CloudFlare Partnership
We are pleased to announce our partnership with CloudFlare.
We have chosen CloudFlare as a partner as they have developed an effective yet simple solution which protects and accelerates websites. Once your website is a part of the CloudFlare community, your users will experience faster page load-times and improved performance.
What is CloudFlare?
CloudFlare is a CDN (Content Delivery Network) with a security layer.
CDN is a collection of servers which are distributed across many global locations to deliver your website content faster and more efficiently to your users. Depending on the users location, CDN selects the server which is nearest to the user and loads your website content from that server.
It works in conjunction with your existing hosting service and caches static content for your site. This lowers the number of requests to your servers. There are several advantages in using the CloudFlare system.
Advantages of the CloudFlare system:
- Site Performance Improvement: CloudFlare has proxy servers located throughout the world. Proxy servers are located closer to your users, which means they will likely see page load speed improvements as the cached content is delivered from the closest caching box instead of directly from our server. There is a lot of research which shows that the faster the site, the longer a visitor stays
- Bot and Threat Protection: CloudFlare uses data from Project Honey Pot and other third party sources, as well as the data from its community to identify malicious threats online and stop the attacks before they get to your site. You can see which threats are being stopped through your CloudFlare dashboard https://www.cloudflare.com/your-websites.html.
- Spam Comments Protection: CloudFlare leverages data from third party resources to reduce the number of spam comments on your site
- Alerting Visitors of Infected Computers: CloudFlare alerts human visitors that have an infected computer that they need to take action to clean up the malware or virus on their machine
- Offline Browsing Mode: In the event that your server is unavailable, visitors should still be able to access your site since CloudFlare serves the visitor a page from its cache
- Lower CPU Usage: As fewer requests hit our server, this lowers the overall CPU usage of your account
- New Site Stats: You have good tools to evaluate human traffic coming to your site, but no insight into search engine crawlers and threats. With CloudFlare, now you do.
How does it work?
CloudFlare powered websites see a significant improvement in performance and a decrease in spam and other attacks. People view your site through an accelerated path that uses the shared security knowledge of thousands of other sites to automatically detect and block malicious traffic.
The end result being that your pages load faster and are more secure.
A reason to backup your backups
Australian domain registrar and web host Distribute.IT suffered an attack on Sat, 11th June. The company said: “The overall magnitude of the tragedy and the loss of our information and yours is simply incalculable; and we are distressed by the actions of the parties responsible for this reprehensible act.”
Unable to fulfil its role as an accredited registrar, auDA gave NetRegistry Pty Ltd its consent to acquire Distribute IT’s .au registrar accreditation and customer base on Wed, 22nd June.
The security attack was so sophisticated and calculated that customer data, emails and websites hosted on four of its servers were deemed by experts to be unrecoverable. Subsequently, Distribute.IT advised that 4800 accounts had been affected by the hack. The demise of Distribute.IT looks well and truly sealed.
Distribute.IT had always been a valuable supplier to Net Solutions. Alex, Carl and the rest of the team were always approachable, helpful and provided superb support. This is a devastating situation, and I sympathise with everybody who lost their content.
So what can we take away from this?
The domain names were largely under control with many resellers hitting the airwaves at whirlpool.net.au. Net Registry’s Larry Bloch and Brett Fenton were there to listen and offer support.
Some 4800 customer websites were totally wiped with no chance of recovery. Even though Distribute.IT had backed up data from their clients’ sites, all the backups were on-site and subsequently targeted by the attackers. Some customers found themselves scraping the ‘Way back machine’ to recover whatever they could.
What I can suggest is backup, backup and backup! Backup your data on the server, backup your data off-site and backup your data locally or to your computer. It’s not good enough that your only backup exists in the same place as your website does. Ask your web-host about backup options. It will more than likely cost you more money, but ask yourself what would it mean if you lost all your data and how much would you be prepared to pay to recover from a disaster such as Distribute.IT’s.
For CMS’s and Blogs use a tool like MarsEdit to write posts and duplicate them. There’s a lot of information and plugins out there to help you backup your data easily and seamlessly.
You cannot afford to be too over-protective of your data.
Google Places not friendly for P.O. Box users
This time last year Google announced that Google’s Local Business Centre will become Google Places. Now Google have made some changes which punishes small businesses who operate using P.O.Box. This may not have been the intent but certainly is the case for some.
It is not unusual for self employed individuals such as web-designers, plumbers and electricians to operate using a P.O.Box. They don’t want users to know where their office/bedroom is located if they must publish their home address. To simply assume that businesses who operate using a P.O. Box is illegitimate is just not helpful to small business owners, who are the very people that Google to help.
Lina Paczensky from Google explains this decision as follows:
“Google Places is meant to facilitate customer interaction with brick-and-mortar businesses and service providers. Therefore, the business owner or employee who is officially authorised to represent their particular business location must have a physical address in order to comply with our quality guidelines. P.O. Boxes are not considered accurate physical locations. Listings submitted with P.O. Box addresses will be removed.”
With a major shift towards online local search, a free business listing in Google Places is very helpful.
So what does one do? A few small business owners I know have simply lost their Google places listings as their address was a P.O.Box Numbers?
They were not given the opportunity or notified to edit their listing, instead it was removed and they had to go through the process of recreating a new listing. They need to lease an office or publich the location of their bedroom/office.
Since SMS verification has also removed during the application process, you need to wait for your postcard to arrive.
Have you suddenly found that your Google Places listing has been removed?
If so, we would love to hear from you.
cPanel Wildcard DNS Setup
Have you ever wanted to setup subdomains via your cPanel service, such that a keyword is the wildcard part of your domain? Something along the lines of:
* jacky.yourdomain.com
* johnny.yourdomain.com
* harry.yourdomain.com
You may be installing WordPress 3 to use the Multi Site features that will require wildcard DNS hosting. In any case your domain should be functioning and propagated before you attempt setting up a wildcard subdomain.
In cPanel Login to your account and look for your subdomain control panel applet.

Now you want to add a subdomain that will point to the location of your content. For WordPress 3.0 install choosing the directory with your .htaccess file as your target. If you only have one domain and site on your account you can point to your base public_html directory.
Click Create and you are ready to add subdomain hosting including WordPress 3.0 Website.
If you have problems because you are hosting many addon domains meaning many domain names with independent sites then you should make sure that the wildcard is pointing to the directory with WordPress 3.0 in it.
You will need to go into WordPress and enable your Network Options after you add your wildcard.
Please also see the cPanel’s website and review documentation .
SCAM Warning – Domain Renewal Group
We have received many complaints from our customers who have received letters from the Domain Renewal Group claiming to offer to renewal of their domain names they have registered. They obtain information about individual domain names that are close to expiry.
It is not unusual for individuals who are busy with their day to day work to overlook which registrar the domain was registered with. The Domain Renewal Group try to take advantage of this fact. They feel it is quite legitimate to catch people off guard and scam them for money. A quick google search on their company turned up lots of information about this scam. In fact all the results I see in Google are complaints about this company rather than any services they provide.
If you read the letter carefully, you realise that they are using an approach called slamming, which tricks you into switching your domains to another company. Specifically, they are highlighting each domain that is due to expire and that I risks associated with losing the domain name unless you renew with them. They don’t highlight any risks such as losing all your email and website when you switch over to them.
Although the letter states that it is not a bill, it has been designed to look like an invoice. An interesting aside is that they offer other variants of your domain name in the hope they can SCAM you registered other domains too.
If you receive a letter like this from Domain Renewal Group or from anyone else contact your own registrar or the person who maintains your website before parting with any money.
Revealing Email Headers
When a fraudulent phishing e-mail or scam, arrives in your mailbox, there is no danger to you unless you reply to the message. The ACCC’s SCAMwatch website provides information on common scams. The website has tips on how to protect yourself from scams and report them to the relevant agencies.
We encourage all customers to forward any and all spam to ACMA. In order for ACMA to do anything about the spam you have received, you must include the full email headers in the email that you forward.
Full e-mail headers are needed to investigate any phishing attempt so that the source of a message can be revealed. To retrieve the full headers from a message, you will need to locate it within your e-mail client. Instructions for locating and copying e-mail headers in different e-mail clients can be found at: www.spamcop.net.
Below is a quick set of instructions in how to reveal email headers in Outlook 2003 and Outlook 2007

- Open the offending email.
- Click on the word View in the menu bar.
- Select the option Options.
- The Message Options dialog will apear.
- Right-click on the text in the Internet Headerssection.
- A submenu will appear.
- Choose the option Select All.
- The text will appear in inverse video, indicating that it is selected.
- Right-click on the selected text.
- A submenu will appear.
- Choose the option Copy.
- Click on the Close button.
- The Message Options will disappear and you
will return to the offending email. Now you have the message in your buffer.
A Sample phishing mail
Below is a more detailed look at email headers, it is not for the faint hearted.
Return-Path: <(Aktiviere JavaScript, um die Email-Adresse zu sehen)> Envelope-To: (Aktiviere JavaScript, um die Email-Adresse zu sehen) Received: from [84.120.132.215] (helo=84-120-132-215.onocable.ono.com) by example.com with smtp (NetMail-SMTP 1.16); Sun, 10 Oct 2004 03:40:32 +0200 (CEST) Date: Sun, 10 Oct 2004 05:39:35 +0300 From: CitiBank <(Aktiviere JavaScript, um die Email-Adresse zu sehen)> MIME-Version: 1.0 To: (Aktiviere JavaScript, um die Email-Adresse zu sehen) Subject: CITIBANK REMINDER: UPDATE YOUR DATA
The sample above shows a very typical mail header. In this case it is even a so-called phishing e-mail, offering a link to a faked website which looks like the one of a bank, but then captures (fishes) your log-in data to use it for fraud. We have changed the recipient’s address to (Aktiviere JavaScript, um die Email-Adresse zu sehen) for privacy reasons. Let’s look at the header lines one by one.
Return-Path: This line is not created by the sender but inserted by the receiving e-mail server using the address behind MAIL FROM in the SMTP dialogue. It is not verified. In most cases (but not all) it is the same as in the From: header line which your e-mail client displays as the sender’s address. Since there is only one MAIL FROM during the SMTP dialogue, there should be only one Return-Path line. An empty address like <> is allowed if the mail is from a Mailer-Daemon or a similar automated sender which cannot receive answers.
Envelope-To: For routing the received e-mail to the intended recipient(s), many e-mail systems insert this line using the address(es) from RCPT TO in the SMTP dialogue. While this is not really necessary for mails where all recipients are behind To: or Cc:, it allows the correct routing even for a Bcc: addressed e-mail. Unfortunately, the syntax is not standardized. “X-Envelope-To:”, “Delivered-To:” or “X-Pop3-Rcpt:” are some alternative forms. Angle brackets around each address are optional.
Received: While our example shows only one Received line, two or more of them are typical for most e-mails. Each mail server the e-mail passes on its way from the sender to the recipient inserts its own. The topmost is the newest, created by the server nearest to you, and you should rely on this one only, since all following lines may be faked. If there is only one Received line in the header, the sender did not deliver it via the SMTP smarthost of his local provider, but sent it directly to your server or your provider, which is very typical for spam and viruses. The format of Received lines is not always exactly the same, but in most cases it consists of this information:
- IP address: If the topmost Received line is created by your local mail server or your provider, the true IP address of the sender is shown here (which is 84.120.132.215 in our sample above).
- HELO identification: The HELO command is used by the sending SMTP client to identify itself (…ono.com here, obviously an ISP in Spain). Note that HELO should display the reverse-DNS name of the IP, which surprisingly is the case in this phishing e-mail, but for many spam and virus mails it is just a fantasy name. If the IP address is not in your local LAN, a HELO name without dots is definitively faked. In the sample above, the sender apparently used a reverse DNS request to find out his local domain name in order to send a realistic HELO string.
- Mail server name and system: The line "by example.com with smtp (NetMail-SMTP 1.16)" shows the (or at least one) domain of the server receiving this e-mail, the protocol used (typically SMTP) and the server software (the NetMail SMTP module in this sample).
- Recipient (optional): The recipient’s address is sometimes given behind the keyword "for" in the Received line. This may be useful for BCC-addressed mails. If there is no Envelope-To line (or similar), then this may be the only place where the intended recipient address can be seen. However, this field is optional. Furthermore the SMTP standard only allows one address there, so this information is often suppressed for multi-addressed mails.
- Date and time: Assuming that the clocks of all systems involved are not too inaccurate, you can see when a specific server received this message. Note that the local time zones may be different. The difference to GMT/UTC is given as a signed 4-digit number. For instance, +0200 means 02 hours and 00 minutes earlier than UTC. Some systems add the name of the time zone in brackets for better readability. A few proprietary, typically American systems replace the number by the time zone name like EDT (Eastern
Daylight Time), but this is a bad idea since it is often ambiguous: EDT is valid in the US (UTC+4) as well as in Australia (UTC+11).
Date: The date and time when this e-mail was created. It is not necessarily the time when the message was actually sent to the Internet. The format is the same as the one used in Received: lines described above. Since it depends on the client’s system clock, it may be more inaccurate than the times in the Received lines created by well-adjusted servers.
From: The alleged sender of this e-mail. If an answer is requested to a different address than the one behind From:, a Reply-To: line is added with the address where an answer should go to. Both may be completely faked. It is crystal-clear that citibank.com would never send their mails over a cable access of ono.com in Spain. For most normal mails, the From: line shows the same address as the Return-Path information in the header, but this is not required. Typical From lines are (comments added in brackets):
From: CitiBank <(Aktiviere JavaScript, um die Email-Adresse zu sehen)> (as in sample above) From: "CitiBank" <(Aktiviere JavaScript, um die Email-Adresse zu sehen)> (quoted real name) From: (Aktiviere JavaScript, um die Email-Adresse zu sehen) (no real name given)
The From: address in the sample above is faked, of course: The word “antifraud” and the name of the bank are simply intended to confuse the recipient.
To:, Cc: Displays the recipients except the ones sent as Bcc. Some badly implemented clients even send a Bcc line, but this does not conform to the standard since Bcc addresses should not be visible to other recipients. When sending an e-mail, the SMTP dialogue uses RCPT TO for all destination addresses, so the things behind To and Cc (just as all the other content of the message header and body) are completely irrelevant and may be even faked. The possible address formats are the same as for From (see above), multiple addresses can be separated by commas.
Subject: The subject of the e-mail. It is interesting that it is uppercase-only in this sample; this fact could add some percent to a probability value that an e-mail is unwanted spam.
Avoid Fraud and Scams
Almost everyone will be the target of a scam at some time – you may have been already. Some scams are easy to spot, while others can happen without you even knowing it. It is designed to trick you into giving away your money or your personal details. Scams succeed because they look like the real thing and are crafted to appeal to your needs and desires.
Common scam include:
- lottery and competition scams
- investment or ‘get rich quick’ scams
- money transfer requests or ‘Nigerian’ scams
- banking and online account scams
- employment scams
The people who run these scams (scammers) are imaginative and manipulative; they know how to push the right buttons to produce the response they want.
Many scams originate from outside Australia and once money is sent overseas it is virtually impossible to recover.
SCAMwatch is a website run by the Australian Competition & Consumer Commission (ACCC). The aim of SCAMwatch is to provide information to consumers and small business about how to recognise, avoid and report scams.
Scams that are reported to SCAMwatch will be analysed by the ACCC. Many scams originate overseas or take place over the internet, making them very difficult to track down and prosecute. If you lose money to a scam, it is unlikely that you will be able to recover your loss. The ACCC publishes this website to help consumers recognise scams because prevention is definitely a better option when it comes to scams.
Some tips for protecting yourself from phone scams
- Be suspicious of unexpected calls and text messages.
- Hang up. Or text ‘STOP’ to unwanted messages.
- Don’t give your number to just anyone.
Some tips for protecting yourself from internet scams
- Keep your protection software up-to-date
- Don’t respond in any way to unsolicited emails
- If in doubt, delete
Google SEO Starter Guide
All webmasters want high search engine rankings to list their site on top of search engines search result pages. There are hundreds of sources providing information about search engine optimization to drive more site traffic. Google just made it simpler to master these SEO techniques.
Google webmaster tools has released an official Search Engine Optimization Starter Guide that covers many areas that webmasters might consider optimizing to get better Google ranking and indexing. Here is the index of contents that should interest you.
- Create unique and accurate page titles
- Make use of the ‘description’ meta tag
- Improve the structure of your URL’s
- Make your site easier to navigate
- Offer quality content and services
- Write better anchor texts
- Use heading tags appropriately
- Optimize your use of images
- Making effective use of Robots.txt
- Be aware of ‘nofollow’ tags for links
- Promoting your website in the right ways
- Make use of free webmaster tools
- Take advantage of web analytics services
Download the Official Google SEO Started guide (.pdf) today and see what Google expects from your site structure and functionality.
Brute Force Detection (BFD) in CPanel
We’ve all been faced with the problem of weak passwords. As much as you inform users about password security, they want to use something they can easily remember. So, we end up with passwords like ‘ilovesue’ and ‘spunky′. Even with the new password strength meters in cPanel, it is important to go that extra step to make sure that your users are protected, well, from themselves.
Net Solutions uses cPHulk which enables a brute force password protection system. With cPHulk, you can set a threshold for authentication attempts on services like POP3, cPanel, WHM, FTP, etc. After a certain amount of attempts, the attacker will no longer be able to authenticate.
BFD Protection is necessary as, there are literally thousands of attempts made every day to gain access to peoples accounts. Users will never notice as cPHulk works in the background blocking access to IP addresses originating from China, Taiwan, Russia, etc.
So while BFD may be seen as an inconvenience if you get locked out, imagine the risks of allowing someone else to gain access to your account by password guessing. What would you have to lose?
Account Level Blocks
This will block access to a specific account for a period of time. If you find yourself blocked and continue to try and authenticate while you are blocked, the time will get extended.
IP Address Level Blocks
This will block your IP address. Block of this type will prevent you from having any access to the server including access to CPanel itself.
Thresholds
Account Level
- How long an account is locked out when it reaches the failure limit: 5min
- Maximum Failures by account: 15
IP Address
- Number of minutes a remote IP is locked out when it reaches the failure limit: 15min
- Maximum Failures by remote IP Address:5
- Maximum Falures by remote IP before IP is blocked for two weeks:30
I got blocked from my own server by BFD! Now what?
In most cases once you have been blocked by your server’s BFD system the easiest way to regain access is to simply create a Support Ticket with our support team. (No need to feel embarrassed. We fix issues like this all the time!)
The vast majority of cases that our support department handles involving customers who are blocked by their own servers are due to FTP clients that contain a saved password. If someone in your company, group, organization, or household changes the password to that FTP account and doesn’t notify you to update your saved password it is quite easy to end up blocked by the server. Most FTP clients automatically reconnect several times if the initial attempt fails, and once your FTP client with the bad password attempts to login several times and fails the server’s BFD system will kick in and block your IP address.
Customers in an office environment that utilize a private network connected to the internet may find their entire office blocked by their server. This happens (usually in a small/home office situation) when multiple computers are sharing a single internet connection, meaning they also share the same public facing IP address. Once a single computer on that local network gets blocked by the server all of the other local computers will find themselves blocked as well.
While this can cause some initial panic there is no need for concern. Even if you are temporarily blocked by your own server that does not mean it is down. It may be ignoring your requests for a short while but it is still working away, handling the tasks from other visitors to your web site(s).
Publishing your website using Fireftp
The process of transferring a file from your computer to your website is often referred to as “uploading”. This guide only deals with how you can transfer a file to your web server using a free FTP client known as fireftp. Fireftp is a great add-on for the Firefox web browser. There are many other free FTP programs but this guide will only deal with fireftp.
What is FTP?
FTP stands for File Transfer Protocol. Both HTTP and FTP protocols deal with transferring data across the Internet. FTP is used to upload and download files from your computer to a web server. Download http://fireftp.mozdev.org
Once downloaded follow the the on-screen intructions to install fireftp.
Using Fire FTP
- Click on Tools the select FireFTP
- Once FireFTP is open follow these steps to Connect to your Server.
- Click on Manage Accounts
- Select New…
- Go to the "Account Name" field and enter the hostname (usually the website name, i.e cityofmonash.com)
- Go to the "Host" field and enter the hostname (as above)
- Go to the "Login" field and enter your FTP username as setup in VHCS2 (ie (Aktiviere JavaScript, um die Email-Adresse zu sehen))
- Go to the "Password" field and enter your FTP password (please note this is case sensitive
- Click OK to save the account information and to close the dialog.
- Click on "Connect" to establish a connection.
- Click OK on the FireFTP pop-up and fireftp will connect to the FTP server
Once you have Connected, you will find that the local files are on your left and the remote files on your right. You can click on a local file and press the arrow pointing to the right to upload a file to the server.
Similarly, you can click on a file on the right side and press the arrow pointing to the left to
download a file from the server to your computer.
Where should I publish the website content?
All website content files need to be placed in the htdocs directory or folder.
What filename should I use as the default page for my Website?
The web server will look for the following files when no page in the URL is provided.
index.html index.cgi index.pl index.php index.xhtml (all files are case sensitive)
What file permissions should I use?
The UNIX security model allows you to set different levels of access to a file for different groups of people. This allows you to let the web server modify a file via a CGI script, for instance, while preventing other users from having normal access to the file. There are three groups in terms of file access, and three different permission types they can receive.
File Permissions And Groups
The groups are:
- User – the ‘user’ group consists only of the owner of the file (your account, in most cases)
- Group – the ‘group’ group consists of the other users on the server — you can usually remove their permissions entirely if you think it is necessary
- Other – the ‘other’ group consists of everyone else — most importantly, the web server falls into the ‘other’ category
The potential permissions are:
- Read – the ‘read’ permission allows a user or program the ability to read the data in a file
- Write – the ‘write’ permission allows a user or program the ability to write new data into a file, and to remove data from it
- Execute – the ‘execute’ permission allows a user or program the ability to execute a file, if it is a program or a script
Setting Permissions
You can set permissions via FTP by right-clicking (clicking and holding for Mac users) on the file and select Properties in fireftp.
Most of your html files will do fine with a permission of 644 (Owner=Read+Write Group=Read Other=Read). Most script files will need a permission of 755 (Owner=Read+Write+Execute Group=Read+Execute Other=Read+Execute).
Can FireFTP resume downloads?
Yes it can. If you lose your connection, FireFTP will automatically try to reconnect and resume downloading. After this, you can resume a file just by trying to download it again. FireFTP will notice that you have a partial file already downloaded and will ask you whether you want to resume from where you left off click "Resume".
How do I rename a file/make a directory/delete files?
Right-click on the file lists. A context menu will appear showing the available functions you have, along with related keyboard shortcuts.
What is the "View on the Web" feature and what do you put in "Host" and "Prefix" for it to work?
The "View on the Web" feature is primarily designed for web developers so that they can preview images and webpages within FireFTP (using Firefox's latest Canvas technology). It can be found on the "Account Manager" dialog, under the Advanced tab.
If experiencing problems with your connection, follow these steps.
- Do you have the latest versions of FireFTP and Firefox? The latest version can be found at http://fireftp.mozdev.org/
- Are you behind a firewall? Try turning it off temporarily to see if it is the source of your problem. If so, you might have to configure your software to allow FireFTP to access the Internet.
- Does your server allow only active mode? Try turning off "Passive Mode" in FireFTP under your account's configuration options. This is found on the "Account Manager" dialog, under the Connection tab.
- Do you use a proxy? Try setting the proxy under Preferences in the Connections sub menu.
- Have you been able to connect with other FTP clients? Please check to see if the problem is reproducible with other FTP clients.
This should allow your FTP client to establish a connection.
Related Articles
- CloudFlare Partnership
- A reason to backup your backups
- WordPress.org Security Alert
- Why do websites need to be maintained?
- cPanel Wildcard DNS Setup
- SCAM Warning – Domain Renewal Group
- Geo-targeting by IP Address
- Brute Force Detection (BFD) in CPanel
- WordPress.org Security Alert
- Google Places not friendly for P.O. Box users
- Why do websites need to be maintained?
- What is this SEO thing anyway?
- WordPress 3 released
- Geo-targeting by IP Address
- Google SEO Starter Guide
- Publishing your website using Fireftp





