{"id":31499,"date":"2021-02-09T22:04:11","date_gmt":"2021-02-09T14:04:11","guid":{"rendered":"https:\/\/web.mwwsb.com.my\/pjci\/?post_type=kb&#038;p=31499"},"modified":"2022-09-07T18:39:24","modified_gmt":"2022-09-07T10:39:24","slug":"security-alert-website-defacement-hacked-pages-info","status":"publish","type":"kb","link":"https:\/\/www.casbay.com\/guide\/kb\/security-alert-website-defacement-hacked-pages-info","title":{"rendered":"Security Alert: Website Defacement\/Hacked Pages [INFO]"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"31499\" class=\"elementor elementor-31499\" data-elementor-post-type=\"kb\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-76b01c4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"76b01c4\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-17ac506\" data-id=\"17ac506\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ee19502 elementor-widget elementor-widget-heading\" data-id=\"ee19502\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Security Alert: Website Defacement \/ Hacked Pages<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-360c759 elementor-widget elementor-widget-text-editor\" data-id=\"360c759\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Our Security team found that majority of the website being defaced are using CMS (Content Management System) e.g common CMS are Joomla or WordPress. Currently CMS itself doesn\u2019t have that many security constraints [though new versions versions are launched very frequently by them] it is not that very secure, so it is better to take care of your blog by following the steps below: <\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ff84d28 elementor-widget elementor-widget-heading\" data-id=\"ff84d28\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">i) Make Sure CMS is 100 percent secure<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7012d64 elementor-widget elementor-widget-text-editor\" data-id=\"7012d64\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do not assume that your open source CMS is 100 percent secure. All software have issues and mess ups or security holes. If a CMS has a security flaw hackers will find them at some point. <\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5d6c6e0 elementor-widget elementor-widget-heading\" data-id=\"5d6c6e0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">ii) Keep yourself updated on security issues in your CMS<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-409f0a1 elementor-widget elementor-widget-text-editor\" data-id=\"409f0a1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do not forget to keep yourself updated on security issues in your CMS. Most open sources systems release updates on a regular basis \u201cjust like Windows or OS X\u201d. However not all systems check for updates instantly and some can\u2019t install them with a single click. Keep yourself updated by joining the open source service mailing list or following their Twitter account.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-52537e1 elementor-widget elementor-widget-heading\" data-id=\"52537e1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">iii) Updating your CMS<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3cfff26 elementor-widget elementor-widget-text-editor\" data-id=\"3cfff26\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do not forget who is accountable for updating your CMS. Maybe you have used your hosting provider\u2019s 1 click installer or perhaps your web designer has installed the CMS for you. But do they update it for you? Rarely. Keep in mind it\u2019s your responsibility that your CMS is updated with the newest security patches. However you could outsource the task to your webmaster, website development expert or website designer.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b536c71 elementor-widget elementor-widget-heading\" data-id=\"b536c71\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">iv) Don\u2019t neglect<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-df1449a elementor-widget elementor-widget-text-editor\" data-id=\"df1449a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>If your CMS does give you update alerts, then don\u2019t neglect them. Systems like Umbraco and DotNetNuke have a function that checks if there are updates available when you log in. A system like WordPress also checks and by only a few clicks in the admin you can update your CMS very easily (don\u2019t forget to backup before you update). Take the update alert seriously and update straight away!<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9134449 elementor-widget elementor-widget-heading\" data-id=\"9134449\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">v) Update third party modules<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5b0a5a elementor-widget elementor-widget-text-editor\" data-id=\"f5b0a5a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Don\u2019t forget to update third party modules. Developer other than the open source team can develop modules on your CMS. These modules can also contain security issues. Just as you have to be updated on the CMS updates, you also need to be updated on updates on any of the third party modules your CMS uses.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-40e98ba elementor-widget elementor-widget-heading\" data-id=\"40e98ba\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">vi) Team up with an expert or a supporter<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-81e5813 elementor-widget elementor-widget-text-editor\" data-id=\"81e5813\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Don\u2019t forget to team up with an expert or a supporter. Keeping your system up-to-date can be difficult. However, if you team up with a consultant who is used to update your kind of open source system, you are able to save valuable time and concentrate on running your business. You can pay him monthly and he is going to make the updates when available, or your can pay by tasks.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-51a95ce elementor-widget elementor-widget-heading\" data-id=\"51a95ce\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">vii) Robust password policy<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4550cb1 elementor-widget elementor-widget-text-editor\" data-id=\"4550cb1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do not forget to have a robust password policy. This is really the biggest reason why hackers get access to systems \u2013 weak passwords! Try to make a long password, at least 8 characters with both numbers and letters. Do not use your name or zip plus city. If you find it hard to remember long passwords, attempt to make a sentence with a number, and then use the 1st letter of each word to make a password. E.g. \u201cThe Rabbit jumped over 4 Stones and 7 Flowers\u201d makes the password TRjo4Sa7F.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eeb999e elementor-widget elementor-widget-heading\" data-id=\"eeb999e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">viii) Backup your full system<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fc941d3 elementor-widget elementor-widget-text-editor\" data-id=\"fc941d3\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Do not forget to backup your full system, both files and database \u2013 constantly. Do not take for granted that your hosting supplier backs up everything. Well they do, but mistakes happen even in the largest hosting suppliers. Also the hosting suppliers\u2019 backup history may be only a couple of weeks long. If your system gets hacked, the very first thing a hacker does is leaving a backdoor. After weeks perhaps months he returns and defaces the homepage. When your hosting supplier revives from the newest backup the hack seems to be resolved on the surface, but the backdoor is still there.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-43c56f4 elementor-widget elementor-widget-text-editor\" data-id=\"43c56f4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>If you choose a free open source CMS for your homepage, then remember that it does take some time to upkeep and update it. Outsourcing this part might be a brilliant idea. Do get back to us if you have any feedback or concerns. Read more on <a href=\"https:\/\/www.casbay.com\/guide\/kb\/security-alert-website-defacement-on-joomla\/\">SECURITY ALERT: Website Defacement on Joomla<\/a>.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Security Alert: Website Defacement \/ Hacked Pages Our Security team found that majority of the website being defaced are using CMS (Content Management System) e.g common CMS are Joomla or WordPress. Currently CMS itself doesn\u2019t have that many security constraints [though new versions versions are launched very frequently by them] it is not that very [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"no-sidebar","site-content-layout":"page-builder","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[],"kbtag":[106],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/31499"}],"collection":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/comments?post=31499"}],"version-history":[{"count":1,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/31499\/revisions"}],"predecessor-version":[{"id":32975,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/31499\/revisions\/32975"}],"wp:attachment":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/media?parent=31499"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=31499"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtag?post=31499"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=31499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}