Showing posts with label Website. Show all posts
Showing posts with label Website. Show all posts

Monday, November 26, 2012

Sentry Pigeon Review - Does Sentry Pigeon Really Offer A Proper Website Security Solution?

Sentry Pigeon Review - A candid look at Munchweb's latest product offering.

After having purchased this training course and having delved into it fully, I can give you a real overview of the pros and the cons of investing in this security training designed for the non-technical audience out there.

What Is Sentry Pigeon?

Although Sentry Pigeon has a rather curious and somewhat ambiguous name on the surface, it is actually the WordPress website security solution recently released by one Chris Much (aka Munchweb) and promises a combination of reports and videos that encompass everything you need to know about securing your WordPress blog from hackers attacks and other undesirables out there on the World Wide Web.

What Does Sentry Pigeon Consist Of?

Sentry Pigeon consists of a well written and easy to follow PDF guide that takes you through the individual steps required in securing your WordPress website.

This isn't just your typical digital download product that has been highly touted as a professional offering which eventually falls flat. Having fully reviewed and implemented the methods and techniques covered in the guide, I can safely say that I feel better protected from the hacker community lurking out there on the Internet looking to do harm to my websites.

As well as the guide there are a series of 25 videos presented in the "screen capture" family of videos (where you effectively watch "over the shoulder" of the trainer to see exactly how and what they are doing in the training demonstration).

What Do The Sentry Pigeon Videos Cover?

As well as being easy to follow, the Sentry Pigeon videos contain a variety of techniques on how to secure your WordPress website such as;

How to change the file and folder permissions to give you the best protection for your Web host files and folders Scripts and additional code that is a must to add to your The best WordPress plugins out there that are not only free but also offer the best automated protection for your websites Tactics for reducing the likelihood of a hacker gaining entry to your Web server through FTP or your WordPress blog itself Modifications that you can make to the WordPress login interface to lower the chances of your website being hacked by a method known as Brute Force Attack

This shapes up to be a comprehensive training course but unfortunately there are some downsides to the overall offering, the main points I will go through with you just now.

Now, I will go over what I see as the true pros and cons of the Sentry Pigeon WordPress security training package:

PROS:

Extremely well priced offering. You would be hard pushed to buy a similar mainstream or commercial WordPress security course for the price Munchweb have set. Sentry Pigeon covers all the major aspects of implementing a solid security "blueprint" on your WordPress based website or websites. The PDF report is well written, presented with easy to understand text and overall it is jargon free. Perfect for the intended target audience The videos are well narrated and cover a whole host of aspects within the WordPress security arena, some of which I must admit I had never heard of before Actually implementing the techniques and methods discussed in the videos and the PDF report are very straightforward. Nothing has been left to chance by the course designer.

CONS:

The narrator of the videos, although clear and concise may cause issues for some people that have difficulty in understanding certain dialects and accents These aren't the best "scaled" videos, you may find it irritating to not see the "whole picture" when watching the training videos At the time of writing, there is no option to maximize the videos on the screen. This is overcome by pressing CTRL & the + key to zoom in but it can still be a bit irritating for those of you used to viewing training videos in full screen The videos cant be downloaded to your computer so the content must be viewed online. The PDF report however be downloaded.

And My Overall Impression of Sentry Pigeon?

With various options available on the market, both from commercial companies and "Indie" companies, Sentry Pigeon had to not just be good, it had to be concise, to the point, accurate with the content and above all else provide real value to those that invest their hard earned in the training it provides.

Thankfully, aside from the negative points above, I feel that at the end of the day Sentry Pigeon delivers what it promises to the point that you will not only feel more comfortable with how secure your websites are, but also increase your overall knowledge of how and why we increase security levels on our WordPress blogs and websites in the first place.

I can recommend Sentry Pigeon as a solution that not only will tick the above two boxes, but will provide you with solid knowledge for the foreseeable future.

Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Why Should I Only Trust A Website With SSL Encryption?

It seems that the world revolves around the internet these days, with about ninety five percent of daily life somehow relating to computers and internet use in some way. Bank transactions, shopping, family updates, and even wills and trusts can be done online. SSL encryption ensures that secure information is kept safe. The SSL certificate is free to obtain, which means that webmasters and website developers do not risk losing anything in order to have the certificate. If a webmaster or web developer does not have an SSL certificate, they risk losing business, web traffic, and their integrity.

SSL encryption protects sensitive information as it is transmitted on the internet. SSL certificates work by providing a mixing up the words, letters, and numbers entered over a secure connection. Thieves cannot do anything with this information, assuming that they are able to see it in the first place. That means that when a consumer makes an online purchase, an unscrupulous hacker cannot steal their credit card number. SSL certs also protect bank account numbers, addresses, national insurance numbers, and the like Consumers on an SSL protected site know that their information is safe, and that they can browse with confidence. SSL certificates contain two keys. One is private and one is public. A private key will unscramble all information that the public key has scrambled. This is only half of the story.

SSL certs also authenticate both the website and the client. Authentication is crucial. SSL certificates are created for verified businesses and specific domains. These certificates are like having a birth certificate and social security card when applying for an identification card. It ensures that the website is owned by the company that is represented on the website. It is the same as sharing your birth date and with your doctor versus sharing that same information with a complete stranger.

SSL security provides as much piece of mind for the company as it does for the consumer. SSL certificates ensure that a company will not be responsible for contacting clients and informing them that their information has been stolen. It helps a company preserve its reputation and its integrity. It also makes it harder for hackers to steal information by going into company files. It ensures companies that the internet is not only safe for their clients, but that it is safe for the companies themselves. It costs nothing to get an SSL certificate, so there is no risk in adding one to a website. The bigger risk would be in operating, or doing business, on a website without security.

Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

How To Reduce The Chances Of Your Website Being Hacked

All types of websites are prone to hacking. Even your own email address is prone to hacking at any point in time. For as long as there is a site that could be hacked and information that could be exploited, your website is never a hundred percent safe. This could very much damage your account as well as your reputation if the hackers have managed to exploit your identity with negative intent. It can be worse if you are running a business and your hacked website starts getting in the way of your sales, operations and reputation management.

This is exactly why you have to at least reduce the risk of your website being hacked. While there is still no known definite way of eliminating hacking, it is just important that you stay on your guard so that chances of your website being affected by it will be lessened.

One way to reduce the risk of your website being hacked is to secure your account. Make sure that you nominate a password that cannot be easily tampered with. It would also be better if you refrain from broadcasting around what your password is. If you can, change your password periodically to avoid predictability. Also, use different passwords in your various online accounts.

Another way of keeping your website safe is to name only a few trusted people as administrators. It may be you and your assistant or your IT personnel. Having only a few people who know how to access your website can minimize the risk of a lot of the others accidentally forgetting safety precautions in terms of website security and eventually putting your account in danger of being hacked.

Finally, it would definitely help you keep your website safe from being hacked if you always monitor activities within it. Spending even a few minutes of your everyday logging in to your site gives you a brief update as to the happenings around it. You would then be able to distinguish if something wrong is happening or if some of your posts are deleted or if there are comments about your content that are unexpected.

All in all, it comes down to preparing your website for any possibility of intruders. Knowing what you are up against would also help so that you can enhance the basic guidelines above. Your online security may seem a minor concern but it is definitely not.

Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Is the Use of WordPress Security Plugin Enough to Protect Your Website?

How do WP Security Plug-ins Work?

In general, a WordPress security plugin works by reducing and hiding the vulnerabilities of your site. Aside from scanning and reporting your WP security problems, this plugin provides different automated security measures that make it difficult for cyber criminals to insert malicious scripts or perhaps steal sensitive information from your site.

But like I said earlier, it is not enough to simply use these add-ons. You must keep in mind that hackers work day and night just to steal all the websites they can amass quite easily. In fact, they are not doing it manually. They use special computer programs or bots that could creep into your system and attack your site's weak points. Once they find a hole, it would be easier for them to attack and steal all the information you have been working on for so many years.

How to increase the security of your website?

There are several ways on how you can increase the security of your website in addition to WordPress security plugin's and these are some of them:

1. Delete unused plugins. First thing you can do is to delete all of your unused plugins as these can provide loopholes that hackers can use to easily gain entry into your site. Take note that old and unused plugins are the primary factors that can attract malware attacks and many other website hosting problems.

2. Use .htaccess file. According to Matt Cutts of Google, using a .htaccess file is another way to secure your WP Admin site for it only allows access from specific IP address. You can do it by replacing the IPs with the ones you like to add in your white list.

3. Change your admin username to something other than "Admin" and use stronger passwords if you want to make it harder for Internet evildoers to infiltrate your site. When it comes to changing passwords, it is highly recommended to use stronger passwords consisting of at least fourteen characters such as lower case letters, capital letters, numbers and special characters.

4. Upgrade your WordPress version on a regular basis. This step is very important in keeping your site more secured since latest WP versions contain up-to-date bug fixes for any security vulnerabilities. The latest version of WordPress is version 3.4.1.

5. Hire a WP security service. Perhaps the most ideal thing to do when it comes to maintaining a website is hiring a WP security service that will do all the security measures you need for your site. This professional will ensure that no malicious script, hacker codes, malware attacks or any other website hosting issues could ever take your WP site away from you.

Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Twitter Facebook Flickr RSS



Français Deutsch Italiano Português
Español 日本語 한국의 中国简体。