{"id":67,"date":"2019-05-15T12:09:36","date_gmt":"2019-05-15T12:09:36","guid":{"rendered":"https:\/\/www.pcubelive.com\/blog\/?p=67"},"modified":"2019-05-15T12:24:05","modified_gmt":"2019-05-15T12:24:05","slug":"how-to-secure-a-cpanel-account-from-hackers","status":"publish","type":"post","link":"https:\/\/www.pcube.tech\/blog\/how-to-secure-a-cpanel-account-from-hackers\/","title":{"rendered":"How To Secure A cPanel Account From Hackers"},"content":{"rendered":"<p>In an effort to help improve the security on the servers we encourage clients to follow some of our best practices. Please keep an email address where you can be reached for important system notifications like disk quota warnings, change of preferences, external logins, password changes, and more.<\/p>\n<p>&nbsp;<\/p>\n<p>Here are some security tips for improve your cPanel account security.<\/p>\n<ol>\n<li>Completely and correctly scanning your computer for viruses and other malware like Trojan horses, rootkits, spyware, adware, worms, etc. Make sure that you have up to date Spyware \/ Malware \/ Anti Virus protection on any computer that connects to the site via FTP and SSH. Run a scan on these machines and fix whatever issues arise.<\/li>\n<li>Permission is very role in cpanel security. Permission used to specify which particular person may or may not have access to file or directory. Incorrect file permissions can cause errors or even worse, allow unauthorized users to hack your site. Once an unauthorized user gains access, they can further alter more of your file permissions to make a site even more vulnerable.<\/li>\n<\/ol>\n<p><strong>Folders<\/strong> \u2013 755<\/p>\n<p><strong>Files<\/strong> \u2013 644<\/p>\n<p>Remember that <em>777<\/em> permissions means that your file is readable, writeable and executable by the &#8220;world&#8221;. This is not common, as it is a rare situation where a file needs to be written and executed by the &#8220;world.&#8221; If you find files or folders with permissions that do not match the default permissions, it&#8217;s usually best to change them to the above recommended permissions.<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li>Change all FTP user account passwords. Make sure the passwords you reset are secure. Use upper and lower case lettering and numbers.<\/li>\n<\/ol>\n<ul>\n<li>Log into cPanel.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-69\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c1.jpg\" alt=\"\" width=\"587\" height=\"297\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c1.jpg 587w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c1-300x152.jpg 300w\" sizes=\"(max-width: 587px) 100vw, 587px\" \/><\/p>\n<ul>\n<li>Select <em>FTP Accounts<\/em> under the <em>Files<\/em> section of cPanel.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-70\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/cp2.jpg\" alt=\"\" width=\"592\" height=\"191\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp2.jpg 592w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp2-300x97.jpg 300w\" sizes=\"(max-width: 592px) 100vw, 592px\" \/><\/p>\n<ul>\n<li>Select &#8220;<em>Change Password<\/em>&#8221; in the <em>Actions<\/em> column beside the FTP account that needs a password reset.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-71\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/cp3.jpg\" alt=\"\" width=\"602\" height=\"121\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp3.jpg 602w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp3-300x60.jpg 300w\" sizes=\"(max-width: 602px) 100vw, 602px\" \/><\/p>\n<ul>\n<li>Type in your new password and click &#8220;<em>Change Password<\/em>&#8220;.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-72\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/cp4.jpg\" alt=\"\" width=\"602\" height=\"226\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp4.jpg 602w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp4-300x113.jpg 300w\" sizes=\"(max-width: 602px) 100vw, 602px\" \/><\/p>\n<p>4. Make sure that allow_url_include, fopen, and register_globals are set to \u201coff\u201d within any customized php.ini files you have within your account. Also make sure you have included insecure functions within the disable_functions list. This only applies if you are running PHP applications within your account.<\/p>\n<p>5. Update any applications you are running to the latest stable versions. If you are running a CMS, such as Joomla, WordPress, or Drupal, I recommend checking to make sure it and any plugins\/Addons are fully updated as security exploits may have been fixed by the developers. If any security patch install in the website. Newer versions will contain security patches for known exploits within that application. This also applies to any 3rd party plugins themes and application versions you are running for these applications.<\/p>\n<p>6. Backups is one of the most important parts of having a working website. It is crucial to backup your files on a regular basis or just before making any substantial changes so that a backup is available in the event of data . Make frequent personal backups, and make sure that your backups are not infected with malicious code. That way you can easily restore files if you need to.<\/p>\n<p>&nbsp;<\/p>\n<p>Preforming your account backup.<\/p>\n<ul>\n<li>Login to your cPanel.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-69\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c1.jpg\" alt=\"\" width=\"587\" height=\"297\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c1.jpg 587w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c1-300x152.jpg 300w\" sizes=\"(max-width: 587px) 100vw, 587px\" \/><\/p>\n<ul>\n<li>Click the Backup wizard button in the Files section of cPanel.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-73\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/cp7.jpg\" alt=\"\" width=\"568\" height=\"182\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp7.jpg 568w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/cp7-300x96.jpg 300w\" sizes=\"(max-width: 568px) 100vw, 568px\" \/><\/p>\n<ul>\n<li>In the Full Backup section, click the Download a Full Website Backup button.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-74\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c8.jpg\" alt=\"\" width=\"558\" height=\"231\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c8.jpg 558w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c8-300x124.jpg 300w\" sizes=\"(max-width: 558px) 100vw, 558px\" \/><\/p>\n<ul>\n<li>On the next screen make sure the Home Directory option is selected.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-75\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c9.jpg\" alt=\"\" width=\"552\" height=\"308\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c9.jpg 552w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c9-300x168.jpg 300w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c9-215x120.jpg 215w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c9-414x232.jpg 414w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c9-550x308.jpg 550w\" sizes=\"(max-width: 552px) 100vw, 552px\" \/><\/p>\n<ul>\n<li>If you want an email notification when the backup completes, enter your email address.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-76\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c100.jpg\" alt=\"\" width=\"538\" height=\"341\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c100.jpg 538w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c100-300x190.jpg 300w\" sizes=\"(max-width: 538px) 100vw, 538px\" \/><\/p>\n<ul>\n<li>Click the Generate Backup buton to begin the Full cPanel Backup.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-77\" src=\"https:\/\/www.pcubelive.com\/blog\/wp-content\/uploads\/2019\/05\/c101.jpg\" alt=\"\" width=\"556\" height=\"353\" srcset=\"https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c101.jpg 556w, https:\/\/www.pcube.tech\/blog\/wp-content\/uploads\/2019\/05\/c101-300x190.jpg 300w\" sizes=\"(max-width: 556px) 100vw, 556px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>This will generate the back up for you and place the tar.gz file inside of your home directory. You can then download the backup via cPanel, FTP or SSH.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>7. Time to time Check all administrative areas of your sites. Make sure they are all password protected. Sometimes hackers remove this protection which can lead to easy entry later.<\/p>\n<p>8. Time to time Check your applications for new Administrative user accounts that hackers may have setup as back doors. Remove any and all suspicious user accounts. If any suspected user entry found then remove the suspected user entry.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In an effort to help improve the security on the servers we encourage clients to follow some of our best practices. Please keep an email address where you can be reached for important system notifications like disk quota warnings, change of preferences, external logins, password changes, and more. &nbsp; Here are some security tips for [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":79,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[],"_links":{"self":[{"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/posts\/67"}],"collection":[{"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/comments?post=67"}],"version-history":[{"count":1,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/posts\/67\/revisions"}],"predecessor-version":[{"id":78,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/posts\/67\/revisions\/78"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/media\/79"}],"wp:attachment":[{"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/media?parent=67"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/categories?post=67"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcube.tech\/blog\/wp-json\/wp\/v2\/tags?post=67"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}