In today’s digital landscape, ensuring the security of your website is crucial. With XeonBD’s comprehensive SiteLock web security solutions, you can protect your website from vulnerabilities and attacks, allowing you to focus on your business.
SiteLock monitors your website 24×7 for vulnerabilities and attacks, which means you can worry less about your website and more about your business.
Over 70% of customers look for a sign of security before providing personal details online. The SiteLock Trust Seal not only re-assures customers but also boosts sales.
You don’t need technical expertise to install and set up SiteLock for your website. SiteLock is cloud-based and starts scanning your website and email instantly.
SiteLock screens every aspect of your web presence daily to identify security gaps. It not only checks your website, email and applications but also search engine blacklists and spam filters.
SiteLock’s 360 degree scan and powerful firewall identify advanced vulnerabilities before they can be exploited to damage your web presence, thus putting you one step ahead of hackers, always!
SiteLock not only identifies threats but also fixes them for you automatically. This way, SiteLock works in the background to protect your website, while it’s business as usual for you and your customers.
Vulnerabilities are detected immediately with the use of TrueShield™ virtual patching technology. By evaluating your website’s request SiteLock applies all necessary repairs automatically.
SiteLock always scans a website’s IP and domain against the leading Email spam database to check if it’s listed as a spammer. It also prevents your website or service is sending or being referenced in spam emails.
Obsolete or defenseless applications are the most popular way for hackers to gain access to websites and data. The SiteLock Application Scan checks website applications to verify they are up-to-date and free from vulnerabilities.
The Network Scan checks thousands of server ports to ensure that only the appropriate ports for the desired services are open. Customers are alerted of any high-risk visitor traffic. SiteLock creates a secured field around your website.
By using SiteLock, your impotent file will be always secure. SiteLock configured such deep scanning experiences. If there is anything wrong or has been any change, you will be instantly alerted. It will help you to prevent any kind of unauthorized edits before they cause any damage.
There are many malware sites. Sitelock monitors search engines blacklist and checks their own database of 7000+ malware sites. Actually SiteLock assure that your site is no more linked or blacklisted. Through this process, SiteLock boosts your site’s organic traffic and ranking.
SQL Injection is one of the most common vulnerabilities. The SiteLock SQL Injection Scan penetrates a site with SQL injection methods to find vulnerabilities. This prevents leaking data to hackers.
Attackers upload a custom coded, malicious file on a website or server using a script. The vulnerability exploits the poor validation checks in websites and can eventually lead to unintended code execution on the server or website.
Cross-Site Scripting is another common vulnerability that can be used to steal visitor’s data or trick visitors into providing data to third parties. On that particular case, SiteLock checks for susceptibilities and notifies customers of any problems.
Security misconfiguration flaws give hackers unauthorized access to system data via default accounts, unused pages, unpatched flaws, unprotected files and directories.
It is an ongoing attack, which forces the ultimate user to perform unwanted actions on a web application. CSRF attacks specifically target a state changing requests. SiteLock also prevents this attack.
Due to improper validation, websites often redirect users to other pages using untrusted data to determine the destination. This allows attackers to redirect victims to phishing or malware sites, or use forwards to access unauthorized pages.
It is a common type attack. It occurs when a developer published a reference to an inner implementation object, such as the file, directory or database key. Short of access control check or other defense, this types of attackers can control these references to access unauthorized data.
Often, application functions related to authentication and session management are not implemented correctly, allowing hackers to steal passwords, keys, tokens, or exploit other implementation flaws to assume users’ identities.
Insecure Cryptographic Storage isn’t a single vulnerability, but a collection of vulnerabilities that compromise data storage. Usually, this collection involves encryption of very sensitive data. Known causes are incorrect encryption of data, improper key storage and management, using known bad algorithms or using your own insecure cryptography.
Applications often fail to authenticate, encrypt and protect the confidentiality of network traffic. Some use weak algorithms, expired or invalid certificates or use them incorrectly. This allows hackers to “eavesdrop” on online exchanges. An SSL certificate can also neutralize this threat.
The global leader in website security, SiteLock scans over 5 million websites every day for malware and vulnerabilities. SiteLock uses such an instant 360’s scanning tools that evaluate your website both from the outside-in and the inside-out to analyze your website and notify you instantly if any threat detected.
SiteLock SMART, threat removal tools, provides full website analysis to detect and remove malicious files and code. Cross-Site Scripting (XSS) Scan, Daily FTP SMART Scan, Daily vulnerability scans, CDN (Content Delivery Network) website performance, Reputation monitoring, Verifiable Trust Seal, Identifies loopholes or vulnerabilities in your code .
SiteLock is a cloud-based, website security solution for small businesses. It works as an early detection alarm for common online threats like malware injections, bot attacks etc. It not only protects websites from potential online threats, but also fixes vulnerabilities. Features include:
Note
SiteLock is only meant for websites and not for a personal computer or laptop.
An SSL certificate is used only to encrypt a connection between the browser and server to safely transmit sensitive information. However, SiteLock actually protects the database where this information is stored, scans your website files and applications, protects from data breaches and spreading of viruses/malware. These functionalities are not provided by an SSL certificate.
SiteLock is a cloud-based service and does not require any installation. Once provisioned for your website, it automatically starts scanning your website using the basic scans. To use the advance features, some amount of configuration is required:
TrustSeal – requires minimal installation
SMART Scan – requires user to input FTP details in the SiteLock Panel
basic firewall
Firewall – requires addition of an A record
CDN – requires addition of a CNAME record
SiteLock badge or TrustSeal is a image that can be displayed on your website to assure users that your website is secure and malware-free. Since SiteLock performs all scans daily, the TrustSeal is update everyday to indicate that all scans have passed Note
The badge is displayed only when no issues are found during the website scan.
Deep 360-Degree Site Scan checks all files susceptible to threats, including .css files, .js files, .jpg, .png and other image files and others. It performs a deep scan checking for anything that could turn into a security issue.
Available types of scan include:
All these scans are part of the Deep 360-Degree Site Scan. The availability and frequency (daily or one-time) of these scans differ from Plan to Plan.
If a scan fails, site visitors will not be alerted to any problem. The TrustSeal will simply continue to display the last date when all scans were passed. If the site owner fails to rectify the problem, within a few days SiteLock will remove the TrustSeal from the site. The TrustSeal will never indicate that a website has failed a scan.
The Firewall is pre-configured, and no options are available within the SiteLock Panel to manage it. However, in the higher end Plans, users can configure certain aspects of the Firewall.
Search engines use spiders to crawl and index websites. SiteLock’s Firewall can distinguish good bots from bad bots and hence will not block search engines from indexing the site.
A Content Delivery Network is a set of servers, spread across the world that cache your website. When a user requests your website, the server closest to the user’s location will serve those requests. This in turn serves the website faster, thus speeding up its performance. Note Faster load times not only improve user experience but also contribute to better website ranking, as search engines take load time into account while ranking a website.
You need to add a CNAME record to a sub-domain (www.mysite.com) to redirect to SiteLock’s CDN Note A CNAME record should always be added to a sub-domain and not the primary domain, as it might clash with an MX record set up on the primary domain, thus hampering the email.
No. All notifications are sent from our system.
SiteLock is compatible with all types of hosting purchased either from XeonBD or elsewhere.
No. A single SiteLock Order can be used for only a single domain name. Hence, separate SiteLock Orders need to purchased for domain names individually. However, all SiteLock Orders belonging to the same user can be managed from a single SiteLock Panel.
Secure Malware Alert and Removal Tool (SMART), if enabled, performs an in-depth site scan and automatically removes malicious code from files on the site. SiteLock makes calls to the web server and replicates the website files on their secure servers and scans the contents thoroughly to identify malicious code or vulnerabilities. In the course of doing this, it can also remove the malicious code from the files, to prevent further damage.
You can choose to not allow SMART to remove any code. In that case, you will only be notified of the vulnerability identified, and you will need to manually check / remove it. Note
SiteLock provides a month’s worth of change logs for your website. You can always restore the previous version of the page / website. You then need to manually check the highlighted code for any malicious components and remove them yourself.
It might be happen that certain code on the website looks vulnerable but it is still doing what you intended it to do. If so, you can use the Report a False Positive option in the SiteLock Panel and SiteLock will ignore that vulnerability moving forward.
The purpose of this verification is to ensure that the user indeed owns and controls the website.
Instructions for these options are available in the SiteLock Dashboard.
Business verification is a service offered by SiteLock where it verifies the phone number and physical presence of a business. This is typically conducted to assure online users that a business actually exists and it is not a fly-by-night setup. This consists of:
Note If you want to display your contact information on the TrustSeal, it is necessary to verify your business details.
SiteLock’s Reputation Monitoring consists of the following components:
SiteLock offers a basic firewall to help block bot traffic which may harm the website. On logging into the SiteLock Dashboard, you can see a graph of your website’s traffic which reports human visits and bot visits.
To use SiteLock’s Firewall, you need to add an A record to your domain name in order to point to SiteLock’s servers where the Firewall is installed. This way, all traffic coming to the website is routed through the Firewall.
You are required to specify the IP address of your website in the SiteLock Panel so that after routing your traffic through the Firewall, SiteLock can divert it back to your website.
There is no way to access the SiteLock Panel directly through any URL. It can only be accessed from the SiteLock Management page from within the XeonBD’s management panel.
We are not offering any Money Back Guarantee for SiteLock Orders.
You can upgrade or downgrade your SiteLock Order from your XeonBD’s clients area..
On receiving a threat alert, login to the SiteLock Panel and view the details of the threat. Then, you may:
SiteLock probes your site to determine if fields and forms on your site are vulnerable to attempts by hackers looking to exploit these forms to gain access to your data. This will result in attempts to submit forms on your website with encoded data. If you wish to stop receiving these e-mails or entries, you may want to do some validation on the fields within your form to ensure that data is being submitted in the correct formats before triggering e-mails or database inputs. Since SiteLock inserts data that would not likely be valid for any fields on your site, these validation measures should stop you from getting these empty e- mails or entries. It is also a good coding and security practice to make sure your website visitors are providing the correct data in the expected formats.