How to Handle Website Attacks Your Security May Not See Coming – eWeek

How to Handle Website Attacks Your Security May Not See Coming – eWeek

This is carried out by sending a large amount of innocent-looking traffic to the Website. All it takes are just a few thousand requests per second to kill most of today's application stacks. If there is just an order of magnitude more, even the servers …
See all stories on this topic »

Skyword raises $6.7M to expand marketing content biz

Skyword, whose founder and CEO is Tom Gerace, seeks to help clients lure in search and social Web traffic. Kyle Alspach: VC Editor- Boston Business Journal: Email | Twitter | Google+. Boston-based Skyword, which provides Web content to help large …
See all stories on this topic »

New Hampshire Internet Marketing Company Expands to Offer Full Exposure …

Industrial Traffic, a veteran provider of internet marketing and search engine optimization services has announced plans to establish a new division and expand the firm's services. Industrial Traffic's announcement to unveil a new identity under the …
See all stories on this topic »

Popular Questions

How can you handle website attacks your security may not see coming, as discussed by eWeek?

Start by assuming that a breach can bypass a single security control. Monitor login activity, administrator changes, unusual traffic, file modifications, and unexpected database requests for signs of compromise. Keep web applications, plugins, servers, and security tools patched so attackers have fewer known weaknesses to exploit. Maintain tested backups so the site can be restored without relying on compromised systems.

What should you do first when facing a website attack your security may not see coming?

Contain the incident by isolating affected systems or restricting suspicious accounts and traffic. Preserve logs, alerts, altered files, and other evidence before deleting or rebuilding anything. Change exposed credentials, especially administrator, hosting, database, and API passwords, from a clean device. Then determine the attack’s entry point and verify that no hidden access mechanisms remain.

How can businesses detect website attacks that their existing security may not see coming?

Use layered monitoring rather than depending only on a firewall or antivirus product. Review server and application logs, authentication events, DNS changes, outbound connections, and sudden shifts in traffic or resource usage. File-integrity checks and alerts for new administrator accounts can reveal activity that appears normal to automated defenses. Regular vulnerability scans and manual security reviews can also uncover gaps between the site’s real configuration and its expected baseline.

How do you prevent future website attacks that security measures may not see coming?

Apply least-privilege access so compromised accounts cannot control the entire website or hosting environment. Require multifactor authentication for administrative tools, segment critical services, and remove unused plugins, accounts, and integrations. Test backups and incident-response procedures regularly instead of waiting for an emergency. Staff training, timely patching, and continuous review of alerts should complement technical controls rather than replace them.

Scroll to Top