While the media tends to focus only on security breaches affecting major businesses, even small websites can be the target of hacking.
There are many reasons why a hacker might think it worthwhile to target your website, no matter how small. While many hacking attempts target credit card information or other sensitive data, others aim to take hold of a server's resources to send spam email or distribute files of an illegal nature. At SiteCenter we take website security very seriously, and take a number of steps to make sure that every website we build is as secure as possible:
1. Software Security
Most website hacking is performed by automated scripts that are written specifically to target known exploits in widely-used open-source software. Websites that we custom-build are largely immune to this risk because our code can not be examined by hackers for potential weaknesses and your website will therefore not be targeted by automated scripts. Few hackers will make the effort to hack a website constructed with code with which only a handful of website are built, unless that website contains extremely valuable data. Websites that use third-party software such as Wordpress can be kept just as secure by keeping the software updated whenever a new version is available.
2. Secure Sockets Layer (SSL)
All websites we build now feature a Secure Sockets Layer (SSL) to fully encrypt data being sent to or from your website. This means that sensitive data, for example credit card details, is fully encrypted and cannot be intercepted.
3. PHP/MySQL Good Practice
In the vast majority of cases, the websites we build use MySQL databases to store website data, and PHP code to retrieve this code and present it as a web page. We follow standard practice in maintaining secure PHP code that prevents MySQL injection, cross-site scripting and non-permitted file uploads.
In addition, and where the hosting environment permits, core settings such as database passwords are stored in files that are located in a different IP address from websites, meaning that such information is absolutely inaccessible to hackers.
4. Form Security
All form input fields feature HTML character stripping and string length validation to prevent MySQL injections. In addition, for forms such as a user login form, error message are intentionally vague to prevent repeated manual hacking attempts. For example, if a password is incorrect, the user will not be told whether or not their username is also correct or incorrect.
5. Other Precautions
The Website Dashboard we provide for administering your website will use a number of enhanced security measures, in addition to those above. For example, passwords associated with Dashboard Users are encrypted and are therefore unable to be known even by someone who can access the website's database.