<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>New Winnipeg Web Hosting</title>
	<atom:link href="http://www.newwinnipeg.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.newwinnipeg.net</link>
	<description>Canadian Web Hosting</description>
	<lastBuildDate>Wed, 08 May 2013 19:13:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>WordPress Plugin Security Vulnerability</title>
		<link>http://www.newwinnipeg.net/blog/2013/04/wordpress-plugin-security-vulnerability/</link>
		<comments>http://www.newwinnipeg.net/blog/2013/04/wordpress-plugin-security-vulnerability/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 23:16:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.newwinnipeg.net/?p=3615</guid>
		<description><![CDATA[<p>A security vulnerability has been discovered in two popular plugins for the content management system WordPress. The vulnerability affects the plugins WP Super Cache in version 1.2 and older as well as W3 Total Cache in version 0.9.2.8 and older. Adversaries may execute program code on servers using one of these plugins and e.g. install [...]</p><p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/wordpress-plugin-security-vulnerability/">WordPress Plugin Security Vulnerability</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></description>
				<content:encoded><![CDATA[<p><img class="alignright  wp-image-3104" alt="Wordpress Web Hosting" src="http://www.newwinnipeg.net/wp-content/uploads/2011/07/wp.gif" width="60" height="60" />A security vulnerability has been discovered in two popular plugins for the content management system WordPress.</p>
<p>The vulnerability affects the plugins <strong>WP Super Cache</strong> in version 1.2 and older as well as <strong>W3 Total Cache</strong> in version 0.9.2.8 and older. Adversaries may execute program code on servers using one of these plugins and e.g. install malicious software.</p>
<p>If you use WP Super Cache or W3 Total Cache, you should update the plugins immediately or disable them.</p>
<p>We are notifying our customers using these plugins by telephone this evening  (6:30pm CST forward) to alert them of this vulnerability. If you haven&#8217;t received a phone call from us, you are safe. Most of all, <strong>no security breach has taken place</strong>, we&#8217;re just urging people to disable or upgrade as a precaution. If we can&#8217;t reach you, we will just delete the plugin folder as a precaution.</p>
<p>See here for more info: <a href="http://www.acunetix.com/blog/web-security-zone/wp-plugins-remote-code-execution/" target="_blank">http://www.acunetix.com/blog/web-security-zone/wp-plugins-remote-code-execution/</a></p>
<p>&nbsp;</p>
<p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/wordpress-plugin-security-vulnerability/">WordPress Plugin Security Vulnerability</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.newwinnipeg.net/blog/2013/04/wordpress-plugin-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Secure Your Web Site from Hackers</title>
		<link>http://www.newwinnipeg.net/blog/2013/04/how-to-secure-your-web-site-from-hackers/</link>
		<comments>http://www.newwinnipeg.net/blog/2013/04/how-to-secure-your-web-site-from-hackers/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 00:10:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Control Panel]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.newwinnipeg.net/?p=3560</guid>
		<description><![CDATA[<p>We posted what we’re doing about Web Security a couple days ago. Now here’s what you can do to keep your web site secure: Keep strong passwords A strong password is the easiest and strongest move you can make. It is our policy that all passwords should include a minimum strength score of 50% as [...]</p><p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/how-to-secure-your-web-site-from-hackers/">How to Secure Your Web Site from Hackers</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></description>
				<content:encoded><![CDATA[<p><img class="wp-image-2876 alignright" alt="Security is important" src="http://www.newwinnipeg.net/wp-content/uploads/2012/10/security_lock.png" width="62" height="68" />We <span style="text-decoration: underline;"><a title="What We Are Doing About Web Security" href="http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/">posted what we’re doing about Web Security</a></span> a couple days ago.<br />
Now here’s what you can do to keep your web site secure:</p>
<h3><b>Keep strong passwords</b></h3>
<p>A strong password is the easiest and strongest move you can make.</p>
<p>It is <a title="Password Policy" href="http://www.newwinnipeg.net/blog/2013/02/password-policy/"><span style="text-decoration: underline;">our policy</span></a> that all passwords should include a minimum strength score of 50% as measured using this tool: <span style="text-decoration: underline;"><a href="https://www.newwinnipeg.net/password/">https://www.newwinnipeg.net/password/</a></span></p>
<p>Most tools in our Control Panel include a password generator to help you create strong passwords. Otherwise, create a password that includes a word that can’t be found in the dictionary and liberally pepper it with numbers and non-alphabetic symbols like #@$ or %.</p>
<p><a href="http://www.newwinnipeg.net/wp-content/uploads/2011/07/password02.png"><img class="aligncenter" alt="Password Generator" src="http://www.newwinnipeg.net/wp-content/uploads/2011/07/password02.png" width="456" height="392" /></a></p>
<p><strong>Strong password tips:</strong></p>
<ul>
<li>Avoid dictionary words</li>
<li>Use a combination of letters, numbers, and special characters</li>
<li>Use more characters (7+)</li>
<li>Avoid using one password for all your logins</li>
<li>Avoid logging in from public computers</li>
<li>Change your password every few months</li>
</ul>
<div class="woo-sc-hr"></div>
<h3><b>Regularly scan your computer for viruses</b></h3>
<p>A common way for a web site to be infected is through an infected computer. Just as we scan our servers for viruses, you should be doing the same.</p>
<p>Here are some anti-virus software links for both PCs and Macs.</p>
<ul>
<li><span style="text-decoration: underline;"><a href="http://www.microsoft.com/security/pc-security/malware-removal.aspx" target="_blank">Malicious Software Removal Tool</a></span></li>
<li><span style="text-decoration: underline;"><a href="http://windows.microsoft.com/en-us/windows/security-essentials-download" target="_blank">Microsoft Security Essentials</a></span></li>
<li><span style="text-decoration: underline;"><a href="http://macscan.securemac.com/download.php">MacScan</a></span></li>
<li><span style="text-decoration: underline;"><a href="http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx">Sophos antivirus for Macs</a></span></li>
<li><span style="text-decoration: underline;"><a href="http://click.linksynergy.com/fs-bin/click?id=XxPR1/MuEFg&amp;offerid=179852.10000046&amp;type=3&amp;subid=0" target="_blank">Protect your PC with the McAfee 2013 product line up &#8211; get 50% off!</a></span></li>
</ul>
<div class="woo-sc-hr"></div>
<h3><b>Regularly update your web software</b></h3>
<p><img class="alignleft  wp-image-3104" style="margin-right: 12px;" alt="Wordpress Web Hosting" src="http://www.newwinnipeg.net/wp-content/uploads/2011/07/wp.gif" width="90" height="90" />Using WordPress to manage a web site is very popular because it’s easy to use. However that popularity also makes WordPress websites a target; hackers use a variety of ways to sneak in malware, viruses and malicious scripts into a WordPress website. WordPress updates its software to plug these leaks, usually every few weeks. It is critical that you keep such software up to date.</p>
<p>Always keep your web software up to date &#8211; including the core software, any themes and plugins.</p>
<p>If you’ve installed WordPress, or any web software, through our auto-installer or we have installed WordPress for you, you should be receiving email notices from us when updates become available. Otherwise, if you login to the Control Panel or the WordPress dashboard, you’ll see a notice to upgrade. You can also <span style="text-decoration: underline;"><a href="http://wordpress.org/extend/plugins/automatic-updater/" target="_blank">use this plugin</a></span> for WordPress to automatically update everything.</p>
<p>For customers managing several WordPress sites, we recommend using <a href="https://wpremote.com/" target="_blank"><span style="text-decoration: underline;">wpremote.com</span></a> to regularly update several sites, plugins and themes, at once.</p>
<p><b>Another option is to use our auto-update service. For an one-time fee of $49, we will update your web software for you. </b></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/how-to-secure-your-web-site-from-hackers/">How to Secure Your Web Site from Hackers</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.newwinnipeg.net/blog/2013/04/how-to-secure-your-web-site-from-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What We Are Doing About Web Security</title>
		<link>http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/</link>
		<comments>http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/#comments</comments>
		<pubDate>Tue, 16 Apr 2013 21:36:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.newwinnipeg.net/?p=3538</guid>
		<description><![CDATA[<p>In the last week, there has been a rash of brute force login attempts on WordPress sites and other distributed global attacks in recent weeks, with the intention of spreading malware (malicious software designed to gather sensitive information). Many webhosting companies seem to be unprepared for this, causing more panic among web users. We want [...]</p><p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/">What We Are Doing About Web Security</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></description>
				<content:encoded><![CDATA[<p><img class="size-full wp-image-3098 alignleft" alt="Secure Web Solutions" src="http://www.newwinnipeg.net/wp-content/uploads/2008/11/secure-remote-backup.png" width="64" height="64" />In the last week, there has been a rash of brute force login attempts on WordPress sites and other distributed global attacks in recent weeks, with the intention of spreading malware (malicious software designed to gather sensitive information).</p>
<p>Many webhosting companies seem to be unprepared for this, causing more panic among web users. We want to assure our hosting customers that we have had security measures in place since last year that have saved our customers from this concern.</p>
<div class="woo-sc-hr"></div>
<h3>Layered Bulletproof Security</h3>
<p>Our security system includes three firewalls; a network firewall, a server firewall and a web application firewall, all of which filters illegitimate traffic of all sorts.</p>
<p>Our security system also includes something called ModSecurity, which filters out bad login attempts to websites, email and other web services. This is so tight it usually locks out our own customers. When customers notice that they can’t connect to our servers, 99% of the time it’s because ModSecurity has locked them out for too many failed login attempts.</p>
<p>Last week, we setup a ModSecurity rule to block an IP address for 15 minutes after 10 failed WordPress login attempts once we had heard about the rash of brute force login attempts on WordPress sites affecting other hosts. Other ModSecurity rules are in place to permanently block repeated failed login attempts.</p>
<p>We also actively monitor a mixture of traffic patterns to known attack vector strategies and providing evasive action in the event of a DDoS attack. We also have third party monitoring services setup to review all web services; including SSH, FTP, HTTP and Email.</p>
<p>We have balanced all of this without compromising server performance.</p>
<div class="woo-sc-hr"></div>
<h3>Weekly Server Audits</h3>
<p>We employ extensive auditing of various web applications, configurations and patches, on a weekly basis, looking for vulnerabilities and weaknesses of our own software and hardware, preventing future attacks and issues.</p>
<p>Our weekly audits include scanning our servers for over 6000 known exploit script fingerprint matches, suspicious file names and types, illegal software installations and PHP/CGI/HTML upload scripts. All of our employees also follow a rigid protocol to enact a series of security measures if something odd is found.</p>
<div class="woo-sc-hr"></div>
<h3>Malware Prevention and Cleaning</h3>
<p>We’re seeing a rise of companies offering to clean malware for a cost, often costing more than our customers’ annual web hosting bills. There are also companies that offer secure hosting as a separate hosting service, which we feel is redundant.</p>
<p>Even if a web site hosted on our server gets infected with malware, we utilize an Apache symlink security patch, which prevents the malware from “leaking” into other accounts.</p>
<p>We scan our servers weekly for malware and if found, we clean it out for free. This is one of dozens of features included for free with our web hosting services.</p>
<div class="woo-sc-hr"></div>
<h3>We are always working</h3>
<p>The Internet is a 24-hour environment. We host hundreds of web sites for customers who do business across all time zones. Whether it’s 3am or 3pm, we are always working.</p>
<p>Hackers often rely on the fact that most hosting companies have available technical support during banking hours and hit servers in the middle of the night. We have always been a 24-hour business so when hackers try to get us in the middle of the night, we’ve been available to squash these attempts.</p>
<div class="woo-sc-hr"></div>
<h3>We backup our servers nightly</h3>
<p>Even in the worst-case scenario, we have your back.</p>
<p>It’s a bit more work than just providing web hosting services, but this extra work is a life saver if you accidentally delete your web site without a local copy.</p>
<p>Many WordPress users are being advised to keep backups of their sites before installing new plugins, which is fine but in most cases unnecessary as we already have your sites backed up, every night.</p>
<div class="woo-sc-hr"></div>
<p>There are over a dozen other initiatives we’ve undertaken in the past two years that have saved us from a lot of disasters that have struck our competitors, however for security reasons we cannot disclose what these are.</p>
<p>We have always been reluctant to publish details about our security system and measures, so if you are a current hosting customer of ours and you have questions about this or anything related to your hosting account with us, <a title="Contact Us" href="http://www.newwinnipeg.net/contact/"><strong><span style="text-decoration: underline;">please contact us</span></strong></a>.</p>
<p>If you’re not a customer, ask your web host what they are doing about this. If you’re not happy with your current web hosting provider, consider hosting your site with us – we can migrate your web site over to us for free!</p>
<p>&nbsp;</p>
<p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/">What We Are Doing About Web Security</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.newwinnipeg.net/blog/2013/04/what-we-are-doing-about-web-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hardware and Software Update</title>
		<link>http://www.newwinnipeg.net/blog/2013/04/hardware-and-software-update/</link>
		<comments>http://www.newwinnipeg.net/blog/2013/04/hardware-and-software-update/#comments</comments>
		<pubDate>Thu, 11 Apr 2013 02:38:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Control Panel]]></category>
		<category><![CDATA[RAM]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Webdisk]]></category>
		<category><![CDATA[Webmail]]></category>

		<guid isPermaLink="false">http://www.newwinnipeg.net/?p=3532</guid>
		<description><![CDATA[<p>On Thursday, April 11th, from 11:00pm to 11:15pm CDT, we will be updating our cPanel software, as well as updating: Perl 5.14  Apache 2.4  Roundcube 0.8.5  MySQL 5.5.30 phpMyAdmin 3.5.5 Rails 2.3.18 Access to cPanel and Webmail may be limited during this update window. Later this night, from 12:15am to 12:30am CDT, we will be updating the [...]</p><p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/hardware-and-software-update/">Hardware and Software Update</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>On Thursday, April 11th, from 11:00pm to 11:15pm CDT, we will be updating our cPanel software, as well as updating:</p>
<ul>
<li><span style="font-size: 13px; line-height: 19px;">Perl 5.14 </span></li>
<li><span style="font-size: 13px; line-height: 19px;">Apache 2.4 </span></li>
<li><span style="font-size: 13px; line-height: 19px;">Roundcube 0.8.5 </span></li>
<li>MySQL 5.5.30</li>
<li>phpMyAdmin 3.5.5</li>
<li><span style="font-size: 13px; line-height: 19px;">Rails 2.3.18</span></li>
</ul>
<p>Access to cPanel and Webmail may be limited during this update window.</p>
<p>Later this night, from 12:15am to 12:30am CDT, we will be updating the RAM on the &#8216;webhost&#8217; server. We expect there may be some downtime while this occurs during this 15-minute window.</p>
<p>&nbsp;</p>
<p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/hardware-and-software-update/">Hardware and Software Update</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.newwinnipeg.net/blog/2013/04/hardware-and-software-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Server Updates</title>
		<link>http://www.newwinnipeg.net/blog/2013/04/server-updates/</link>
		<comments>http://www.newwinnipeg.net/blog/2013/04/server-updates/#comments</comments>
		<pubDate>Thu, 04 Apr 2013 21:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Server]]></category>

		<guid isPermaLink="false">http://www.newwinnipeg.net/?p=3509</guid>
		<description><![CDATA[<p>On Friday, April 5th and Saturday, April 6th, from 7pm to 11pm CST, we will be making some minor updates to our servers &#8211; both hardware and software updates. No downtime or service interruption is expected. &#160; &#160;</p><p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/server-updates/">Server Updates</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>On Friday, April 5th and Saturday, April 6th, from 7pm to 11pm CST, we will be making some minor updates to our servers &#8211; both hardware and software updates. No downtime or service interruption is expected.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a href="http://www.newwinnipeg.net/blog/2013/04/server-updates/">Server Updates</a> appeared first on <a href="http://www.newwinnipeg.net">New Winnipeg Web Hosting</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.newwinnipeg.net/blog/2013/04/server-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
