透過集合功能整理內容
你可以依據偏好儲存及分類內容。
防止惡意軟體感染
想要杜絕惡意軟體侵擾,就必須隨時保持高度警戒。本文提供實用的提示和建議,可協助您杜絕惡意軟體感染。然而,由於本文無法列舉所有情況,Google 建議網站擁有者另加深入研究。
監控網站的健康狀態
Search Console 中許多功能皆可協助您偵測潛在問題。舉例來說:
-
嘗試在 Google 上執行
site:
搜尋運算子搜尋,看看 Google 在您網站上找到哪些網頁。建議您定期執行這項操作,查看是否有人暗中在您網站上加入不該有的網頁或內容。如果您在網站上看到不明網頁,或者不是由您撰寫的主題,表示網站可能已遭到入侵。如果您不熟悉 site:
搜尋運算子的用途,這個運算子可將搜尋範圍限制在特定網站。舉例來說,搜尋 site:developers.google.com
只會傳回來自 Google Developers 網站的結果。
-
如果 Google 在您的網站上找到任何遭入侵的網頁,會在安全性問題報告中列出這些網頁,並提供解決問題的操作說明。
-
如果 Google 在您的網站上偵測到惡意軟體,Search Console 的訊息面板會顯示通知。為確保能迅速收到通知,您可以設定將訊息轉寄至電子郵件帳戶。
安全性檢查清單
除了定期監控您的網站以外,我們也建議您採取以下措施:
所有網站擁有者
-
選擇高強度的密碼。
請參閱 Google 帳戶使用指南中的實用資訊。
-
慎選第三方內容供應者。
檢查您網站上的第三方應用程式和廣告,確定都來自信譽良好且做法符合規定的來源,這類來源會在其網站中提供支援和聯絡資訊。
-
與您的代管公司或發布平台聯絡以取得支援。
多數公司皆設有專業的支援小組和/或安全性網頁,以回應需求。如果安全性網頁或網站提供 RSS 動態消息,請予以訂閱,以便掌握最新資訊。
-
保護您所有電腦的安全。特別是在建置網站時,請確定本機工作站使用的是最新軟體,且未包含病毒、木馬程式或類似惡意軟體,並已更新您安裝的防毒軟體。
具備伺服器存取權的網站擁有者
如果您是 Search Console 使用者,且您的網站有無法修正或持續發生的安全性問題,請通知我們。
回報安全性問題
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-08-04 (世界標準時間)。
[null,null,["上次更新時間:2025-08-04 (世界標準時間)。"],[[["\u003cp\u003eThis guide offers essential tips and best practices for preventing malware infection on your website.\u003c/p\u003e\n"],["\u003cp\u003eGoogle Search Console provides valuable tools, such as the Security Issues report, for monitoring your site's health and identifying potential problems.\u003c/p\u003e\n"],["\u003cp\u003eImplementing strong security measures like choosing robust passwords, carefully selecting third-party content, and regularly updating software is crucial for website owners.\u003c/p\u003e\n"],["\u003cp\u003eFor website owners with server access, securing server configurations, monitoring log files, and staying informed about the latest security updates are vital steps in safeguarding your site.\u003c/p\u003e\n"],["\u003cp\u003eIf you encounter persistent security issues despite implementing these recommendations, Google provides a channel to report them.\u003c/p\u003e\n"]]],["To prevent malware, website owners should monitor site health using Search Console features like the `site:` operator and Security Issues report. Key actions include choosing strong passwords, carefully vetting third-party content, and contacting hosting support. For those with server access, regular software updates, server configuration checks, log file monitoring, and vulnerability checks are crucial. Utilizing secure protocols like SSH/SFTP and staying informed on the latest security news are also recommended.\n"],null,["# How To Prevent Malware Infection | Google Search Central\n\nPreventing malware infection\n============================\n\n\nThe price of freedom from malware is eternal vigilance. This article contains tips and\npointers for preventing malware infection. However, it is by no means exhaustive, and Google\nencourages website owners to conduct more thorough research as well.\n\nMonitoring your site health\n---------------------------\n\n\nMany of the features of Search Console can help you identify potential problems. For example:\n\n- Try a search on Google with the [`site:` search operator](https://support.google.com/websearch/answer/2466433) to see what pages Google has found on your site. It's always a good idea to do this periodically to see whether anyone has snuck unexpected pages or content on your site. If you see unknown pages on your site, or topics that you didn't write, you may have been hacked. If you're not already familiar with the `site:` search operator, it's a way for you to restrict your search to a specific site. For example, the search [`site:developers.google.com`](https://www.google.com/search?q=site%3Asite:developers.google.com) will return results only from the Google Developers site.\n- The [Security Issues report](https://support.google.com/webmasters/answer/9044101) shows any hacked pages that Google has identified on your site, and instructions on how to fix the problem.\n- If Google detects malware on your site, you'll see a notification in the [message panel in\n Search Console](https://support.google.com/webmasters/answer/9388335). To ensure that you're notified quickly, you can have your messages [forwarded to your email account](https://support.google.com/webmasters/answer/140528).\n\nSecurity checklist\n------------------\n\nIn addition to monitoring your site regularly, we also recommend the following:\n\n### All website owners\n\n- **Choose good passwords.** The [Google account guidelines](https://support.google.com/accounts/answer/32040) are helpful.\n- **Pick third-party content providers very carefully.** Make sure that third-party apps and ads on your site are from trusted and legitimate sources. A trusted and legitimate source provides support and contact information on their website.\n- **Contact your hosting company or publishing platform for support.** Most companies have helpful and responsive support groups and/or security pages. If a security page or site has an RSS feed, subscribe to it to make sure you stay up to date.\n- Keep all of your computers safe. Especially when working on a website, make sure that your local workstation has up-to-date software, is clean from viruses, trojans, or similar malware and has recently updated anti-virus software installed.\n\n### Website owners with server access\n\n- **Check your server configuration.** Apache has some [security configuration tips](https://httpd.apache.org/docs/2.4/misc/security_tips.html) on their site and Microsoft has some [tech center resources for IIS](https://www.google.com/search?q=microsoft+iis+security+best+practices) on theirs. Some of these tips include information on directory permissions, server-side includes, authentication, and encryption.\n- **Make a backup copy of your `.htaccess` file** (or other access control mechanisms depending on your website platform). Use your backup file to recover if the following fails. Be sure to delete the backup file once you are finished.\n- **Stay up-to-date with the latest software updates and patches.** There are lots of tools that make building a website easy, but each one adds some risk of being exploited. A common pitfall for many website owners is to install a forum or blog on their website and then forget about it. Much like taking your car in for a tune-up, it's important to make sure you have all the latest updates for any software program you have installed. Make a list of all the software and plug-ins used for your website, and keep track of the version numbers and updates. Even if you're diligent and keep all your website components updated, you may still be vulnerable if your web hoster has not installed the most recent operating system patches. This problem affects not only small sites; there have been warnings on the websites of banks, sports teams, and corporate and government websites.\n- **Keep an eye on your log files.** Making this a habit has many great benefits, one of which is added security. For example, unfamiliar URL parameters (like `=http:` or `=//`) or spikes in traffic to redirect URLs on your site may indicate that a hacker is exploiting [open redirects](/search/docs/advanced/guidelines/sneaky-redirects). Also, bear in mind that hackers often try to alter log files. Take measures to protect these files from attack. For example, you can move these files from their default location, making it harder for hackers to find them.\n- **Check your site for common vulnerabilities.** Avoid having directories with open permissions. This is like leaving the front door to your home wide open.\n\n\n Also check for any\n [XSS](https://www.owasp.org/index.php/Cross_Site_Scripting)\n (cross-site scripting) and\n [SQL injection](https://owasp.org/www-community/attacks/SQL_Injection) vulnerabilities.\n- **Use secure protocols.** Google recommends using SSH and SFTP for data transfer, rather than plain text protocols such as telnet or FTP. SSH and SFTP use encryption and are much safer.\n- **Keep up to date on the latest security news.** The [Google Security Blog](https://security.googleblog.com/) provides useful information about online security and safety, as well as pointers to other resources. The government site [US-CERT](https://us-cert.cisa.gov/) (United States Computer Emergency Readiness Team) provides technical security alerts and tips.\n\n\nIf you're a Search Console user and are having trouble with persistent or unfixable security issues on your site, you can let us know.\n\n[Report a security issue](https://support.google.com/webmasters/contact/report_security_issues)"]]