GLOBE.LU News


IPv6 connectivity integrated – IPv6 and IPv4 ready

Dual stack connections via IPv4 and IPv6 are now available for all new orders (shared hosting). For existing hostings, the host systems Host1 and Host4 have already been equipped with IPv6 & IPv4, support for Host2 and Host3 is coming soon.

WordPress Backdoor Found in Themes and Plugins!

Backdoor Found in Themes and Plugins from AccessPress Themes Due to the way the extensions were compromised, we suspected an external attacker had breached the website of AccessPress Themes in an attempt to use their extensions to infect further sites. Details: https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ Please update or remove (un-install completely) the extensions mentioned in the details from the link above. If there are no updates for this […]

PHP mail function – Captcha protection required!

In order to avoid blacklisting of our mail servers due to unprotected contact forms & other forms, the forms must be secured with Captcha, e.g. (re-captcha v2) this is required to use PHP mail. If your application does not support PHP mail at the moment, please let us know when a captcha protection has been integrated and therefore the PHP mail function should be activated. […]

WordPress security issues – please update!

4 security issues affect WordPress versions between 3.7 and 5.8. If you haven’t yet updated to 5.8, all WordPress versions since 3.7 have also been updated to fix the security issues. details english: https://wordpress.org/support/wordpress-version/version-5-8-3/ Sicherheitsupdate: Angreifer könnten sich auf WordPress-Websites einnisten. In der aktuellen Version des Content Management System WordPress haben die Entwickler vier Sicherheitslücken geschlossen. details german: https://www.heise.de/news/Sicherheitsupdate-Angreifer-koennten-sich-auf-WordPress-Websites-einnisten-6320363.html?wt_mc=nl.red.security.security-nl.2022-01-10.link.link

Too many WordPress Plugins can cause conflicts

Too many plugins can lead to security breaches on your site, site crashes, bad performance, slow loading speeds, and more. It may come as no surprise that piling a ton of plugins on top of each other on your website can cause some conflicts. Some plugins will disrupt the way others function, causing problems on your site. Details: https://pressable.com/why-its-smart-to-limit-plugins-on-your-wordpress-site/

Enjoy 20% Off for PROWEB-XL 5000 MB

Hosting Package: PROWEB-XL Promo Code: GLOBE21 please enter the promo code during checkout (Promo code expiry date: 01/01/2022) https://www.globe.lu/en/hosting/

How to Fix Website is Not Secure Browser Message?

Why does my website say it’s not secure? Any modern browser will display the “Not secure” warning in the address bar when your website is using HTTP instead of HTTPS. An SSL certificate can be used to encrypt and decrypt data transferred to and from your website. The best way to deal with the question “Why does my website say not secure?” is to install […]

Lets Encrypts Root Certificate is expiring – Incompatible clients!

Let’s Encrypt DST Root CA X3 expiration on Sept. 30 2021 Due to significant changes of the certificate provider Let’sEncrypt problems with some outdated clients can occur (web browser, email clients). The Let’s Encrypt DST Root CA X3 will expire on September 30, 2021. That means those older devices that don’t trust ISRG Root X1 will start getting certificate warnings when visiting sites that use […]

WP Fastest Cache vulnerabilities – update now

Multiple vulnerabilities in WP Fastest Cache plugin – please update now! https://jetpack.com/2021/10/14/multiple-vulnerabilities-in-wp-fastest-cache-plugin/ german: https://www.heise.de/news/WordPress-Beliebtes-Plugin-WP-Fastest-Cache-braucht-dringend-ein-Update-6220994.html?wt_mc=nl.red.security.security-nl.2021-10-21.link.link

WordPress: Ninja Forms Admin + SQL Injection

Please update now! The plugin does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks. Details: https://wpscan.com/vulnerability/55008a42-eb56-436c-bce0-10ee616d0495

New Mod_Security rules – 90% reduction of false alerts & 403 errors

We are working hard to bring you a better and smoother experience! Today we’ve published an Mod_Security update for all shared hostings which includes a 90% reduction of false alerts and 403 errors. CRS 3 includes many coverage improvements, plus the following new features: – Over 90% reduction of false alerts in a default install – Application-specific exclusions for WordPress Core and Drupal – SQLi/XSS […]

HTTP2 – available now for all our shared server

HTTP/2 support is available now for all our shared hosting packages. HTTP/2 will make your applications faster, simpler, and more robust. The primary goals for HTTP/2 are to reduce latency by enabling full request and response multiplexing, minimize protocol overhead via efficient compression of HTTP header fields, and add support for request prioritization. HTTP/2 is compatible with almost all major browsers. It’s also backward compatible […]

Email Clients – TLS Version 1.0 and 1.1 Deprecation

If you are using an old mail client or an old OS, it is possible the software does not support TLS 1.2 or 1.3 and therefore your emails are not working anymore on your computer. If your emails don’t work following the update it means your mail client (Mail, Thunderbird, Outlook) does not support TLS 1.2 or 1.3. It is therefore not up to date […]

Webbrowser & Email Clients – TLS protocol 1.0 & 1.1 End of Life

Webbrowser & Email Clients – TLS protocol 1.0 & 1.1 End of Life TLS 1.0 and 1.1 is End of Life, for a successful connection via browser or email client, at least TLS version 1.2 is required (TLS v 1.3 is the current version). Browser TLS check: https://clienttest.ssllabs.com:8443/ssltest/viewMyClient.html Details: https://www.comodo.com/e-commerce/ssl-certificates/tls-1-deprecation-browsers.php https://docs.microsoft.com/en-us/microsoft-365/compliance/prepare-tls-1.2-in-office-365?view=o365-worldwide

Lets Encrypt – Change for older browsers

On September 30, there will be a change in how older browsers and devices trust Let’s Encrypt certificates, resulting in a minor decrease in compatibility. Details: https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/

WordPress Security – Update Now!

WordPress 5.8.1 Security and Maintenance Release This security and maintenance release features 60 bug fixes in addition to 3 security fixes. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 5.4 have also been updated. Details: https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and-maintenance-release/ Sicherheitspatch: WordPress-Entwickler raten zu zügigem Update Das Content Management System WordPress ist über mehrere Sicherheitslücken angreifbar. Details: https://www.heise.de/news/Sicherheitspatch-WordPress-Entwickler-raten-zu-zuegigem-Update-6188735.html?wt_mc=nl.red.security.security-nl.2021-09-13.link.link

WooCommerce – Critical vulnerability!

Please Update NOW! Details: https://www.heise.de/news/WordPress-Plugin-WooCommerce-schliesst-kritische-Sicherheitsluecke-6140221.html

Critical vulnerability threatens WordPress 3.7 to 5.7

One security issue affecting WordPress versions between 3.7 and 5.7. If you haven’t yet updated to 5.7, all WordPress versions since 3.7 have also been updated to fix the following security issue: Details https://wordpress.org/news/2021/05/wordpress-5-7-2-security-release/ https://www.heise.de/news/Jetzt-patchen-Kritische-Luecke-bedroht-WordPress-3-7-bis-5-7-6045823.html?wt_mc=nl.red.security.security-nl.2021-05-17.link.link