I would recommend an air gap, disabling autorun, removing the CD hardware, and any hardware used to connect to the internet. You could also remove any other hardware and uninstall the drivers you don't need such as a webcam.
I previously used KeePass and the password database corrupted one day. I would only use KeePass if you are comfortably keeping several backups using TrueCrypt and your system is compatible with it.
I prefer LastPass because it has more features that are valuable (I can use one tool/service instead of several), I can use it on all of my devices, it is very secure.
I would recommend using LastPass as a password manager. Here is some advice I recently wrote up on passwords.
In regards to Heartbleed, the Security Check that LastPass offers will help with that in terms of notifying you of the sites that you should change your passwords on since they were vulnerable to Heartbleed, but really all sites could be vulnerable to it, so I would recommend changing all your passwords fairly frequently over the next few months.
As long as the password is not contained within a list of commonly used words and isn't in the dictionary, length is the most important thing. The second most important thing I would say is using the widest variety of characters possible including lowercase letters, uppercase letters, numbers, and special characters.
You want to generate a secure password from a password generator such as GRC's Password Generator. I always generator my passwords to be 50+ characters but everything over 15+ characters will be fine.
Also, make sure you change your passwords every 3 months and don't share your password with anyone. Lastly, store your passwords securely using a password manager such as LastPass (https://lastpass.com/). You should have a strong master password with LastPass and use two factor authentication. You should also use two factor authentication with all of your other accounts that offer it.
If a site requires a secret question, make sure the answer to that question no one else would know or make it a password or phrase that you would remember. Don't reuse passwords on other things as well (only use the same password once).
Make sure when you are logging in that the site is using HTTPS (the browser addon HTTPS Everywhere can help with that) and you aren't logging in from a public network such as from Starbucks. Even if you are logging in from a private network, I recommend using a VPN that uses encryption such as proXPN. For your home or office network that you are logging in from make sure it is using WPA2 encryption, it has a random network name, a secure password, you have changed the default credentials for the network settings to something secure, you have disabled WPS, etc.
That is all I can think of right now in terms of password security, but those are the main things that you should focus on in terms of secure passwords.
Everything on these sites isn't "white hat" per say, but it gives you a different perspective on SEO that isn't the typical "white hat" stuff like on Moz (for the most part it is all pretty white hat) for example. I am not talking about hacking sites and placing links for SEO, but private blog networks and that kind of thing on these two sites. Hope that helps. If you have any questions shoot me an email at caleb.lane4(at)gmail.com.
This has a lot of good information in it and I put a lot of time into it, but I do realize it is hard to read since Hacker News doesn't start things on new lines. If someone can tell me how to do that if it is possible that would be great. If not here it is on Pastebin - http://pastebin.com/MspKq8sz.
Here is what I recommend for website security (this is a lot of advice and is not perfect - if you want me to write this up in a detailed blog post and cover more things let me know)... I also provided my contact information at the bottom if you have any questions or need any help settings this up.
- Enable WHOIS protection
- Enable domain locking - if you want more details on how to set this up let me know
- Enable email notifications and make sure you keep your account information up to date
- Log in from a computer using a VPN (I use and recommend proXPN - https://proxpn.com/) which encrypts your connection
DNS
1. Any of the domain registrars mentioned above
2. CloudFlare - https://www.cloudflare.com/ (offers performance benefits as well) Their DDOS protection, DNS, and performance benefits are why I use and recommend them. They are not very good in terms of their WAF or website security and that is why I use and recommend Sucuri as well.
3. DNS Made Easy - http://www.dnsmadeeasy.com/
- Follow advice from passwords section
- Delete unnecessary DNS records
- Enable DNSSEC if possible
- Follow advice from passwords section
- Take advantage of the security Google offers
Passwords
1. Create strong passwords using a password generator. I use GRC's Password Generator by Steve Gibson. - https://www.grc.com/passwords.htm
2. Store your passwords in a password manager such as LastPass. - https://lastpass.com/
3. With LastPass use a strong master password, limit login attempts to your country and the ones you travel to frequently, use two factor authentication, don't use a password reminder, don't write down your master password - only memorize it and don't ever share it, change your master password at least slightly every 3 months, and disable logins from the TOR network.
4. Use the same password only once (Don't use the same password on multiple sites).
5. Don't store your passwords in the browser or save them, so you are automatically logged in.
6. Make sure your password is at least 15+ characters (I use 50+ characters) and it contains lowercase letters, uppercase letters, numbers, and special characters.
7. If a site requires a secret question, make sure the answer to that question no one else would know or make it a password or phrase that you would remember.
8. Use the browser add-on HTTPS Everywhere and use Mozilla Firefox or Google Chrome as your browser.
9. Try to not share your passwords - I would like to say never share your passwords, but I know that is not possible :). If you have to share your passwords, do so using LastPass, change the password after they are done, make sure they haven't done anything that looks malicious, have a clear plan of what they need to do, and ask them how long it will take them.
3. Use a WAF - I recommend and use Sucuri CloudProxy - http://cloudproxy.sucuri.net/signup ($9.99 a month for the most basic plan - the two other plans are $19.98 and $69.93 per month)
4. There could be a lot more in this area, but that should do a pretty good job for you. If you are using a CMS such as WordPress, Joomla, or Drupal you have quite a bit more you can do in this area.
Hosting
1. It honestly depends on your needs, so I am not going to recommend anyone specifically. If you want help with this or anything you can find my contact information at the bottom.
Network Security
1. Use WPA2 for the encryption protocol
2. Make your network name random
3. Make your password to connect to your network very strong
4. Change the default login credentials to login to your network to a secure username and password.
5. Disable Wi-Fi Protected Setup (WPS)
6. Configure OpenDNS at the router level - http://www.opendns.com/
7. Follow the passwords section for your passwords
Computer Security
1. Use a antivirus program (Antivirus for Mac by Sophos for MAC computers and Microsoft Security Essentials or Avast for Windows)
2. Use an anti-malware program (Malwarebytes Antimalware and Malwarebytes Anti-Exploit for Windows)
3. Use a firewall (Windows Firewall or TinyWall for Windows)
4. Keep your operating system updated
5. Keep your programs updated (Secunia PSI or FileHippo Update Checker for Windows and AppFresh for MAC)
6. Remove Java and Quicktime if you don't need them
7. Replace Adobe Reader with Foxit Reader or Sumatra PDF
8. Make sure you keep Adobe Flash Player up to date
9. Uninstall programs that you don't need or don't use
10. Only download things from trusted sources (the browser extension Web of Trust would help with this)
11. For your browser make sure you are using Google Chrome or Mozilla Firefox. For Google Chrome and Mozilla Firefox, I recommend that you use Adblock Plus, Disconnect, and HTTPS Everywhere). If you want to be very secure and are somewhat technical, I recommend that you also use NoScript for Mozilla Firefox and NotScripts for Google Chrome.
If you have any questions you can email me at [redacted].
I would recommend Melbourne IT or Namecheap for what you are looking for. I would recommend you take advantage of WHOIS protection, two factor authentication, locking your domain at the registrar level (not just with Namecheap for example, but with the actual registrar), using strong passwords, etc.
The company can only do so much, so make sure you do everything you can do as well to make your domains as secure as possible.
To answer your first question, like people said already, pull a log from your servers with the IP's. If it is a lot of different IP addresses then that is a good sign of a DDOS attack of some kind. If it is a lot of requests from the same IP address or only a few IP addresses it probably is a search engine or something like which is causing the problem. You can also look up the IP addresses by simply Googling them to see who owns the IP.
To fight off the attack immediately I would recommend switching your DNS over to CloudFlare's Pro or Business plan (that depends a lot though on your site's current configuration, the size of your budget, etc.) with certain settings, then configuring Sucuri CloudProxy with CloudFlare, and lastly implementing some additional security for your server on Single Hop.
In terms of preventing future ones, you basically want to be proactive as possible in terms of preventing them, but that won't stop everything. The configuration I recommended above should be pretty good for most sites, but you might want to consider other DDOS mitigation companies as well and you could need something completely different depending on your business etc. Then you want to have a plan and several other things in place in case it was to get past the infrastructure you implemented to prevent it, so you can minimize the downtime you have etc.
It is hard to tell whether that is a possible issue just based on the information you gave in terms of the sleeping MySQL connections.
Lastly, depending on what the issue exactly is, it probably would be a good idea to make your site as static as possible, but that is difficult to do since your site is down right now. Once you get the site back up though and stable, you might consider doing this for a little bit. Lastly, having a separate site that you can deploy in the event of an attack is a good idea as well.
If you want more help, shoot me an email at [email protected]. I hope that helped and you get this solved quickly.
Here is a good article on the Malwarebytes Anti-malware blog for some recommendations: http://blog.malwarebytes.org/security-threat/2014/04/windows...