The time has come to say a few word to help those people that still don't have their own website and they are planing or making one already.I saw lot of tutorials for saying that you need to chose good domain,nice template fonts and similar makeup things.But what about security part of the whole story?What is the point of fancy website if it gets destroyed in few days?Am not saying that you don't need good domain,nice template and all but you also need to take care about security.There are some things that you should check when starting.
HOSTING
First thing you should look for is secure hosting.How secure hosting you will have depend allot on how many money are you willing to spend.Best solution you can chose would be to take dedicated server or VPS.On the other hand if you don't have enough money to buy dedicated server or VPS and you have to consider shared hosting which is also not bad if you do the right choice.Things that you should look for when taking shared hosting except normal specifications like bandwidth,space available,You also need to look for hosting that don't have many websites.More websites on the server bigger are your chances for getting hacked.Best choice would be if you can find hosting with max 30 sites.Less sites means safer server for you in 80% of cases.As You can see from the % number of sites is not all you should look for.
TYPE OF SITES
Yes you heard it good.Next thing to look for after you find some hosts with small amount of sites is to look for types of those sites.Reason Am saying this is that nowdays there is not too much server side attacks,that mean that most of the attacks that are happening are done trough other websites.And if you consider the fact that html is actually pure text.I say this because with html you cant execute commands like on the php or asp cfm.Take example of sql injections.When is the last time you heard that someone hacked html site trough sql injection or RFI,LFI or something similar.You will see that only on sites who use php components combined with html sites or have php masked as html.So Hosting that have as less php,asp.aspx cfm and other similar sites and have html instead will save you allot.
SCRIPT
Now that you have find good hosting for yourself.You actually did nothing if you chose wrong script for your website.By wrong script i mean on scripts that have tendency to be vulnerable.For example if you are planing to start forum and you compare some scripts like vbulletin,IPB,SMF,phpbb and other my choice would be IPB from payed ones category or phpbb from free category.If you look at the latest advisory on security websites you can notice that Ipb is not regular guest there and has less Exploits for new versions than for example vbulletin,same rule is for phpbb.Point why am i explaining all this is for you to do some checking before choosing script regardless what you want from your website.No mater if you want to start forum or normal website or webshop or whatever kind of site.Go to some mayor advisories sites like milw0rm,packetstormsecurity,securityfocus,and compare last couple of versions of scripts that you like.Make sure you chose one that had less bugs in last few versions than others.
USER MODIFIED SCRIPTS
People often start site and became unsatisfied with some functions so they run and search for mods for it.Am not saying that is a bad thing but i suggest that you look for tested plugins and mods.Don't just pick up any mode or plugin that is doing the things you are want to mod on your site,check the security part of it also.Mods and plugins are natural sources of bugs,main reason for this is that most of those mods and plugins are done precisely by users who are unsatisfied by some options of their script and they have no clue about safe programing.Its always better to use mods and plugins that are made officially by the script company or they are well tested.
I hope this part gave you at least some directions on who to start webmastering safe.and that now you will also consider about safe side of the story
Twitter
Myspace
Mister Wong
Digg
Del.icio.us
Reddit
StumbleUpon
Slashdot
Furl
Yahoo
Blogmarks
Technorati
Newsvine
Blinkbits
Googlize this
Blinklist
Facebook
Wikio