Security questions
13 short answers about security. Each one links on to the full article and, where there is one, a step-by-step tutorial.
- How do I keep my website secure?
Keep everything updated, use long unique passwords, turn on HTTPS and take backups you control. Those four cover the overwhelming majority of real attacks on small sites — outdated plugins are the single most common way a site gets compromised.
- My website has been hacked — what do I do?
Change every password first, then take a copy of the site as evidence before cleaning anything. Find and remove the malicious files, update everything, and only then bring the site back. Restoring a backup without closing the original hole just gets you reinfected.
- Why does my site redirect visitors to another website?
That is a common symptom of a compromise: injected code in
.htaccess, a theme file or the database sends visitors elsewhere, often only on mobile or only for first-time visitors. Treat it as a hacked site and clean it properly. - What makes a strong password?
Length, and never reusing it. A passphrase of four or five unrelated words beats a short password full of symbols, and a password manager means you never have to remember any of them.
- How do I stop brute-force login attempts?
You cannot stop the attempts — every site on the internet gets them — but you can make them pointless. A long unique admin password, a plugin that limits login attempts, and not using
adminas a username together handle it. - How do I know if my email account has been compromised?
The usual signs are bounce messages for mail you never sent, contacts receiving spam from your address, or sent items you do not recognise. Change the mailbox password immediately, then check for forwarding rules an attacker may have added.
- I got an email saying my website is hacked or my hosting will be suspended — is it real?
Treat it as phishing until you have checked independently. Never click the links: log in to the client area directly by typing the address yourself, and see whether anything is actually wrong there.
- How do I find malicious files on my site?
Sort the File Manager by modification date: injected files almost always have a timestamp that does not match your last real change. Look especially for PHP files in upload folders, where no PHP file should ever be.
- What are security headers?
They are instructions your site sends with each page telling the browser how to behave — for example, to refuse to load the page inside someone else’s frame. You add them in
.htaccess, and a sensible basic set takes a few minutes. - What is malware on a website?
Malware on a website is code an attacker has added to your files or database — to send spam, redirect your visitors, or serve their content from your domain. It usually arrives through an outdated plugin or a stolen password rather than through the server.
- What is phishing?
Phishing is a message designed to look like it comes from a service you use, to get you to enter your password on a fake page. Hosting and domain accounts are common targets because they control everything else.
- What is a DDoS attack?
A DDoS attack floods a site with traffic from many machines at once so real visitors cannot get through. It is a availability attack, not a break-in — nothing is stolen, the site simply stops responding.
- What is SQL injection?
SQL injection is when input from a visitor is passed into a database query without being handled safely, letting an attacker change what the query does. It is one of the oldest web vulnerabilities and still one of the most damaging.
Need more than a quick answer?
The knowledge base covers security in full detail, with the background and the edge cases these answers deliberately leave out.
Questions on other topics
All questions- Getting started (13)
- Hosting explained (23)
- DirectAdmin (8)
- Domains (17)
- DNS (18)
- Email (21)
- Email deliverability (8)
- SSL & HTTPS (13)
- WordPress (25)
- Forums & communities (2)
- Online shops (2)
- PHP (9)
- Databases (10)
- Files & FTP (11)
- Developer tools (12)
- Performance (14)
- Backups & recovery (7)
- Troubleshooting (26)
- Account & billing (14)