- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: Free Web Site Pen test?
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Free Web Site Pen test?"
Collapse
-
To be honest if a machine gets hacked then by default you should wipe the machine and start again you have no idea what has happened.
-
Ta all,
I'll read up on FrontPages issues and see if he's using the extensions - it's a very simple site.
I'll also suggest it's time for a redesign but suspect it will fall on deaf ears!
Leave a comment:
-
I hate to say this, but FrontPage Server Extensions are insecure. Here's just one article you can look at Web Server Security Issues and Front Page Server Extensions. I would suggest using some proper WebDev application, or use a template like Wordpress, Joomla or Drupal to design the website and ditch FPE.
As the web hosting company is hosting the site, it is most likely a shared site, so doing a pen test against their server without their permission, knowledge and consent could well be in violation of their terms and conditions and could also fall foul of the Computer Misuse Act, so be careful about doing a Pen Test of any form.
Leave a comment:
-
I would start by checking who has write permissions on the files/folders the site contains.
Leave a comment:
-
Well, it's his site and his choice how much he wants to pay!Originally posted by SimonMac View PostTwo questions, firstly is security other than for home use something you want to do on a free basis?
Secondly, if he is using FrontPage that might be the problem in itself, quite a few professional tog's are using wordpress sites which might be a better option
Yes, the original site was created with FrontPage so this could well be the problem.
However it would be nice to know how it was hacked instead of just assuming a site rewrite using a different product would fix it.
It could be his FTP password was compromised in which case it would not matter how the web site was created?
Leave a comment:
-
Two questions, firstly is security other than for home use something you want to do on a free basis?Originally posted by ctdctd View PostMorning,
A mate of mine has a small site for his photography business.
It appears to have been hacked and a folder has appeared full of images - nothing nasty. There is no e-commerce on the site.
His hosting co said a remote shell appears to have been installed and shut down the site. It's all running on a LAMP box by the look of it.
He got them to reset his passwords and FTP'ed in, deleted everything and re-uploaded so it works again.
Are there any free tools he can use to test the site to try and work out if it is likely to happen again.
He's only at the FrontPage level of web authoring and I'm not much better so something with a nice big "click here to test" button is what we need!
Any advice?
Secondly, if he is using FrontPage that might be the problem in itself, quite a few professional tog's are using wordpress sites which might be a better option
Leave a comment:
-
Free Web Site Pen test?
Morning,
A mate of mine has a small site for his photography business.
It appears to have been hacked and a folder has appeared full of images - nothing nasty. There is no e-commerce on the site.
His hosting co said a remote shell appears to have been installed and shut down the site. It's all running on a LAMP box by the look of it.
He got them to reset his passwords and FTP'ed in, deleted everything and re-uploaded so it works again.
Are there any free tools he can use to test the site to try and work out if it is likely to happen again.
He's only at the FrontPage level of web authoring and I'm not much better so something with a nice big "click here to test" button is what we need!
Any advice?Tags: None
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Is your Director’s Loan Account (DLS) a target of HMRC’s closer look at close companies? Yesterday 04:45
- Contractors, are you making any of the five big limited company bank account mistakes of 2026? May 28 05:51
- ‘Welcome’ increase in HMRC mileage rates for contractors using their own cars for work May 27 05:18
- King’s Speech 2026 including a welcome Late Payments Bill still leaves contractors short May 26 04:42
- Getting a mortgage when you're a contractor. The system wasn't built for you. Is that finally changing? May 22 06:11
- How deepfake AI contractors threaten umbrella company supply chains under JSL May 20 06:31
- Mileage rates review: Will the first AMAP rethink in 15 years benefit contractors? May 19 05:57
- What is a Forward Deployed Engineer (FDE), and are FDE jobs for IT contractors ripe? May 18 04:43
- IT contractor demand lunged towards growth in April 2026 May 13 04:48
- What does PGMOL’s win over HMRC mean for contractors? May 12 07:25

Leave a comment: