck does it need to scan if it’s already detecting them? Or the scan is to prevent you from inadvertently putting hack files on your site/server? Again, the malware scanner doesn’t detect everything and not only that but it slows down your server when it runs. How annoying.
    • Brute force protection – limiting login attempts. This one’s good!
    • Enforcing strong passwords – this is silly. You don’t need a plugin for this! Just use strong passwords.
    • Hiding WP-admin login page – this works somewhat in that hackers can’t find your login page to attack it. But it also fails (slowing down your site/server) if the automated bot keeps trying to reach your login page and your 404 page isn’t cached.
    • Checking WP core files – this is a nice feature; making sure your WordPress core files aren’t compromised. It’s nice but at the same time, believe me…it’s obvious when you’re hacked and the moment you realize one is affected, you’ll already know to immediately replace all WP core files. Everybody who’s been hacked knows immediately to check wp-config.php, index.php, functions.php. I can’t think of any hack that doesn’t prioritize these files first!
    • Hack reports – it’s nice because you see how many hacks are thwarted and makes you more aware of how often your site is being hit by bots and hackers. But also over-estimates the plugin’s effectiveness since many of these hackers would have been thwarted by WordPress naturally!
    • Bullshit features – captcha against bots/spammers, logging user actions, forcing SSL, blocking file editing, blocking XML-RPC protocol, removing WordPress site information from the code, changing database prefix. All this junk isn’t specifically-related to WordPress security and doesn’t actually thwart any attacks. They also don’t need a security plugin to implement. They’re a bunch of bloated features to justify the cost of having a security plugin.

    Fine, so what’s the best way to secure WordPress?

    1. BACK UP YOUR SITE. So that things can be repaired!
    2. Update your WordPress core, themes, and plugins.
    3. Use only quality themes/plugins. Avoid outdated ones or ones by smaller little-known development teams. Don’t buy themes/plugins illegally or download from unknown sources. Also avoid keeping any unused themes/plugins since they create unnecessary directories for hacks to hide inside and making your job harder when you have to find the hacks.
    4. Use strong passwords. And don’t use the same passwords for your site that you do for email and your PayPal account.
    5. Protect against brute force.
    6. Have some kind of brute force protection on your login page. Block XML-RPC protocol if you don’t use it.
    7. If you’re paranoid, you can install a security plugin that has a malware scanner BUT leave it deactivated. Don’t have it running constantly. And every now and then or when you notice issues with your site, you can run the scanner to see what it finds.
    8. Have a contact for a good server-admin or programmer for when you do get hacked. It will happen eventually and you’ll need someone you can call immediately. Are you really gonna trust your business site to random plugin? It’s much better to trust a live human-being who knows your site and can be made to guarantee their work.
    9. All other common sense applies. Use updated webhost, web-server, PHP, etc.
    10. You can install Cloudflare or Sucuri for extra security at the DNS level. Problem is they only help against DDOS attacks which most of you will never get! DDOS attacks are kind of expensive and usually targeted for very specific purposes.

    So does this mean you NEVER use security plugins?

    Yeaup, I don’t use ANY security plugins on my site. Again, the reason why these security plugins suck is because:

    • They can’t secure vulnerable themes/plugins. Most of you getting hacked are due to vulnerable code in your themes and plugins. Your best protection against this is not a security plugin but simply to keep your WordPress core, themes, and plugins updated!
    • They can’t detect the newest hacks and attacks. Their system is designed against detecting old ones that are already known and probably not circulating anymore. Don’t be fooled by “this scanner detects 5,000,000 known signatures”…it’s bullshit. Almost all of them are not used anymore. Hackers are always coming up with new hacks to exploit new vulnerabilities! So don’t waste your time with scanners slowing down the server and still not detecting the latest attacks. ARGH, I’m so impatient explaining all this!
    • They slow down your site. How annoying, right? They can’t detect the latest stuff AND they slow down your site? What’s the point anyway?!
    • NOTE: if you get hacked, you’re welcome to run a security plugin just to help repair/remove the most obvious hacked files but you still need to hire a professional to make sure the site is completely secured!

    More interesting reads:

    I’ll get some more helpful examples soon. Honestly, I think security plugins do almost nothing but slow down your site and give you a checklist of basic “security tips”. I see tons of people still getting hacked with security plugins installed and the ones that don’t get hacked are probably because their site wasn’t vulnerable in the first place.

  • Recovering from a HACKED web server (Linux)

    Recovering from a HACKED web server (Linux)

    Comprehensive guide on how to recover from server attacks (whether inbound or outbound). NOTE: this guide is written for WordPress users but can be applied to any CMS.

    I wrote this security guide to be as helpful as possible. It should help you detect and repair at least 99% of the hacks out there. I repair around 20 servers every year due to hackers, intrusions, and other interruptions caused by attacks. This cheatsheet was originally compiled for my personal use but has since been re-written to be digestible for even newb server admins. (In the midst of complicated server jargon guides out there, I figured to help the community by writing something more actionable for real-world use.)

    The only requirement of this guide is that you know how to get to the command line. Also, I don’t cover all nuances of server security here or list every command for every linux distro. I’m more often using CentOS (RHEL) rather than Ubuntu (Debian). It’s up to you to look up alternative commands if that’s what you need.

    First thing to do when your server gets hacked…

    OH NO! YOU JUST GOT HACKED!! WHAT DO YOU DO?!! WHAT DO YOU DO?!

    Usually, you find out your server got hacked because your datacenter or provider has network-restricted you. Or maybe you find out because of failed services, or defaced websites showing malware. It’s a scary situation as you don’t know what’s wrong and the immediate reaction is to panic. What’s most annoying is that it always seems to happen at the worst time (e.g. big project, vacation, wedding, medical illness).

    1. Hire an expert

    Seriously, don’t mess around. If you don’t know what you’re doing or have critical sites/client stuff, just hire an expert and be done with it. Now is not the time to play DIY. I advise you not to continue venturing on your own unless you really like being an IT paramedic and being responsible for other people’s lives.

    2. Figure out what’s being hacked

    • Is it an inbound attack?
    • Or is it an outbound attack?
    • Is it just malware and defaced website or altered data?
    • How much access did the hackers get into your server? (Just a backdoor/script running from from user directory? Or is it a root-level intrusion?)
    • Did your webhost or datacenter limit your network connections?
    • If the damage is really bad, do you have a plan to temporarily restore critical client sites?

    3. Be prepared to build a new server

    In many cases, if your server is hacked that badly, it’s faster to rebuild a new server from scratch than to waste time trying to find all the hacks and repair all the damaged services and config files in the server. It’s also not wise as you’re not 100% sure whether it’s still compromised somewhere.

    4. Restore from backup or no?

    Many people get lazy and try to resolve hacks simply by restoring an older backup. Sure, this can work if the data hasn’t changed much. Just restore the backup and then quickly harden your server/sites to block the impending attack. But it’s not an option if you don’t have backups or the backup data has changed since. Quite often, we don’t notice an attack until much later from when the server was breached. So if you notice it too late, the clean backups may have already been overwritten.

    Recovering from INBOUND ATTACKS

    This is when outside machines/servers are attacking YOUR server. Some of these attacks actually try to gain entry into your server but others only intend to disrupt services by overwhelming your server. Regardless of their intentions (to get in or not), all of these attacks eat up server resources rendering it unable to load your website for real website visitors.

    Different kinds of inbound attacks:

    • Brute force – multiple attempts in rapid succession at guessing your admin passwords and gaining entry through your login pages or other connection protocols (like XML-RPC for WordPress).
    • Flood attacks – denial of service (DOS), the even stronger distributed denial of service (DDOS), or SYN FLOOD attacks. These attacks specifically target the server on different ports and protocols, requesting many open connections (beyond the server’s limit). It’s the equivalent of mass-calling someone’s phone-line to make it unavailable for legitimate callers.

    These attacks can be randomly targeted or specifically-targeted. The random ones are annoying and erratic. The specifically-targeted are most impactful (they don’t stop until your site goes down). It helps to not have controversial material, exposed IP’s on the internet, or making enemies on the internet. Sometimes, you just can’t help it. It might just be because you have an ecommerce site and those make attractive targets.

    Detecting inbound attacks:

    • Server running slow – this is an obvious sign you might getting hacked. Especially if you haven’t changed anything else on the site and traffic is still the same.
    • Check for high server (CPU) load grep processor /proc/cpuinfo | wc -l. Unnecessary if your webhosting control panel already has a GUI for this. Anything at or above the number of CPU cores you have is considered really high (i.e. load of “5” when you only have 4 cores). High CPU usually means an attack at network level (bombarding services).
    • Check for high memory usage cat /proc/meminfo or top. High swap messages in your control panel at random intervals are also an obvious indicator. Sometimes the attacks will erratic and you’ll just have to scan logs. High memory usually means an attack at software level (bombarding php scripts).
    • Check connections per IP netstat -ntu|awk '{print $5}'|cut -d: -f1 -s|sort|uniq -c|sort -nk1 -r. Up to 50 connections from one IP can be normal, anything over 100 is suspicious. If you see many single connections but coming from the same subnet, check 2nd half of this guide.
    • Alternate commands to check connections per IP tail -n 10000 yourweblog.log|cut -f 1 -d ' '|sort|uniq -c|sort -nr|more and netstat -n|grep :80|cut -c 45-|cut -f 1 -d ':'|sort|uniq -c|sort -nr|more. Use these if the previous ones didn’t help.
    • Check for syn connections netstat -n | grep :80 | grep SYN
    • Check logs for failed login attempts cat /var/log/secure (RHEL, Centos, Fedora) or cat /var/log/auth.log (Ubuntu, Debian).
    • Check for WordPress wp-login brute-force attack (current day) grep -s $(date +"%d/%b/%Y:") /usr/local/apache/domlogs/* | grep wp-login.php | awk {'print $1,$6,$7'} | sort | uniq -c | sort -n
    • Check for WordPress XMLRPC attack (current day) grep -s $(date +"%d/%b/%Y:") /usr/local/apache/domlogs/* | grep xmlrpc | awk {'print $1,$6,$7'} | sort | uniq -c | sort -n
    • Then ban the most offending IP’s and/or disable the ports and services that are being attacked.

    Stopping inbound attacks:

    • Ban IP’s – you can block the most offending IP’s through your firewall or security plugin. It might also be helpful to install security software like fail2ban that automatically scans your logs and bans the most obvious IP’s. Sure, there are some debates about its efficacy since it may slow down your server and also unable to detect all kinds of attacks.
    • Disable ports/services (OPTIONAL) – this is another good tactic to remove attacks by taking away their attack point. Just make sure it isn’t a port or service that you’re actually using.
    • Enable security (firewall) plugins – the point of using security plugins is to block attacks more efficiently than your current firewall solution. Again, the real risk isn’t that these attacks actually get in but that they use up server resources.
    • Enable security (firewall) services – another way of blocking attacks is to rely on a security service. Usually they operate at the DNS level, and you send all your traffic through their proxy servers so that they can police incoming requests. This is especially important when you have really complicated attacks that low-level plugins cannot handle. For example, layer 7 DDOS attacks are able to send tons of requests to your computer from many different machines. Because it’s a botnet and not just one computer, you cannot ban a single IP. You’d need a much more sophisticated security service (that probably relies on multiple computers) with the capacity to quickly process these requests and let legitimate traffic through without affecting their page load [too much].

    I wish I could be more clear about how to ban IP’s and disable ports/services but it really depends on what firewall you have have. The most common ones I’ve come across are:

    • iptables (command-line)
    • ConfigServer
    • ModSecurity
    • Firewalld
    • Lua-Resty-WAF

    See which one you have and if you DON’T have one, well it’s time to install one then! Then look up its documentation to see: which ports/services are open, where the block/ban lists are, how to make changes. Don’t forget to restart it after you make changes. (Note to myself to update this distinguish between network vs application firewalls.)

    Reference links:

    Recovering from OUTBOUND ATTACKS

    This is when there’s a hack or malware script on your server, using your server to hack other servers. Typically, they take over your server, using it and its resources as part of their botnet to target other servers. Pretty malicious and evil, I know! In doing this, they can clever deploy tons of servers to brute force or DDOS for them instead of having to pay for all those servers themselves. It’s very diabolical! And worst of all, aside from using up your server resources, it gets YOUR SERVER and YOUR IP reputation trouble. It’s the equivalent of a criminal using a stolen car to rob banks.

    Unlike other hacks, you cannot fix these on your own time. Quite often, I’ll have clients that have a hacked site but aren’t in a rush to fix it since it’s not as important as the others. Well, guess what? These hacks typically cause other server owners and datacenters to complain to your datacenter that you’re hacking them. At this point, your hardware vendor has no choice but to do the responsible thing by limiting YOUR network connections. That means restricting some of your ports and services to limit the damage, which will affect all sites on the server. So sure…it might not be an important site that was hacked but it will affect all other sites. A definite quandary if you’ve got other client sites on there. So what do you do? Fix the outbound attack ASAP and so your datacenter can lift the network restrictions.

    Different kinds of outbound attacks:

    • Same as the inbound attacks but now it’s your server that’s doing the hacking. Brute force, flood attacks, email spam, etc.

    But this time, we don’t diagnose it the same way. We don’t look to see how many connections we have with each IP because the idea isn’t to ban other IP’s. The strategy now is to see which illegal processes are running, find out their location, kill them (from running), and delete them. And then most ideal is to find the hole where they got in and fix or remove that vulnerability as well.

    Detecting outbound attacks:

    • Check outbound connections netstat -nputw and see which ones look suspicious. If you see too many lines, try netstat -nputw | less (PS: you can exit less command with q). If you see any “stealth” processes on the right side, take note of their process ID number (aka “PID”).
    • Can also check for stealth processes directly ps -ef | grep stealth.
    • Find location of stealth process lsof -p 12345 | grep cwd and lsof -p 12345 but replace 12345 with actual process ID. Now you know which directory to clean. You should also check /tmp directory as stealth processes often run files from there find /tmp | grep -i stealth.

    Stopping outbound attacks:

    • Clean the directory manually (using your eyes to detect bad files), or plugins (like Wordfence) to scan the site.
    • Check recently modified files within last 24 hours find /directorypath -mtime -1 -ls using path to home directory of hacked user account or wherever the hack was. (Of course, change the path or timeframe as needed). More info on adjusting this command here. Then go in there and delete or fix files! (NOTE: if the list of files is too long, you can use the pipe command to output them to a file.)
    • Change passwords – if you saw backdoor scripts and Adminer during your cleaning process, it’s probably a good idea to change all control panel, admin, and database passwords. If you also used any of these passwords for your email, PayPal, eBay, Facebook accounts…I recommend changing them as well. (Hackers often cross-check your passwords against other online services.)
    • Kill the process, using kill if you know the process ID (kill 12345) or pkill if you know the process name (pkill processname). This will kill the PID, as well as anybody running the process under that ID.
    • Find and close the vulnerability – time to figure out how they got in. Almost always, it’s a vulnerable theme or plugin (probably one that has a form in it). Usually you have to check the modified files. But what if you didn’t detect the hack until many days later? Unfortunately, it’s really hard to know as you probably won’t have the time to read all the logs or maybe the logs showing how they got in have already been deleted. All you can do from here is update all your 3rd-party extensions and keep a close eye on the site. If it gets hacked again, immediately check the recently-modified logs.

    Reference links:

    Recovering from INJECTION, MALWARE, DEFACEMENT ATTACKS

    Malware or defacement attacks are usually the most obvious and most low-level ones. You can see it when your website all of the sudden starts redirecting to another site (probably with ads and questionable material), or maybe your site itself is showing ads, weird pop-ups and triggering security warnings. The worst is when they actually change the data in your database, changing your content and even payment gateway API (re-routing incoming payments to their financial accounts instead of yours!).

    Different kinds of malware/defacement attacks:

    • Website redirects to another one
    • Website has ads or weird messages/content that you didn’t put
    • Website content altered and now has links in it that you didn’t put
    • Website redirects incoming customer payments to the hacker’s financial account instead of yours
    • Website stops working or is broken
    • Login page hacked into a “phishing page” and sends info from user login attempts to the hacker

    In case you’re wondering of how they got there in the first place…WELL, it usually has to do with some vulnerable plugin or theme that you had running on your site. And to be more specific, it’s almost always some plugin that has a form somewhere or allows users to input information. Quite often, these forms don’t properly “sanitize” the data (sanitization means to disallow illegitimate data)…which then allows the hacker to plug vulnerable code into the database (aka “SQL injection”). These SQL injections are used to run commands that can return information like user names and passwords, payment gateway API’s, or output hack code to a php file (backdoor scripts). And of course, these backdoor scripts are usually placed inpublicly-allowed directories like image and upload directories which allow php execution. Why do plugins sometimes fail to sanitize data? It’s either one or a mix of both lazy and incompetent coding.

    The thing that many people don’t understand about security: hackers got in because YOU installed or activated some vulnerable plugin that then let them in. It’s not because your security system failed.

    Detecting malware/defacement attacks:

    Usually pretty obvious as you can see your website functions have gone awry but now is the time to check the usual places. The first 3 steps must because checked and corrected first.

    • Check htaccess – open it up and see if there are new lines in there that you didn’t add.
    • Check wp-config (or other CMS config) – open it up to see if the site URL was changed in there.
    • Check database – if using WordPress, go to the wp_options table and look at the “site address” and “WordPress address” rows. If it’s got the wrong URL in there, change it back. If they changed all the urls in your database (uncommon), you’ll have to manually change all those strings back.
    • Check theme files – go into your active theme directory and look around for weird files. Also check the functions.php file to see if any malicious functions were put in there.
    • Check plugin files – same thing as above but in your plugin directories. This option is often not realistic if you have too many directories to look through.
    • Check uploads directory (or other public directories) – many hacks and scripts will hide (and execute) from these directories because these are open to the public. Would be smart to block php execution from the uploads directory.
    • Check plugin settings in WordPress – log into your WordPress admin (or other CMS admin) and check all settings to see if they’ve been changed. What you’re looking for is any place where they might have changed sensitive info, like putting their PayPal email instead of yours, putting their logo or site URL instead of yours, having your backups go to their remote storage instead of yours, etc…the possibilities are endless. Be thorough and check everything over carefully!
    • Checking for base 64 encrypted code – hackers use this to hide their code. So you can’t read and see the exact strings to search for. No worry at all…we learn how to search base64 code below…

    Use find and grep to search for these strings. (But beware that there are legitimate uses for base64.):

    • base64_decode
    • gzinflate(base64_decode
    • eval(gzinflate(base64_decode
    • eval(base64_decode

    Stopping malware/defacement attacks:

    • Run a malware scanner – run something like WordFence as it has the best malware database and also notifies you of which files are changed and which files don’t belong there. Honestly, this should have been the very first step as soon as you can get into your site admin. But I mention all the other since you have to be at least pass over it with your eyes and know how to do some of this stuff manually.
    • Check recently modified files – using commands I already shared above.
    • File comparisons – this is so time-consuming and probably not absolutely necessary unless this is a truly critical site and you need to make sure no other hack or vulnerability is on the server. Simply compare side-by-side between current site backup and one from a date you know is clean. If you’re clever, you’ll know how to do this quicker with code editors.

    Reference links:

    Recovering from ACCESS BREACH

    This is when hackers have gained access into your websites (or web server) and its content. Even scarier is when they have their own admin accounts or gained access to yours, even worse—have root-level access! Server accounts, FTP, database, email, website admin, and so forth. It’s scary stuff!

    Different kinds of access breaches:

    • Website admin – they have admin rights and can change info as they please.
    • FTP access – they’re able to upload files and scripts to your server, or also download stuff off of it.
    • Database access – they’re able to download or change data, even inject code into files.
    • Email access – able to read, or send emails from your server.
    • Server access – with access to the server, they can do any or all of the above and even take complete control of your server. Once a hacker has root access and enough time, they could theoretically create so much damage and chaos that it’d be much faster for you to rebuild a new server from scratch than to try repairing their damage. The risk is that even if you found 99.99% of their hacks but still left one backdoor open, they could let themselves back in again.

    Detecting access breaches:

    • Check who is logged in (and where from) w, the hacker might be logged in and working as you speak. Take note of the usernames used and their IP location. Most likely if they’ve gotten this far, they’ve gained root access. Do NOT try to kick them out just yet! You don’t know how much access they have and trying to kick them out now might cause immediate retaliation (further hindering your recovery process).
    • Check login history last. Useful to see who has previously logged in. Again, take note of usernames and IP location. You should be very suspicious if the login history is empty (that means somebody is hiding their tracks!)
    • Check command history history, shows you all the recent commands used (also stored at ~/.bash_history). Look for wget or curl commands used to install malicious software/packages. Again, if you see nothing that means somebody is hiding their tracks.
    • Check for high use processes top, look at the top cpu-use processes. Hackers with root level access typically use as much server resources as possible to hack other servers, send email spam, or mine for cryptocurrency. If you don’t recognize a process, try lsof -p 12345 or strace -p 12345 (replacing “12345” with the actual process ID number). Lsof will show all the files run by a process (super useful).
    • Check all processes ps, ps aux, ps auxf. Each one shows more info than the last. I personally prefer “ps aux”. Here, you can see all running processes and can take note of any that you don’t recognize. TIP: the more often you run this command the better you’ll get at spotting strange processes.
    • Check network usage iftop shows processes sending/receiving data, along with their source and destination. Any processes abusing your network with DOS or spam will show at the top.
    • Check listening connections lsof -i or netstat -plunt, look for any “LISTEN” or “ESTABLISHED” processes that you don’t recognize. It’s good to check for listening processes as they don’t consume much CPU to get noticed in “top” but are used by hackers to send commands to the server. Again: use the “lsof -p” command to look up processes if you don’t know what they do.

    Stopping access breaches:

    • Shut off server, and hire someone – if this is way above your level. Shut off the server and don’t turn it back on until you have an experienced admin there to quickly remove and reseal so the hacker can’t re-access.
    • Disable SSH from all IP’s except your own – do this after you turn server back on. Make sure you’re the only one logged in.
    • Block all ports and services – start limiting your firewall and re-allow things one by one only when you’re sure they’ve been verified.
    • Kill and remove processes – like you did with previous steps.
    • Change passwords – to everything.
    • Search for new admin accounts – hackers often create new admin accounts for themselves once they get in. Or they might do clever things like increasing another user’s rights to full admin, or disguising an admin account as an official “support” account for your webhost/software. Look carefully and remove or adjust all accounts. They often create multiple admin accounts if they go through the trouble at all.
    • Copy everything to new server – I’m sorry but just about everyone will tell you it’s irresponsible to continue working off a previously compromised server. There’s no telling how much damage was done and not smart to risk it. You’re safer off copying everything to a fresh install. With that said, this option is quite drastic and may not be absolutely necessary if your site was only vulnerable at the user-level and some backdoor scripts. The sentiment is more for when people had their server breached at the root/admin level.

    Reference links:

    Quick thoughts on server security

    I know most of you will be asking this question here but I really don’t want to write a post-in-a-post, so I’ll leave you with a few quick thoughts.

    • Firewall is best handled at the server level or even DNS level (by 3rd party security service). Using application-level plugins would be resource heavy, slow down legitimate visitors, and not as comprehensive.
    • Malware scanning is theoretically best (most resource-efficient) done at the server level BUT…the problem is that applications are so complicated within their own plugins and extensions that they need their own application-specific malware scanners to be thorough enough for zero-day attacks.
    • The best server-level malware scanner is probably ImunifyAV (free) or Imunify360 (paid). With that said, I don’t use it. So that goes to show how much you really need it. I’m sure it’s great for catching little server oddities and email spam and what not. You can use them if you’d like an easy GUI to do your malware scanning and perhaps auto-scheduling options.
    • The best application-level malware scanner (for WordPress) is Wordfence. It’s got the best signature database, most thorough and protective. Wordfence catches more hacks, malware, and intrusions than any other WordPress security/malware plugin IMO. It would be so awesome if Wordfence could design a server-level plugin to use on WordPress-oriented servers.
    • Maldet is a total waste of time. I can’t tell you the number of times this thing has failed to find the exact hack causing all the problems. At best, it finds some old hacks in your email files and that’s it. It’s terrible for zero-day attacks or real-world use IMO.
    • When it comes to firewall plugins, you need SMART [ADAPTIVE] firewall plugins. With a “dumb” [manual] firewall, it doesn’t adapt to attacks and no settings are applied unless you manually apply them yourself. Smart firewalls can read logs and ban IP’s on the fly based on their behavior.
    • Most security plugins (both server and application) out there are junk. Just plugins with fancy marketing and logos that barely do even as much as the free ones.
    • The best way to handle website/server security AND prevent attacks and security mechanisms from slowing down your sites…is to use best practices and other typical checklists security tasks. I’ll do a post on that later. Honestly, you should be learning from real sys-admins showing you their favorite security configs. I don’t even consider myself a senior admin…so if you’re trying to learn from me, you’re already doing it wrong!
    • Here’s another cool way to deal with security vulnerabilities…by scanning for vulnerabilities during the development process. (Cool service: RIPSTECH) The only issue is that it’s probably very expensive and the only developers who would care to use this are the ones being responsible enough with their coding that they probably won’t need it.
  • What Is a Firewall?

    Every website needs protection. Just like your personal computer, online servers can be targeted for attack. You need a way to keep out hackers or other sources of illegitimate traffic. That’s where firewalls come in.

    What is a firewall, in short? It’s a barrier between a computer and the “outside world”.

    Malicious actors can wreak havoc on your server if you leave your website unprotected and that’s why you should do everything you can to secure your WordPress site. Setting up a firewall should be one of your first orders of business.

    But there are many different types of firewalls and you might not know where to begin.

    “A firewall is the barrier between your computer & the outside world. 🔥 So how do you choose the right one to keep your website safe from hackers? 🦹‍♂️ Read on for recommendations ⤵️

    What Is a Firewall? What Does a Firewall Do?

    Whenever you visit a website, you’re basically connecting to another computer: the web server. But because a server is just a specialized kind of computer, it’s susceptible to the same kind of attacks your own PC is.

    It’s not safe to connect so directly to another device without any kind of protection in between. Once that connection is established, it’s much easier to infect the other party with malware or launch a DDoS attack.

    That’s what a firewall is for. It’s the intermediary between you and any other devices trying to connect to you or, in a web server’s case, between it and the hundreds or thousands of connections it makes with others every day.

    So how exactly does a firewall work?

    Firewalls simply monitor incoming and outgoing traffic on a device, scanning for any signs of malicious activity. Should it detect something suspicious, it will instantly block it from reaching its destination.

    How to Get a Firewall?

    To protect yourself and your website, you need a high-quality firewall that will keep intruders out.

    As far as personal firewalls go, it’s not usually necessary to go out of your way to get one. Windows’ built-in firewall works very well with no configuration at all. And between the application firewall that often comes with your antivirus software, and the packet filter on your router, your computer is usually more than protected.

    Just make sure your firewall is activated, you have a good antivirus installed, and your router is configured properly. The same thing can be said for macOS users.

    But what if you have a website that needs protection?

    It’s a lot different then. There’s not as many built-in tools to protect you, and often it’s up to you to secure your website. For instance, if you’re running WordPress, there’s no firewall or anything to protect your server and security plugins are one of the most common options.

    WordPress developers do their best to keep the code optimized, but when vulnerabilities do arise, you have nothing to prevent intrusions.

    Every site can benefit from a WAF. Online services like Sucuri, Wordfence, Cloudflare can get one set up on your server in minutes.

  • Improve WordPress Security

    There are some simple tweaks you can do to prevent some popular infections.

    1. Disable PHP execution in /uploads/ and /cache/ folders

    You can easily add a few lines of code into your Apache or Nginx configuration which will prevent PHP usage inside /upload/ and /cache/ folders. In many scenarios, this can render the initial backdoor or dropper useless as it can’t be executed even if arbitrary file upload was successful.

    Nginx:

    # Deny access to PHP files in any /uploads/ or /cache/ directories
     location ~ /uploads/(.+)\.php$ { access_log off; log_not_found off; deny all; }
     location ~ /cache/(.+)\.php$ { access_log off; log_not_found off; deny all; }
    Apache:
    Create a .htaccess file to /upload/ and /cache/ folder and write following inside both of the files:
    # Kill PHP Execution
    <Files ~ "\.ph(?:p[345]?|t|tml)$">
    deny from all
    </Files>

    2. Disable file editing from Admin Panel

    It’s a good idea to disable file editing options directly from the WordPress Admin Panel. You can add the following code into your wp-config.php file:

    ## Disable Editing in Dashboard
     define('DISALLOW_FILE_EDIT', true);

    3. Hide default Admin Panel

    WordPress sites are constantly brute-forced by botnets and hacking scripts. The main reasons for this is the vast amount of sites with known admin panel location /wp-admin/ and the fact that many site owners will use default Admin or Administrator username and a weak password. It’s an easy way to gain access to thousands of WordPress sites and infect them with desired malware, install backdoors, send e-mail spam and redirect traffic.

    It can be tricky to change the /wp-admin/ location manually in a way that it works properly. Use a third party plugin instead, such as WPS Hide login.

    4. Web Application Firewall, Up-time Monitoring, Vulnerabilities

    It’s good to have a managed web application firewall which is always updated with the latest security risks and exploits that follow outdated and vulnerable WordPress plugins, themes and core versions. Firewall today is as essential for websites as anti-virus software for computers and having a full overview of what’s going on on your site is a must-have.

    There are different WordPress plugins like WordFence, iThemes Security and All In One WP Security which allow you to set up hardening options to your site automatically, without having to add scripts to different files manually (as above).

    If you want to have confidence and don’t want to go over the WordPress hardening or even worse, a malware removal process, get us, We offer Free migration from other (WordPress) maintenance services or hosts. No fixed contracts, cancel anytime, starting at $ 20/month.

    5. Use secure hosting and keep software up to date

    Your hosting environment has to be updated (check if PHP 7.4 is supported), well configured and secure. If you save money by choosing a cheap, untrusted hosting provider then it’s a matter of time when issues arise. You can secure your application with highest grade security solutions, but when your host is hacked, none of the implemented security on your application matters.

    Discover our top rated hosting for fast & reliable (WordPress) websites. Sites are hosted on secured servers. Get up to 200% the speed compared with HDD hosting. 100% Uptime Guarantee for your websites or applications. We can help you launch, enhance or migrate your hosting according to your needs. 24x7x365 we monitor your (virtual) server or website. Our advice is straightforward and free, and we can’t wait to help.

    If you have any question or need help, feel free to contact us.

    Stay safe!