Technical Resources Malware Monitoring Service Powered by StopTheHacker StopTheHacker Dashboard User Guide End User Version
CONTENTS Introduction... 3 Account Activation... 3 How to Log into Your Account... 3 Type of Service... 4 Navigation Tab: Overview... 4 Malware... 6 Vulnerabilities... 7 Reputation... 7 Performance... 8 Individual Monitored Domains - Detailed Insights... 9 How to Interpret Reports... 10 Reputation Monitoring... 10 Malware... 11 Vulnerability Assessment... 12 Performance... 13 Service Settings... 14 Email Settings... 14 Domain Settings... 15 Automatic Malware Cleanup Settings... 15 Upgrade Options... 15 Trust Seal... 16 Navigation Tab: Account... 17 GlobalSign Knowledge Base... 18 Submit A Support Ticket... 18 About GlobalSign... 18 2
INTRODUCTION StopTheHacker is GlobalSign s preferred malware monitoring service provider and through a strategic partnership its range of services are available to GlobalSign SSL Certificate customers. StopTheHacker enables web hosters, website owners, administrators and web designers to detect malware and recover sites from damaging malware attacks. This guide provides an overview and step-by-step guide on how to use StopTheHacker s web-based dashboard to view, monitor and upgrade your website domains. Please Note: This service is automatically included as standard with GlobalSign retail SSL Certificates. If you have a GlobalSign Managed SSL Account you will need to contact your Account Manager to discuss this service. If you purchased your SSL Certificate via a GlobalSign Partner, you will need to check with them directly to see if this service is included. ACCOUNT ACTIVATION Once you have purchased a GlobalSign SSL Certificate and it has successfully been issued, your domain will automatically be monitored by StopTheHacker. After your SSL Certificate has been successfully issued, you will receive an email welcoming you to the service, instructing you on how to activate your StopTheHacker account, prompting you to create a secure password. Please Note: The email address used will be the email address previously specified as the contact email connected with the SSL Certificate order and it will be this email address to which all StopTheHacker emails will be sent. HOW TO LOG INTO YOUR ACCOUNT Visit https://www.globalsign.com/stopthehacker in your web browser. Login Panel Insert your email address and password and click on Login. 3
You will now be directed to your personal dashboard, showing an overview of all your domains under this account. Please Note: If you only have one domain you will be directed to the specific view for this domain. TYPE OF SERVICE The type of SSL Certificate purchased will determine which level of malware monitoring service you will receive and have access to via your dashboard. The service levels per certificate can be seen in the table below. SSL Certificate Type AlphaSSL DomainSSL OrganizationSSL ExtendedSSL StopTheHacker Product and Functionality AlphaSSL Web Reputation DomainSSL Web Malware Standard OrganizationSSL Web Malware Advanced ExtendedSSL Web Malware Professional Blacklist and Reputation Scan X X X X Scan of Known Malware X X X Scan of Unknown Malware (AI) X X Facebook Protection Speed Monitoring Uptime Monitoring Annual Security Report Pages Scanned All All All Scan Frequency Weekly Daily Daily Hourly Automatic Malware Cleanup (AMC) Vulnerability Assessment (VA) Service Levels Upgrade Option Available Upgrade Option Available X X X X Please note: If your SSL Certificate type does not include a service you would like to receive, upgrade options are available at an additional fee. For GlobalSign retail SSL Certificates this can be managed directly via the dashboard by logging into your account at https://www.globalsign.com/stopthehacker. Alternatively you could upgrade your SSL Certificate type. For customers who purchased their SSL Certificates from a GlobalSign Partner, please contact them directly to discuss upgrade options. NAVIGATION TAB: OVERVIEW At the top of the dashboard you will see the navigation points available within the dashboard. When you login you will automatically start in the Overviews area. On the right hand side of the navigation bar you will also see if you have any notifications or important messages. Below the navigation bar, StopTheHacker provides you a link to their introduction video, in case you would rather watch than read. Please note: This video is based on StopTheHacker direct services and therefore functions may vary slightly. 4
Navigation Bar In the Overviews Section you will see all your domains on the left hand side with a little icon indicating the domains overall status: The red warning triangle means that something is wrong with your domain The green shield indicates that everything is fine with your domain The blue clock icon shows that the scan for this domain is currently in progress The large section is split into four security areas: Malware, Vulnerabilities, Reputation and Performance. In each area an overview for all monitored domains is provided. (Please refer back to the table on page 4 should you wish to know which services are included with your SSL Certificate). Dashboard Overview Multiple Domains 5
The pie charts display the safety status of your websites/domains that are registered with StopTheHacker in the four different areas. The legend to the right of the pie charts explains what the different areas of the charts represent. The list shows all of the individual domains being monitored and where on the chart they are represented. If you have a website that is not being monitored by a particular service (marked in grey), upgrade options are available should you require these additional services. MALWARE Malware Each non-intrusive scan checks all pages of your website for known viruses and web malware threats to see if hackers have injected malicious code into your website. StopTheHacker s email notification system immediately informs you if any malware is found, so you can take all actions needed. The pie chart displays the safety status of your websites/domains that are using a GlobalSign SSL Certificate. The legend to the right of the pie chart explains what the different areas of the chart represent. Blue: Domains being scanned for malware for the first time Green: Domains found to be free of malware Red: Domains found to have malware Grey: Domains not being monitored for malware The list on the far right hand side shows all of the individual domains being monitored and where on the chart they are represented e.g. Safe Domains. Please note: StopTheHacker's Malware Monitoring Service is not available to AlphaSSL customers and should you wish to benefit from this service you will need to upgrade your SSL Certificate type to a DomainSSL or above. Please contact us directly by emailing sales@globalsign.com. OrganizationSSL and ExtendedSSL Certificates also include advanced malware monitoring for detecting unknown malware. StopTheHacker's artificial intelligence based engine with advanced self-adapting capabilities constantly monitor new strains of malware and protects your online business from these emerging threats. This advanced feature is available for DomainSSL Certificate customers as an upgrade option. You can upgrade by logging into your StopTheHacker account at https://www.globalsign.com/stopthehacker. 6
VULNERABILITIES Vulnerabilities The pie chart displays the safety status of your websites/domains for vulnerabilities. Vulnerability scans can prevent web-based intrusions and identify server and application security vulnerabilities that bots and hackers can use to attack you. StopTheHacker can check over 35,000 vulnerabilities on your servers, website and infrastructure, checking for web application vulnerabilities in most popular software like Word Press, Drupal, Django, Joomla, Ruby on Rails, OpenCMS and can uncover vulnerabilities in custom installations too. The legend to the right of the pie chart explains what the different areas of the chart represent. Blue: Domains being scanned for vulnerabilities for the first time Green: Domains found to have no vulnerabilities Red: Domains found to be vulnerable to attack Grey: Domains not being monitored for vulnerabilities The list on the far right hand side shows all of the individual domains being monitored and where on the chart they are represented e.g. Vulnerable Domains and First Scans. Please note: Vulnerability assessment scans are not automatically included as standard with your SSL Certificates and malware monitoring service and this feature is available as an additional upgrade option. You can upgrade by logging into your StopTheHacker account at https://www.globalsign.com/stopthehacker. REPUTATION Reputation The pie chart displays the safety status of your websites/domains for reputation including blacklist monitoring. Blacklist monitoring is a comprehensive daily check on the status of your website on the Google Safe Browsing 7
List and other search engines including Yahoo, and Bing; malware blacklists like Malware Patrol and Malware URL; DNS Blacklists; phishing blacklists like PhishTank; spam blacklists like SpamCop; and many more. StopTheHacker will automatically notify you via email if your website ends up on a blacklist and will help you to remove your site from the search engine blacklist. The legend to the right of the pie chart explains what the different areas of the chart represent. Blue: Domains being scanned for reputation for the first time Green: Domains that have a good reputation Red: Domains that have a poor reputation Grey: Domains not being monitored for reputation The list on the far right hand side shows all of the individual domains being monitored and where on the chart they are represented e.g. Poor Reputation. Please note: This service is included as standard with all SSL Certificate types including AlphaSSL, DomainSSL, OrganizationSSL and ExtendedSSL. PERFORMANCE Performance The pie chart displays the safety status of your websites/domains for performance including up-time and speed monitoring. Up-time Monitoring gives you an overview of the availability of your website including details on down time; in case the site goes down we will send you an email alert. Speed Monitoring gives you real-time information on the page speed and response time of your website using detailed graphs. The legend to the right of the pie chart explains what the different areas of the chart represent. Green: Domains being monitored for performance Grey: Domains not being monitored for performance The list on the far right hand side shows all of the individual domains being monitored and where on the chart they are represented e.g. Monitored. Please note: This service is included as standard only with ExtendedSSL Certificates. This advanced feature is available for DomainSSL and OrganizationSSL Certificate customers as an upgrade option. You can upgrade by logging into your StopTheHacker account at https://www.globalsign.com/stopthehacker. 8
If you have an AlphaSSL Certificate and you wish to benefit from this service, you will need to upgrade your SSL Certificate type to GlobalSign s DomainSSL or above. Please contact us directly to do this by emailing sales@globalsign.com. INDIVIDUAL MONITORED DOMAINS - DETAILED INSIGHTS To get detailed information on any individual domain that is being monitored, simply find the domain you want to get the details for on the left side and click on the domain. This brings you to the detailed status overview of the selected domain. Overviews The detailed domain overview is split into the same four areas as the overall Overviews section and shows you the detailed status of the selected domain in each area. If an area is greyed out, this means that the specific service is not included as standard with your type of SSL Certificate. To activate these areas for your domain, you can upgrade to a more advanced service at an additional charge, by logging into your StopTheHacker account at https://www.globalsign.com/stopthehacker. To view even more details within each area, you can click on the desired topic in the left hand sub-navigation, or you can hover over the Action+ button and click the link that appears. 9
Detailed View The sub-navigation for each individual domain can be found on the left side and also includes the topics Service Settings (for this specific domain) and the Trust Seal. GlobalSign and StopTheHacker recommend that you display the Trust Seal on your website to reassure browsing visitors that your site is malware free. More information about the Trust Seal can be seen on page 16. HOW TO INTERPRET REPORTS REPUTATION MONITORING The Reputation section provides information to answer questions such as: How is your website perceived on the Internet? Is your website on any blacklists? Is your SSL Certificate expiring soon? Are any of the search engines blacklisting your website? This area is divided into three sections: 1. Blacklists: This section shows you the results of checking your domain name against various data sources, such as Google malware, Google Phishing, DNS blacklists, Phishing blacklists and much more. An alert red triangle icon lets you know if the particular data source has an unfavourable reputation about your domain. Hover your mouse over the icon to view further information. 2. Ecosystem: This section shows you the results of the reputation information regarding your IP, your hoster or whether your IP is listed in Botnets or not. Hover your mouse over the icon to view further information. 3. Web of Trust: This section shows you the results from our data partner Web of Trust. Please remember Web of Trust is an independent data provider. Hover your mouse over the icon to view further information. To improve your Web of Trust score please visit http://www.mywot.com/. 10
To get more details about each source within these sections, please click on the grey question mark next to each source in the right hand corner. MALWARE The malware report for your domain will display only one of two messages, either green or red. Green messaging will inform you that everything is ok with your site. There was no malware found on your domain. Red messaging will inform you that malware has been found. Malware has been detected on your domain. No Malware -Website Safe Malware Detected Hover over the Action+ button and on Show More to see the entire malware code. Show More 11
You can also click on View Source to try and view the malware present in the web page at real time. Please note: This might not always work as some malware only appears intermittently and hence grabbing the html page when you click on View Source might not be able to grab the malware at the specific moment you click on this link. Source Code View VULNERABILITY ASSESSMENT The vulnerability assessment report is divided into three sections. It starts with a short overview on all found vulnerabilities. These are grouped into three levels: Critical, Important and Informational. The overview shows you how many vulnerabilities in each group where found and if these are server or application vulnerabilities. Vulnerability Overview The second section is a detailed report on each individual server vulnerability that was found, including a recommendation for each vulnerability on what you should do. The last section deals with the application vulnerabilities found and also contain recommendations on what should be done to fix them. 12
Application Vulnerabilities PERFORMANCE The performance overview shows you the last 30 days statistics of your site load speed for the selected domain, as well as the last 30 days uptime of your domain. You can hover over the graphs to get more detailed information of the site speed, date and more. Performance Overview 13
SERVICE SETTINGS Within the Service Settings of your account you can manage your service level and upgrade options, email recipients and email preferences, in addition to your domain hosting details. To access your service settings select the domain you wish to view the service for, from the domain list on the left hand side of your account. Then click on the Service Settings navigation point on the left hand side in the side menu bar below the selected domain. Service Settings Please note: Please see the Upgrade Options section of this guide on page 15 from more detailed information about the level of service you wish to receive and how to upgrade. EMAIL SETTINGS Within the Email Recipient box you can enter those email addresses you wish alerts to be sent to. If you enter more than one email address, please separate them with a comma. 14
A number of different email options are available depending on how often you would like to hear from StopTheHacker. This can be viewed under Email Preferences where you can select your preferred choice from the following options: Email me about every scan Email me a weekly summary and if there is a problem (recommended) Email me only if there is a problem Never send me email about my scan reports will still be available online Once selecting your preferred option please ensure you hit the Purchase button which will save your settings. Please note: You will not be charged for this service. If you have an ExtendedSSL Certificate, or have upgraded your service to include Performance Monitoring, you can activate it in this section. Simply check the boxes labelled Uptime Monitoring and Speed Monitoring. If your service level includes Performance Monitoring as standard these feature boxes should already be selected, but at any time should you wish to deactivate this particular service, you can do so here by unchecking the relevant feature boxes. DOMAIN SETTINGS In order to help StopTheHacker better keep your site safe and secure, they ask that you provide some additional information about how your site is currently being hosted, including CMS/Framework and Hosting Panel information. If you wish to complete this section, please select options from the drop down menus provided. GlobalSign does not require you to complete this as standard. AUTOMATIC MALWARE CLEANUP SETTINGS If you choose to upgrade your service level to include automatic malware cleanup you will need to complete this information. To upgrade your service level please see the Upgrade Options section of this guide. There are three setting options to choose from: Yes, check for malware on my server and apply fixes automatically Yes, check and apply fixes automatically No, I will find and fix malware infected files on my own Please note: If you do not wish to upgrade to this service, please leave this section blank, GlobalSign does not require you to complete this as part of its standard service. UPGRADE OPTIONS GlobalSign s Malware Monitoring Service offers a number of upgrade opportunities via StopTheHacker, should you wish to extend the services within your account. Please refer back to page 4 to view the services which are included as standard with your SSL Certificate type. E.g. If you currently have a DomainSSL Certificate and would also like to benefit from the scanning of unknown malware provided by StopTheHacker s Advanced Intelligence (AI) engine, in conjunction with the standard blacklist and reputation monitoring and scanning for known malware offered with this certificate type, you would need to upgrade your service level to include AI. 15
Service upgrade options may be shown with the Service Settings section of your dashboard using abbreviations. These include: Vulnerability Assessment VA Automatic Malware Clean-up AMC Unknown Malware (via Artificial Intelligence Engine) AI Complete ExtendedSSL Feature Package (AI, Facebook Protection, Speed Monitoring, Uptime Monitoring, Annual Security Report) Bundle Please note: There is an additional charge for each of these services on an annual basis. Upgrade options are limited for AlphaSSL customers and if you wish to benefit from additional services you will need to upgrade your SSL to a GlobalSign branded SSL Certificate. If you purchased your SSL Certificate directly from GlobalSign you can manage your options and upgrade directly by logging into your account at https://www.globalsign.com/stopthehacker. Within your selected domain click on Service Settings and here you will be able to view all available upgrade options and the associated price per year. Payments should be made directly via the dashboard to StopTheHacker. If you purchased your SSL Certificate from a GlobalSign Partner, please contact them directly to upgrade your level of service. TRUST SEAL Adding the Malware Monitoring Trust Seal to your site is easy. To get the Trust Seal for your individual domain, simply select the domain you want to get the Trust Seal for, from the domain list on the left hand side of your account. Trust Seal Then click on the Trust Seal navigation point on the left hand side in the side menu below the selected domain. You can now view and copy the code for the Trust Seal and implement it in your website. 16
How to Install Copy the HTML from the embed code text box above Paste the HTML into your web page or template Why use a trust seal? Show your visitors that you care about security Trust Seals have been shown to increase conversion rates by more than 10% NAVIGATION TAB: ACCOUNT At the top of the dashboard you will see the navigation points available within the dashboard. The Account section is where you can manage your account details and login credentials settings. Account Overview The Settings section is split into two main areas, Change Credentials and Account Details. Within the Change Credentials section you can choose to receive StopTheHacker alert emails in HTML format. If not selected you will receive email alerts in plain text. Also in this section you can manage your account password and reset it at any time. In the Account Details section you may wish to enter your main contact details, but GlobalSign does not require you to do this as standard. Please note: GlobalSign has shared the email address associated with your SSL Certificate with its strategic partner StopTheHacker. This is to enable you to receive automated email alerts should malware be detected on your site. This service is included with your SSL Certificate and your email address will be kept confidential and not passed on to any third parties. Within the main navigation of the Account section there is also a Pay Bill section. As your service is included with your SSL Certificate you will not need to use this section. 17
GLOBALSIGN KNOWLEDGE BASE If you require assistance you can search for help by consulting the GlobalSign Knowledge Base: https://www.globalsign.com/support/ SUBMIT A SUPPORT TICKET If you cannot find the answer to your question in our Knowledge Base, please submit your question via our Support Ticket Request Form: https://www.globalsign.com/help/ ABOUT GLOBALSIGN GlobalSign was one of the first Certification Authorities and has been providing digital credentialing services since 1996. It operates multi-lingual sales and technical support offices in London, Brussels, Boston, Tokyo and Shanghai. GlobalSign has a rich history of investors, including ING Bank and Vodafone. Now part of a GMO Internet Inc group company - a public company quoted on the prestigious Tokyo Stock Exchange (TSE: 9449) whose shareholders include Yahoo! Japan, Morgan Stanley and Credit Suisse First Boston. As a leader in public trust services, GlobalSign Certificates are trusted by all popular Browsers, Operating Systems, Devices and Applications and include SSL, Code Signing, Adobe CDS Digital IDs, Email & Authentication, Enterprise Digital Solutions, internal PKI & Microsoft Certificate Service root signing. Its trusted root CA Certificates are recognised by all operating systems, all major web browsers, web servers, email clients and Internet applications, as well as all mobile devices. Accredited to the highest standards As a WebTrust accredited public Certificate Authority, our core solutions allow our thousands of enterprise customers to conduct secure online transactions and data submission, and provide tamper-proof distributable code as well as being able to bind identities to Digital Certificates for S/MIME email encryption and remote two factor authentication, such as SSL VPNs. GlobalSign India Tel: +91 124-4311111 www.globalsign.co.in sales@globalsign.com GlobalSign FR Tel: +33 1 82 88 01 24 www.globalsign.fr ventes@globalsign.com GlobalSign EU Tel: +32 16 891900 www.globalsign.eu sales@globalsign.com GlobalSign DE Tel: +49 30 8878 9310 www.globalsign.de verkauf@globalsign.com GlobalSign UK Tel: +44 1622 766766 www.globalsign.co.uk sales@globalsign.com GlobalSign NL Tel: +31 20 8908021 www.globalsign.nl verkoop@globalsign.com 18