How to Make Your Website Hacker-ProofConsider these tips for keeping your site free of malicious content and protecting your business.

ByRiva Richmond

Opinions expressed by Entrepreneur contributors are their own.

How to Make Your Website Hacker-Proof

Hackersare constantly breaking into innocent websites and using them to infect visitors with malware, lure them to dodgy sites and infiltrate databases to grab sensitive customer information. But you can avoid trouble -- or eliminate it quickly -- by taking some relatively simple steps.

Each day,Google identifies9,500 malware-infected websites, about 4,000 of which are legitimate sites compromised by hackers. About half of these victims learn they've been hacked when they see the same browser and search-engine danger warnings their customers see, a sign they've been blacklisted, according to a survey byStopBadware, a nonprofit anti-malware organization in Cambridge, Mass. Some 45 percent are notified of the problem by one of their technology providers -- a much better scenario.

Small businesses are especially vulnerable to hacking because they usually lack thetechnologyexpertise and sitesecuritythat larger companies have. They also suffer more if their lack of expertiseslows repairsand their ability to get back to work. Business owners can lose significant online traffic and sales if their site lands on blacklists operated by Google and other search engines.

TakeMetroSeeker.com, an Austin, Texas-based startup that offers online guides to cities' "personalities," for instance. The site was down for a week in early June after hackers broke in and pointed all its links to sites selling Viagra. Exactly how hackers got in wasn't clear, so CEO Ysmay Gray tackled every entry point. In addition to cleaning all links, MetroSeeker erased and rebuilt its server, upgraded its content management software, and revamped how employees log in and change site content. "I'm a little paranoid now," Gray says.

Related:Free Tools for Improving Online Security

MetroSeeker.com's recovery required the full-time work of three people and significant help from the company's hosting service, DreamHost, Gray says. While it achieved a clean bill of health fromGoogle's Webmaster Toolsservice more quickly, Web searches triggered a scary warning that "This site may be compromised" for more than three weeks, casting a shadow over the new business, she says. When contacted about the issue, Google said residual "spammy content" in search results caused the warning, but that it would remove it because the spam itself was gone.

"A lot of people will have to tangle with [a hack] at some point in time," laments Maxim Weinstein, executive director of StopBadware. His advice for small companies? "Secure everything." Here's how to get started:

Keep your software up to date.
Hackers aggressively target security flaws in popular Web software such as content management systems and blogging programs so they can attack websites en masse. Stay out of the line of fire by using the latest versions of software and applying security patches promptly.

"Sites that get infected and clean up, but don't fix the vulnerability in their software, just get re-infected," says Lucas Ballard, a software engineer with Google's Safe Browsing team. He urges webmasters to解决潜在的弱点that enabled the hack, as well as remove hackers' malicious code from site pages.

Related:Keeping Passwords Out of the Hands of Hackers

Use strong passwords and keep them safe.
Using strong passwordsis crucial because hackers frequently attempt to crack or steal passwords for web software and FTP servers, which are computers that use the File Transfer Protocol to move web pages and other files to another computer, such as a Web-hosting server. Default, common or predicable passwords can be easily broken.

Also make sure to protect your PCs from a virus infection since that can lead to the theft of site passwords. A February 2010 infection in a computer belonging to freelance writer and editorDavid Congreaveallowed hackers to steal his FTP password and plant malware that tried to infect visitors to his sites. Luckily, the malware was buggy, and he noticed the problem immediately. His hosting service, Hostgator, removed the malicious code in hours. Congreave changed his password and began usingCuteFTPfor more secure file management.

Register with Google's Webmaster Tools.
对谷歌的黑名单,这是由th使用e search site and the Chrome, Firefox and Safari browsers, can reduce traffic to your site. By registering with Webmaster Tools, you can receive notifications of malware infections immediately, sometimes before blacklisting occurs, so you can get rid of them faster. The service also provides details about the precise problem Google is seeing. That can speed your clean up and your return to Google's good graces.

Get expert help.
Companies that are heavily dependent on their websites may want to hire a firm that provides alerts if they get on a blacklist, monitoring for malicious activity, scanning for security vulnerabilities or help with repairs after a hack. Firms that serve smaller companies includeStop the Hacker,SiteLock,SucuriandQualys. Prices start at about $90 a year. Businesses that have databases with sensitive customer information connected to their sites should get help building security into their sites and scouring software code for bugs.

Related:How to Determine If Cyber Insurance Coverage Is Right for You

Wavy Line

Riva Richmond is a freelance journalist who has covered technology for more than a decade. She focuses on computer security, privacy, social networking and online business and has written forThe New York Times,The Wall Street Journaland other national publications. Previously, Riva was a technology reporter at Dow Jones Newswires and regular contributor to The Journal's "Enterprise" small business column.

Editor's Pick

Related Topics

Business News

Kristen Bell and Dax Shepard's Family 'Stranded' at Boston Airport During 9-Hour Delay: 'We Made Quite a Home Here'

The actors spent $600 on pillows and blankets while waiting for their flight.

Business News

What Is a 'Lazy Girl Job'? New TikTok Trend Empowers Women to Work However They Want

The trend began as a way for women to find more free time during their days.

Business News

Kevin O'Leary Slams Anheuser-Busch CEO's Listening Tour, Says It Won't Stop Bud Light Backlash for One Huge Reason

Anheuser-Busch U.S. CEO Brendan Whitworth announced plans to hear consumers out this summer.

Business News

'We're Not There Yet': Meta Focuses on User Retention for Threads Amidst Significant Drop in Engagement

Meta's new Twitter competitor, Threads, experienced a substantial drop in engagement, losing more than half of its user base after its initial launch.

Business Culture

I Started My Business In My Mom's Basement at the Age of 17. Here are 5 Rules I Wish I Had Known, But Had to Learn the Hard Way

There is no easy way to break this to you, but you are the least important person in your business!

领导

5 Ways to Turn Rejection Into Resilience

As I've built my company, I've grown a much thicker skin when it comes to rejection — and so can you. Here's how.