{"id":25608,"date":"2026-09-05T02:46:28","date_gmt":"2026-09-04T23:46:28","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/preventing-malware-infection\/"},"modified":"2026-09-05T02:46:28","modified_gmt":"2026-09-04T23:46:28","slug":"preventing-malware-infection","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/preventing-malware-infection\/","title":{"rendered":"Preventing malware infection"},"content":{"rendered":"<p>\n      The price of freedom from malware is eternal vigilance. This article contains tips and<br \/>\n      pointers for preventing malware infection. However, it is by no means exhaustive, and Google<br \/>\n      encourages website owners to conduct more thorough research as well.\n    <\/p>\n<h2 id=\"monitoring-your-site-health\" tabindex=\"-1\">Monitoring your site health<\/h2>\n<p>\n      Many of the features of Search Console can help you identify potential problems. For example:\n    <\/p>\n<ul>\n<li>\n        Try a search on Google with the<br \/>\n        <a href=\"https:\/\/support.google.com\/websearch\/answer\/2466433\" class=\"external-link\"><code>site:<\/code> search operator<\/a><br \/>\n        to see what pages Google has found on your site. It&#8217;s always a good idea to do this<br \/>\n        periodically to see whether anyone has snuck unexpected pages or content on your site. If<br \/>\n        you see unknown pages on your site, or topics that you didn&#8217;t write, you may have been<br \/>\n        hacked. If you&#8217;re not already familiar with the <code>site:<\/code> search operator, it&#8217;s a<br \/>\n        way for you to restrict your search to a specific site. For example, the search<br \/>\n        <a href=\"https:\/\/www.google.com\/search?q=site%3Asite:developers.google.com\" class=\"external-link\"><code>site:developers.google.com<\/code><\/a><br \/>\n        will return results only from the Google Developers site.\n      <\/li>\n<li>\n        The<br \/>\n        <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101\" class=\"external-link\">Security Issues report<\/a><br \/>\n        shows any hacked pages that Google has identified on your site, and instructions on how to<br \/>\n        fix the problem.\n      <\/li>\n<li>\n        If Google detects malware on your site, you&#8217;ll see a notification in the<br \/>\n        <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9388335\" class=\"external-link\">message panel in<br \/>\n        Search Console<\/a>. To ensure that you&#8217;re notified quickly, you can have your messages<br \/>\n        <a href=\"https:\/\/support.google.com\/webmasters\/answer\/140528\" class=\"external-link\">forwarded to your email account<\/a>.\n      <\/li>\n<\/ul>\n<h2 id=\"security-checklist\" tabindex=\"-1\">Security checklist<\/h2>\n<p>In addition to monitoring your site regularly, we also recommend the following:<\/p>\n<h3 id=\"all-website-owners\" tabindex=\"-1\">All website owners<\/h3>\n<ul>\n<li>\n        <b>Choose good passwords.<\/b><br \/>\n        The <a href=\"https:\/\/support.google.com\/accounts\/answer\/32040\" class=\"external-link\">Google account guidelines<\/a><br \/>\n        are helpful.\n      <\/li>\n<li>\n        <b>Pick third-party content providers very carefully.<\/b><br \/>\n        Make sure that third-party apps and ads on your site are from trusted and legitimate<br \/>\n        sources. A trusted and legitimate source provides support and contact information on their<br \/>\n        website.\n      <\/li>\n<li>\n        <b>Contact your hosting company or publishing platform for support.<\/b><br \/>\n        Most companies have helpful and responsive support groups and\/or security pages. If a<br \/>\n        security page or site has an RSS feed, subscribe to it to make sure you stay up to date.\n      <\/li>\n<li>\n        Keep all of your computers safe. Especially when working on a website, make sure that your<br \/>\n        local workstation has up-to-date software, is clean from viruses, trojans, or similar malware<br \/>\n        and has recently updated anti-virus software installed.\n      <\/li>\n<\/ul>\n<h3 id=\"website-owners-with-server-access\" tabindex=\"-1\">Website owners with server access<\/h3>\n<ul>\n<li>\n        <b>Check your server configuration.<\/b><br \/>\n        Apache has some<br \/>\n        <a href=\"https:\/\/httpd.apache.org\/docs\/2.4\/misc\/security_tips.html\" class=\"external-link\">security configuration tips<\/a><br \/>\n        on their site and Microsoft has some<br \/>\n        <a href=\"https:\/\/www.google.com\/search?q=microsoft+iis+security+best+practices\" class=\"external-link\">tech center resources for IIS<\/a><br \/>\n        on theirs. Some of these tips include information on directory permissions, server-side<br \/>\n        includes, authentication, and encryption.\n      <\/li>\n<li>\n        <b>Make a backup copy of your <code>.htaccess<\/code> file<\/b><br \/>\n        (or other access control mechanisms depending on your website platform). Use your backup<br \/>\n        file to recover if the following fails. Be sure to delete the backup file once you are<br \/>\n        finished.\n      <\/li>\n<li>\n        <b>Stay up-to-date with the latest software updates and patches.<\/b><br \/>\n        There are lots of tools that make building a website easy, but each one adds some risk of<br \/>\n        being exploited. A common pitfall for many website owners is to install a forum or blog on<br \/>\n        their website and then forget about it. Much like taking your car in for a tune-up, it&#8217;s<br \/>\n        important to make sure you have all the latest updates for any software program you have<br \/>\n        installed. Make a list of all the software and plug-ins used for your website, and keep<br \/>\n        track of the version numbers and updates. Even if you&#8217;re diligent and keep all your website<br \/>\n        components updated, you may still be vulnerable if your web hoster has not installed the<br \/>\n        most recent operating system patches. This problem affects not only small sites; there have<br \/>\n        been warnings on the websites of banks, sports teams, and corporate and government websites.\n      <\/li>\n<li>\n        <b>Keep an eye on your log files.<\/b><br \/>\n        Making this a habit has many great benefits, one of which is added security. For example,<br \/>\n        unfamiliar URL parameters (like <code>=http:<\/code> veya <code>=\/\/<\/code>) or spikes in<br \/>\n        traffic to redirect URLs on your site may indicate that a hacker is exploiting<br \/>\n        <a href=\"https:\/\/alienroad.com\/google-bilgi-bankasi\/spam-policies\/\">open redirects<\/a>. Also, bear<br \/>\n        in mind that hackers often try to alter log files. Take measures to protect these files from<br \/>\n        attack. For example, you can move these files from their default location, making it harder<br \/>\n        for hackers to find them.\n      <\/li>\n<li>\n        <b>Check your site for common vulnerabilities.<\/b><br \/>\n        Avoid having directories with open permissions. This is like leaving the front door to your<br \/>\n        home wide open.<\/p>\n<p>\n          Also check for any<br \/>\n          <a href=\"https:\/\/www.owasp.org\/index.php\/Cross_Site_Scripting\" class=\"external-link\">XSS<\/a><br \/>\n          (cross-site scripting) and<br \/>\n          <a href=\"https:\/\/owasp.org\/www-community\/attacks\/SQL_Injection\" class=\"external-link\">SQL injection<\/a> vulnerabilities.\n        <\/p>\n<\/li>\n<li>\n        <b>Use secure protocols.<\/b><br \/>\n        Google recommends using SSH and SFTP for data transfer, rather than plain text protocols<br \/>\n        such as telnet or FTP. SSH and SFTP use encryption and are much safer.\n      <\/li>\n<li>\n        <b>Keep up to date on the latest security news.<\/b><br \/>\n        The<br \/>\n        <a href=\"https:\/\/security.googleblog.com\/\" class=\"external-link\">Google Security Blog<\/a><br \/>\n        provides useful information about online security and safety, as well as pointers to other<br \/>\n        resources. The government site<br \/>\n        <a href=\"https:\/\/us-cert.cisa.gov\/\" class=\"external-link\">US-CERT<\/a><br \/>\n        (United States Computer Emergency Readiness Team) provides technical security alerts and<br \/>\n        tips.\n      <\/li>\n<\/ul>\n<section background=\"grey\" header-position=\"top\">\n<p>\n    If you&#8217;re a Search Console user and are having trouble with persistent or unfixable security issues on your site, you can let us know.\n      <\/p>\n<p align=\"center\"><a class=\"button button-primary\" href=\"https:\/\/support.google.com\/webmasters\/contact\/report_security_issues\" class=\"external-link\">Report a security issue<\/a><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>From monitoring site health to reviewing our website security checklist, this guide contains tips for how to prevent and avoid malware infections.<\/p>\n","protected":false},"menu_order":135,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[699],"ar_kb_etiket":[],"class_list":["post-25608","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-preventing-and-monitoring-abuse"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25608\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27606"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=25608"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=25608"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=25608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}