Security & backups tutorials
Locking things down and making sure you can always recover.
3 tutorials, easiest first
Lock down a new site and account, make sure you can always recover, and know what to do if the worst happens. The backup tutorial ends with a verified archive stored away from your hosting, and the recovery tutorial covers removing an attacker's access as well as the visible damage.
- Take a full backup and store it safely
Create a full DirectAdmin backup, download it, verify its contents and remove it from the server.
Covers: Check disk space; Create the backup; Wait for the notification; Download it; Verify the contents; Store it with a date; Delete it from the server.
- Secure a new website and hosting account
Lock down every login, enforce HTTPS, set permissions, harden WordPress and schedule updates and backups.
Covers: Unique passwords everywhere; Two-factor authentication; Account email; HTTPS; Permissions; Harden WordPress (if used); Security headers; Remove leftovers; Schedule the routine.
- Recover a hacked website
Contain the damage, preserve evidence, restore or rebuild cleanly, close the vulnerability and request search engine reviews.
Covers: Work from a clean device; Change every password; Remove unknown access; Snapshot the current state; Choose restore or rebuild; Hunt for leftovers; Close the hole; Verify externally; Request reviews.