Monday, May 17, 2010

Video of Website Security Means Increased Online sales

The following is a video version of the article on "Website Security Means Increased Online Sales: - -

Sunday, May 16, 2010

Website Security Means Increased Sales

The growth of the internet has provided website owners with unique business opportunities. This incredible growth has enabled entrepreneurs of all ages to sell their products and services to a worldwide audience.

However, many forget to give their website the same consideration in regards to security. Most people understand the negative effect that a damaged operating system would have on a business owner, and therefore all efforts are made to secure the operating system and the local network. Unfortunately, many overlook their website.

Many websites are well aware of the need for an antivirus software to protect their home network and computer, and most of them have such a software installed that actively protects them from malicious software. Again, many forget to give their website the same consideration in regards to security. Unfortunately, many overlook the possibility of the website being destroyed by a virus, even though it is a relatively common occurrence in the online world.

With all of the work that goes into building a comprehensive website over time, it may actually be more devastating to lose a website than to lose a PC or even an operating system. When a website is brought down by a virus, it cannot be quickly replaced like an operating system or PC. In fact, the damage that is done can take months to repair, especially when you consider how many negative events can transpire as the result of a worm attack. The most obvious effect will be the loss of traffic that will be seen soon after the worm has infected your website.

Everyday there are thousands of new internet users online. Despite the fact that more people all the time are making purchases on the internet, there are a great deal of consumers who remain uneasy about the process and because of that are timid about the internet. Consumers are becoming more and more smarter, more savvy and more guarded about what can put them at risk. Online customers need to be confident that their personal information is safe and that their privacy will be upheld at all times.

One study by Forrester Research, Inc., uncovered that a whopping 84 percent of consumer survey respondents indicated they didn't think retailers were doing enough to protect them online. The other finding from London-based TNS PLC, a market research company, found that 75 percent of online shoppers surveyed say they had abandoned a retail site due to security concerns.

Website business owners are constantly trying to improve business. What many don't realize is that by improving their website security, they can improve their sales. Customers say that the security of a website is the number one reason why they do or do not shop on particular websites.

Websites have emerged as the target of choice for money hungry hackers. The ramifications for companies are clear: Loss of data, loss of consumer confidence and loss of brand integrity. No company can afford the black mark of a website hack.

Consider the fact that 8 out of 10 websites visited each day have a serious security vulnerability that puts corporate and customer data at risk. Add to that the irreparable harm done to a company whose brand is compromised by a publicized attack. It's a call to action for any company doing any of its business on the Web.

Despite the enormous number of attacks and despite widespread publicity about these vulnerabilities, most website owners fail to scan effectively for the common flaws and become unwitting tools used by criminals to infect the visitors that trusted those sites to provide a safe web experience.

As an internet merchant, an important asset for you is the credibility and trust your website conveys to prospective customers. It may seem like a minor thing, but if visitors trust you and your site, they'll more likely buy something, and the more credibility you have, the higher your conversion rate will be.

Conversion Rate is the number of visitors on your site who actually do what you want them to. For instance if you get 1000 visitors on your site a day and 20 of them buy your product, your conversion rate is 2%. Credibility is crucial if you want to make money with your web site. Your website visitors must have trust in your company. It's pointless to spend a lot of work on getting visitors from search engines if these visitors don't convert to sales.

It makes sense for you as a website owner to remove all the fear, doubt, and suspicion that accompanies making a buying decision online. When there is no hesitation to do what you want your online visitors to do, your conversion rates will increase. When you increase the amount of traffic that trusts you, more people will do what you want them to do. Any doubt or hesitation on their part, substantially decreases your chances of making the sale and lowers your conversion rate.

Website security is of major importance to website owners and the people who are using the websites. As a site owner you are responsible for ensuring that your users are able to view your website without the risk of problems associated with malware, viruses and trojans.

Security is an extremely important consideration for any businesses, especially if your business is connected to the internet. When conducting business across the internet you are faced with issues like mitigating security risks and building customer trusts.

Establishing trust with the customers is highly essential for earning profits and higher sales. The trust factor is the same for a physical shop as well as for a website. If you have offered a quality product the first time, the same thing is expected when they come a second time for purchase and if you fail to offer that similar quality, they look for another website.

A site that succeeds in developing a confidence factor in their clients are successful in selling their products/services to them. The Market is basically dominated by feelings and emotions of the customers. A product that fulfills clients' needs are demanded repeatedly by them, thus creating brand loyalty.

People's trust, once broken, is difficult to restore. The reasons might be many and different in nature. Sometimes companies make fake promises at the time of sale and fail to fulfill it or are unable to deliver quality goods or services. Nearly all customers might have been duped of their expectations by merchants once in their lives, or have listened to their friends or relatives about the bad experience.

There's no doubt that you have already heard numerous stories of hacked credit card details on the net. These incidents are widespread. This is the root cause why online buyers are a little doubtful to just type in their personal information whenever asked. They needed to know the website they are purchasing from is safe. Before customers are ready to give you sensitive information such as their home address or credit card number, they need to be reassured that your website is safe and secure. Ensuring your customer's security should be a top priority. After all, how will customers react if they learn that their sensitive information (such as credit card details) were compromised on your website?

Hackers and harmful code writers can intrude a site of electronic commerce for the purpose of theft of invaluable details, such as the number of a credit card and other helpful information. Your web site, certainly, will be mentioned and can become a dwelling of cybercriminals. It can force you to lose your valuable clients, and also electronic business. Considering that most hackers spend hours every day trying to find new exploits, hacking into sites and looking for opportunities to steal cash from hard working business owners, you need to put forth the same effort to protect your website.

Thinking that your data is safe does not mean your database of sensitive organization information has not already been cloned and is resident elsewhere ready to be sold to the highest bidder. To make matters worse, only recently, it has been discovered that hackers are not simply selling your information; they're also selling the fact that you have vulnerabilities to others. It seems that most hack attacks are discovered months after the initial breach simply because attackers do not want and will not leave an audit trial. Hackers are interested in stealing the data and leaving it intact.

With the increased accessibility to information on the Internet, web security is a vital necessity. Attacks can range from simple nuisances to dangerous compromises of sensitive data. It is important, during website development, that all possible security threats be considered to ensure adequate protection of the website as well as end users.

If you're not doing everything in your power to make your website visitors feel safe and secure while buying from your website then you could be losing up to 49% of your sales. And this has nothing to do with how persuasive your sales pitch is or how fancy your website looks. When it comes to making that critical decision whether to buy from you or not, the final straw is the consumer's concerns about their online security. You cannot afford to ignore these facts, especially in these times of recession when online shoppers are looking for real value and are becoming pickier about where they spend their dollars.

You should now hopefully realize that the most important aspect of operating an online business is keeping your investments secure at all times. The internet is a very dangerous place, especially for business that conduct hundreds or thousands of dollars in eCommerce each and every day. Having a secure website not only prevents the loss of profits, but it also boosts sales as your customers will be more confident when shopping with you if they know that your site is safe.

Most of all, keep in mind that when you support your website with the appropriate website security, you are increasing the trust of your customers, which in return increases sales for you. Website security is essential, make sure you are doing all that you can to ensure a safe site for you and your customers.

So now that you know that website security might as well stand for increased confidence and sales, what are you doing to ensure that your customers are getting the right security signals from you?

If you want more information on plugging the security loopholes in your website, please visit the following website:

http://www.websiteprotection.net/
-
-

Sunday, February 28, 2010

Basic Website Protection and Security Steps

Most people who have websites do not realize that it requires only a few simple steps to ensure some degree of security for your website and download products. No matter what type of digital product you're selling on the Internet, it is critical that you review your digital delivery method to make sure people aren't walking away with your products. A few lost sales may not seem like much, but over time they can really add up to a substantial loss of revenue. There are a few steps you need to think about in order to keep those who have not paid from stealing something you've worked long and hard at creating.

The following are the most Basic Protection and Security Steps (BPASS) that anyone selling digital products online must take. These take only minutes to do and no special software or programming knowledge is required. Best of all, it costs you nothing to implement them.

BPASS-1

Most people who sell digital download products store their downloads as PDF documents. Nearly all search engines can read and list PDF documents. This means that you must never save or upload a product you want to sell as a PDF file. Many search engines can also convert the PDF files into HTML documents. This means these browsers not only have access to download your PDF file,but can also download your source file as well.

A simple way of keeping your files out of the reach of search engines is to upload them as a zip file. Search engines cannot currently look inside zip files to list their contents. You can use many free programs like WinZip to create a Zip archive. You can hide your digital product, ebook in the ZIP archive. Search engines typically do not go near any file with a .ZIP extension.

BPASS-2

All web servers are configured to display a default page for a directory if a default file exists. That is how your home page is found when someone simply enters a domain name for the URL for a web site and the home page is displayed. A server is configured to search a list of default file names and if it finds a match, it displays the page. The default files, index.* could be similar to what is shown below, where * is the index page extension.

index.htm
index.html
index.shtml
index.php

When someone goes to your site by typing in your URL, the index page is what they normally see first. This prevents viewing other pages or files you may have in the root directory. What your visitor actually sees in this case is your home page.

The other directories(sub-folders) on your website, the ones below your root directory, which is typically called "public", or "public_html", do not normally have this index page. If the index page is not there, your visitor may be able to view every web page or file you have in that directory. A folder without an index page is open and everyone can find your product and download it if they search for it. You thus should create an index page for all your folders. This is especially important for your download directory.

The index page can be used in any directory on a web site except those directories that already utilize an index page or default page. This includes the root directory. Never place one of these files in the root directory, never overwrite an index page or default page that already exists and never place an index page in a directory where another index page or default page already exists.

A basic index.* page would have, at minimum the following:

The above basic index page would show a blank web page. Instead of seeing all the files that you have in the sub-folder, they would simply see a blank web page.

If you want, you can put some text or graphics between and tags.
You can add some text that perhaps says: "Internal server error. Please contact system administrator."

The text will give the impression that the person trying to get into your site, caused some type of server error and so will hopefully stop them from going any further. The modified index page is shown below:

You can also take the index web page one step further. You can redirect spying eyes from your website directories back to your home index page in your root directory. You can use what is called a "meta refresh" tag. The tag looks like the following:

META HTTP-EQUIV="refresh" content="0;URL=http://www.yourdomain_name"

You would replace "yourdomain_name" with your actual domain name or whatever URL you would like to put there.

The following shows the index page with the meta refresh tag:

In the meta tag, the page refresh has been set to zero (0) seconds, which is just short enough for redirecting to the specified URL.

If you are using an index page with the meta-refresh tag only, then instead of someone seeing a blank web page, they actually get re-directed to your Home page. If this was a casual surfer who just happened to end up at your website by mistake, then they will find themselves on your Home front page, and, you might end up getting a customer, a good side benefit of the index.html page with meta-refresh tag.

Please don't forget that If you do not create an index.htm or index.html file, etc., you'd be allowing everyone to directly access the root directory of the folder where you store your downloads and cause you loose of potential income.

BPASS-3

You can easily stop search engines from indexing your web pages. An indexed web page means anyone can find it on the internet when they do a search. This disallows search engine spiders from reading and listing the download pages that link to your products. This must be on your download page(s) and any other web page that you do not want indexed for one reason or another.

On the web page, between the and [head] and [/head] tags, add the following “Robot” tag.

The tag prevents search engine spiders from reading and listing the download pages that link to your eBooks. This "Robot" tag tells the spider that this page is not to be spidered or indexed. As a result it should never show up on a search.

BPASS-4

Search engines scan only two levels down your domain; try keeping your downloadable product three or four levels down;
– for example, www.mydomain/directortyA/directoryB/directoryC/download file.

BPASS-5

Make sure to name your download folders and files with strange names and change them often. Don't use common names like downloads.htm or thankyou.htm, as someone could go to the search engines and easily find your documents in this way.

Change your download links frequently. To prevent unscrupulous people from posting your download links on forums or message boards, change the folder or file name where you store them from time to time, even if it means having to change the download links in your merchant account.

BPASS-6

Protect folders by permissions, directory and script file permissions.

A variety of files and directories in your website need to be given the correct permissions to work properly. Giving permissions to files or directories in the Unix world is called CHMOD (change mode). Chmod is a Unix command that lets permission levels be assigned to each file or directory. The proper CHMOD is also needed to help you with your website protection and security.

The following are the basic file permissions:

Files: 644
Folders: 755 (with index page in it)
Images: 644
CGI scripts: 755
Php scripts: 644

Folders with CHMOD 755 must have an index page in it. By default, your public or public_html directory is typically set to CHMOD 755. With this setting, if a Web surfer connects to your website, the server will display either your home page (if a file with the name index.html, index.htm, or index.shtml, etc., exists) or a listing of all the files in that directory. This also holds true for any sub-folder in your domain, which is why you need an index page in every folder on your website.

Always make sure your folders are given 755 permissions (with index file in it) OR 711 permissions. 711 gives Access denied error. This permission setting will not show a file listing. If there is no index page, the Web surfer will receive a "Forbidden" error message.

The CHMOD capability depends on two conditions:

1) The server you are connected to must support the CHMOD command.
2) You must have access rights to change the attributes of that remote file or directory.

Make sure these two conditions are fulfilled.

The 644 Files permissions represents the permissions of your web pages. Suppose you have just finished modifying your web page and you did not want anybody to update or to delete it. Then, give the web page file permission CHMOD 444 and it will have this effect. This gives everybody, including the owner (user), only read capability. If the owner turns off the write permission, the file is protected from accidental or deliberate destruction.

You may have to set CHMOD 444 via your host CPanel in a browser. Make sure you check this out. If you entered your site via FTP, edit your web page file by adding a small change and then removing it. When you try to save the file, you should not be allowed to over-write it.
Once you have changed file persmission to CHMOD 444 on your web page, ensure that it still functions and runs properly. Whenever you need to edit your web page, simply change back to CHMOD 644, do your changes, and then change again to CHMOD 444.

Having to change file permissions everytime you need to edit a web page might feel a bit tedious. Preventing attacks to your website which could stop all traffic to your website, may be well worth the extra few minutes needed to edit a web page via the CHMOD command.

Summary

Using these Basic Protection and Security Steps will give you a good degree of satisfaction, knowing that you have taken the most basic steps to protect your digital valuables - and at absolutely no cost to you.

If you want greater security and more information on plugging the security loopholes in your website, please visit the following website:

http://www.websiteprotection.net

--

Sunday, January 17, 2010

Website Security Statistics

Web security company Cenzic released a report detailing trends and numbers related to Web security for the first and second quarters of 2009.



Among the most serious vulnerabilities were path traversal (folder listing), cross-site scripting, cross-site request forgery and SQL injection. You may have to deal with all of these in order to make your website secure.

A report by security company Whitehat Security has indicated that:
- Historically, 82% of assessed websites have had at least one issue of HIGH, CRITICAL, or URGENT severity
- 63% of assessed websites currently have issues of HIGH, CRITICAL, or URGENT severity
- Historically, websites average 17 vulnerabilities identified during the lifetime of the assessment cycle
- Websites currently average 6 open vulnerabilities

A report by The Web Application Security Consortium (WASC) showed that for about 12186 sites tested, 97554 vulnerabilities were detected. The analysis showed that:
- more than 13% of all reviewed sites could be compromised completely automatically
- about 49% of web applications contain vulnerabilities of high risk level (Urgent and Critical)
- the most wide spread vulnerabilities are Cross-site Scripting, different types of Information Leakage, SQL Injection, HTTP Response Splitting
- administration issues were 20% more frequent cause of a vulnerability than system development errors
- the probability to compromise a host automatically rose from 7 to 13 %

"When Asked, Most Website Owners Stated That Their Website And Data Was Safe From Hackers. Over 73% Were Wrong!"

Website security and monitoring is a vital part of the success of your online business. Making it a priority is crucial for your website file and data protection. Understanding that and taking the steps to properly implement website security practices can mean increased sales and more business opportunities.

To help you with your website security, I recommend that you visit:

http://www.websiteprotection.net/

You will quickly learn how to combat these hackers.
Many of the solutions can be implemented almost immediately, providing you with your first line of defense.

Tuesday, November 10, 2009

Quick Reference Links To Fight Iframe Injections

I have had many requests from people reading my articles on combatting iframe injection attacks to create a quick start page with the various links one can use to detect and recover from iframe injection attacks.

These links are just a quick summary and you should read the full article to get the maximum benifits.

CHECKING TO SEE IF YOUR WEBSITE IS SAFE

a) http://www.google.com/safebrowsing/diagnostic?site=http://yourdomain_name

Copy and paste the above link into your browser and then replace "yourdomain_name" with your actual website name, e.g., websiteprotection.net

b) http://www.unmaskparasites.com/

IFRAME SCANNERS

a) http://www.diovo.com

Using notepad editor, you need to change the following line in the script:

$webpath ="Type your domain name here. Eg:http://www.diovo.com/"
which becomes:
$webpath ="http://www.yourdomain_name/
Where "yourdomain_name" is replaced with your actual domain name.
Test URL is:
http://www.yourdomain_name/clean.php?s=index.php&c=iframe
where:
s=webpage.ext

b) http://www.websanity.co.uk

Using notepad editor, change the following lines in the script as required:
define('IGNORE_EXTENSIONS',"jpg pdf zip psd doc gif swf xls"); // Ignore files of these types
define("IGNORE_BEFORE", strtotime('2009-08-01') );

c) Auto Scanner Scheduler: http://www.splinterware.com

FILE PERMISSIONS

CHMOD 444 to prevent writing to web page

IFRAME DE-OBFUSCATORS

a) http://www.novirusthanks.org

b) http://www.patzcatz.com

c) http://www.strictly-software.com

IFRAME UNPACKERS

a) http://matthewfl.com

b) http://blog.shimazu.org

c) http://www.strictly-software.com

IFRAME PACKER

For those who want to see how packing is done with a javascript packer.
Make sure to check the "Base62 encode" box or else it will not work.

http://dean.edwards.name/packer


You should use this quick guide after you have read all related iframe injection articles.

Don't forget that not all iframes are bad. Be sure before you delete.