บทความนี้อาจมีลิงก์ affiliate · เนื้อหาเป็นความเห็นของทีมงาน CloudPicked.com อิสระจากผู้ให้บริการ รายละเอียด
Security Review

ความปลอดภัยของ AsiaGB 2026: cpGuard, SSL และ Backup ครบจบ AsiaGB Security 2026: cpGuard, SSL & Backup — Complete Protection

ทีมงาน CloudPicked.com · อัพเดต 14 มิถุนายน 2026 · อ่าน 12 นาที
วิธีทดสอบ: จากการทดสอบของเรา — ทีมงานได้สมัครใช้งานบัญชีจริงของ AsiaGB, ทดสอบระบบ cpGuard โดยการอัพโหลดไฟล์จำลอง, ตรวจสอบกระบวนการออก SSL certificate, และทดลอง restore ข้อมูลจาก backup ผ่าน DirectAdmin เพื่อยืนยันความถูกต้องของข้อมูลในบทความนี้
ความปลอดภัยของ AsiaGB — cpGuard, SSL, Backup

1. ภาพรวมความปลอดภัย AsiaGB

AsiaGB ก่อตั้งมาตั้งแต่ปี 2550 (2007) มีประสบการณ์กว่า 19 ปีในวงการ web hosting ไทย ความปลอดภัยของผู้ใช้เป็นหนึ่งในจุดที่บริษัทให้ความสำคัญเป็นอย่างยิ่ง ทุกแผน hosting ไม่ว่าจะราคาเริ่มต้น 500฿/ปี ไปจนถึงแผนองค์กร ต่างได้รับการป้องกันชุดเดียวกันครบทุกชั้น

AsiaGB, established in 2007 with over 19 years of experience in Thai web hosting, bundles a comprehensive security stack with every hosting plan — from entry-level to enterprise — at no additional cost.

จากการทดสอบของเรา พบว่า AsiaGB มีระบบความปลอดภัยที่ครอบคลุมหลายชั้น ได้แก่ cpGuard (ระบบสแกน Malware อัตโนมัติ), SSL Let's Encrypt ฟรีพร้อม auto-renew, Backup 2 ครั้ง/เดือน เก็บนานถึง 1 ปี, และ DirectAdmin ที่มีฟีเจอร์ความปลอดภัยขั้นสูง ทั้งหมดนี้รวมอยู่ในราคาแผนพื้นฐาน ไม่มีค่าใช้จ่ายเพิ่มเติมซ่อนอยู่

All security features — cpGuard malware scanning, free SSL, monthly backups retained for one year, and DirectAdmin with advanced security controls — are bundled into every plan with no hidden fees.

เซิร์ฟเวอร์ของ AsiaGB ตั้งอยู่ในไทยและสิงคโปร์ รองรับการเข้าถึงที่รวดเร็วสำหรับผู้ใช้งานในภูมิภาคอาเซียน พร้อม uptime 99% ด้วยระบบ SSD ที่เสถียร Control panel ที่ใช้คือ DirectAdmin ซึ่งเป็นมาตรฐานของ AsiaGB ทุกแผน

Servers are located in Thailand and Singapore for low-latency access across Southeast Asia. All plans run on SSD storage with 99% uptime SLA and DirectAdmin as the standard control panel.

ระบบความปลอดภัยที่รวมในทุกแผน

  • cpGuard — สแกน Malware/Backdoor/Web Shell
  • SSL Let's Encrypt — ฟรี, auto-renew อัตโนมัติ
  • Backup — 2 ครั้ง/เดือน เก็บ 1 ปี
  • DirectAdmin — 2FA, IP blocking, password policy
  • Firewall — ป้องกัน DDoS และ brute-force
  • HTTPS Redirect — บังคับ HTTPS อัตโนมัติ

ราคาแผน Hosting AsiaGB

  • 5GB — 500฿/ปี
  • 8GB — 800฿/ปี
  • 10GB — 1,500฿/ปี
  • 35GB — 3,500฿/ปี
  • ทุกแผน: Bandwidth ไม่จำกัด
  • ทุกแผน: Email + MySQL ไม่จำกัด

2. cpGuard — ระบบสแกน Malware อัตโนมัติ

cpGuard คือหัวใจหลักของระบบความปลอดภัยของ AsiaGB เป็นซอฟต์แวร์สแกน malware ที่ทำงานอยู่บน server ตลอด 24 ชั่วโมง คอยตรวจสอบไฟล์ทุกไฟล์ในบัญชีของคุณโดยอัตโนมัติ ไม่จำเป็นต้องติดตั้งหรือตั้งค่าใดๆ เพิ่มเติม เพราะรวมอยู่ในทุกแผน hosting ตั้งแต่แรก

cpGuard is the backbone of AsiaGB's security infrastructure — a server-level malware scanner that operates 24/7, monitoring every file in your hosting account automatically. No installation or additional configuration needed; it comes pre-enabled on every plan.

ประเภทภัยคุกคามที่ cpGuard ตรวจจับ

จากการทดสอบของเรา cpGuard สามารถตรวจจับภัยคุกคามได้หลายประเภท ดังนี้:

cpGuard detects malware, backdoors, web shells (WSO/r57/c99), viruses, phishing pages, spam scripts, and cryptominers — covering the full spectrum of threats targeting shared hosting environments.

กระบวนการสแกนและแจ้งเตือน

cpGuard ทำงานแบบ real-time scanning ทุกครั้งที่มีการอัพโหลดหรือแก้ไขไฟล์ในบัญชีของคุณ นอกจากนี้ยังมีการสแกนแบบ scheduled scan เป็นระยะ เพื่อตรวจสอบไฟล์ทั้งหมดอีกรอบ หากพบภัยคุกคาม ระบบจะ:

  1. แจ้งเตือนทันที — ส่ง email แจ้งเตือนไปยัง email ที่ลงทะเบียนไว้ พร้อมระบุชื่อไฟล์ที่ต้องสงสัย, ประเภทภัยคุกคาม, และ path ของไฟล์
  2. Quarantine อัตโนมัติ — ไฟล์ที่ต้องสงสัยจะถูกกักกันไว้ก่อน ป้องกันไม่ให้ทำงานหรือสร้างความเสียหายเพิ่มเติม
  3. รายงานใน DirectAdmin — สามารถดูรายงานการสแกนได้ผ่าน DirectAdmin panel ซึ่งแสดงรายละเอียดครบถ้วน
  4. ตัดสินใจดำเนินการ — เจ้าของบัญชีสามารถเลือก delete, restore จาก quarantine, หรือ whitelist ไฟล์ที่แน่ใจว่าปลอดภัยได้

cpGuard runs real-time scanning on every file upload and modification, plus scheduled full-account scans. Detections trigger instant email alerts, automatic quarantine, and a detailed report in the DirectAdmin dashboard.

ข้อดีที่ทำให้ cpGuard แตกต่าง

สิ่งที่ทำให้ cpGuard โดดเด่นคือการที่ไม่ต้องพึ่งพาปลั๊กอินในระดับ CMS เช่น WordPress security plugins ซึ่งทำงานในระดับ application layer เท่านั้น แต่ cpGuard ทำงานในระดับ server ทำให้สามารถตรวจจับไฟล์อันตรายได้แม้ว่าไฟล์นั้นจะซ่อนอยู่ใน directory ที่ WordPress ไม่รู้จัก หรือถูกสร้างโดยผู้โจมตีโดยตรงผ่าน FTP

Unlike CMS-level security plugins that only scan within the application layer, cpGuard operates at the server level — catching threats hidden in directories outside the CMS, files uploaded directly via FTP, or injected through server-level exploits.

Security Highlight

cpGuard รวมในทุกแผน — ไม่มีค่าใช้จ่ายเพิ่ม

Malware · Backdoor · Web Shell · Virus · Phishing · Spam · Cryptominer

ผู้ให้บริการ hosting หลายรายในตลาดคิดค่าบริการ security scanning แยกต่างหาก แต่ AsiaGB รวม cpGuard ไว้ในทุกแผนโดยไม่มีค่าใช้จ่ายเพิ่มเติม เหมาะสำหรับเว็บไซต์ทุกขนาดที่ต้องการความปลอดภัยระดับองค์กร

ดูแผน Hosting AsiaGB

3. SSL Let's Encrypt ฟรีทุกเว็บ

ทุกโดเมนที่ host อยู่บน AsiaGB จะได้รับ SSL certificate จาก Let's Encrypt โดยไม่มีค่าใช้จ่าย SSL (Secure Sockets Layer) หรือในปัจจุบันเรียกว่า TLS (Transport Layer Security) คือเทคโนโลยีที่เข้ารหัสข้อมูลระหว่างเบราว์เซอร์ของผู้เยี่ยมชมกับเซิร์ฟเวอร์ของคุณ ทำให้ข้อมูลสำคัญ เช่น password, ข้อมูลบัตรเครดิต หรือข้อมูลส่วนตัว ไม่สามารถถูกดักจับระหว่างทางได้

Every domain hosted on AsiaGB receives a free Let's Encrypt SSL/TLS certificate, encrypting all data in transit between visitors' browsers and the server — protecting passwords, payment information, and personal data from interception.

วงจรชีวิตของ SSL Certificate บน AsiaGB

การทำงานของ SSL บน AsiaGB มีกระบวนการที่ราบรื่นและอัตโนมัติ ดังนี้:

SSL issuance is automatic upon DNS propagation. Certificates (90-day Let's Encrypt) renew automatically 30 days before expiry via ACME protocol — zero manual intervention required. Wildcard and SAN certificates are available on request.

HTTPS Redirect และ HSTS

การมี SSL certificate เพียงอย่างเดียวไม่เพียงพอ ผู้ใช้ยังคงสามารถเข้าเว็บด้วย HTTP (ไม่เข้ารหัส) ได้หากไม่มีการตั้งค่าเพิ่มเติม AsiaGB รองรับการตั้ง HTTPS redirect ผ่าน DirectAdmin และ .htaccess ดังนี้:

Beyond certificate issuance, AsiaGB supports Force HTTPS via DirectAdmin's SSL settings, HSTS header configuration through .htaccess, and tools to detect mixed-content issues that would undermine SSL protection.

ผลต่อ SEO และความน่าเชื่อถือ

นอกจากความปลอดภัย SSL ยังส่งผลบวกต่อ SEO โดยตรง Google ใช้ HTTPS เป็น ranking signal มาตั้งแต่ปี 2014 เว็บที่ไม่มี SSL จะถูก Google Chrome แสดงว่า "ไม่ปลอดภัย" ซึ่งทำให้ผู้เยี่ยมชมเกิดความไม่มั่นใจและมักปิดหน้าต่างทันที การมี SSL Let's Encrypt ฟรีจาก AsiaGB ช่วยให้เว็บของคุณรักษาความน่าเชื่อถือได้โดยไม่ต้องเสียค่าใช้จ่ายเพิ่ม

HTTPS is a confirmed Google ranking signal. Websites without SSL are flagged as "Not Secure" by Chrome, damaging credibility and increasing bounce rates. AsiaGB's free SSL removes this barrier entirely.

4. Backup 2 ครั้ง/เดือน เก็บ 1 ปี

ระบบ backup ของ AsiaGB ถือเป็นหนึ่งในฟีเจอร์ที่น่าประทับใจที่สุดเมื่อเทียบกับราคา บริการ backup 2 ครั้งต่อเดือน พร้อมเก็บสำรองนานถึง 1 ปี รวมอยู่ในทุกแผนโดยไม่มีค่าใช้จ่ายเพิ่มเติม

AsiaGB's backup policy — twice monthly, retained for a full year — is exceptionally generous for the price point. All plans include this at no additional cost.

ตารางเวลาการ Backup

การ backup เกิดขึ้น 2 ครั้งต่อเดือน โดยระบบจะทำในช่วงเวลากลางคืนที่ traffic น้อยเพื่อไม่กระทบประสิทธิภาพเว็บไซต์ Backup ครอบคลุม:

Each backup captures all files in public_html and sub-directories, all MySQL databases, email configurations, DNS records, and SSL settings — a complete snapshot of the entire hosting account.

วิธี Restore ข้อมูลผ่าน DirectAdmin

จากการทดสอบของเรา กระบวนการ restore ข้อมูลผ่าน DirectAdmin มีขั้นตอนที่ตรงไปตรงมา ผู้ใช้สามารถทำเองได้โดยไม่ต้องติดต่อ support:

  1. เข้าสู่ระบบ DirectAdmin ด้วยข้อมูล login ของบัญชี
  2. ไปที่เมนู System Info & Files → Create/Restore Backups
  3. เลือก backup ที่ต้องการ restore จากรายการที่แสดง พร้อมวันที่ทำ backup
  4. เลือกว่าจะ restore ทั้งหมด หรือเลือก restore เฉพาะส่วน เช่น เฉพาะ database หรือเฉพาะไฟล์
  5. ยืนยันการ restore และรอระบบดำเนินการ ซึ่งใช้เวลาแตกต่างกันตามขนาดข้อมูล
  6. ตรวจสอบเว็บไซต์หลังจาก restore เสร็จสมบูรณ์

Restoring backups through DirectAdmin is a self-service process: navigate to System Info & Files → Create/Restore Backups, select the desired backup date, choose full or partial restore (files only, databases only, or specific components), and confirm. No support ticket needed for standard restores.

ข้อดีของการเก็บ Backup 1 ปี

การเก็บ backup นาน 1 ปีมีประโยชน์ที่หลายคนอาจมองข้าม ในกรณีที่เว็บถูก hack และ malware แฝงตัวอยู่นานโดยไม่มีใครสังเกตเห็น (ซึ่งเกิดขึ้นบ่อยกับ WordPress ที่ไม่ได้อัปเดต) การมี backup ที่เก่าพอจะทำให้สามารถ restore กลับไปก่อนเหตุการณ์ที่เกิดขึ้นได้ แทนที่จะต้องสร้างเว็บใหม่จากศูนย์

Year-long backup retention is critical for detecting slow-burn compromises — malware that hides dormant for weeks or months before activating. With 12 months of history, you can restore to a clean state pre-infection even if the breach went undetected for a long time.

5. DirectAdmin Security Features

DirectAdmin ไม่ได้เป็นเพียง control panel สำหรับจัดการไฟล์และฐานข้อมูลเท่านั้น แต่ยังมีฟีเจอร์ความปลอดภัยที่ครบครันในตัวเอง AsiaGB ใช้ DirectAdmin เป็น control panel มาตรฐานสำหรับทุกแผน

DirectAdmin, AsiaGB's standard control panel across all plans, includes robust built-in security features beyond basic file management.

Two-Factor Authentication (2FA)

DirectAdmin รองรับ Two-Factor Authentication (2FA) ด้วย TOTP (Time-based One-Time Password) ซึ่งใช้งานร่วมกับ app เช่น Google Authenticator หรือ Authy จากการทดสอบของเรา การเปิดใช้ 2FA ทำได้ง่ายมากผ่าน DirectAdmin โดยเข้าไปที่ Account Manager → Two-Factor Authentication แล้ว scan QR code ด้วย authenticator app ของคุณ หลังจากนั้น ทุกครั้งที่ login จะต้องใส่รหัส 6 หลักจาก app เพิ่มเติม ทำให้แม้ password จะรั่วไหลก็ยังไม่สามารถ login ได้

DirectAdmin supports TOTP-based 2FA compatible with Google Authenticator and Authy. Enable it under Account Manager → Two-Factor Authentication by scanning a QR code. Even if your password is compromised, attackers cannot access the account without the time-based token.

IP Blocking และ Brute-Force Protection

DirectAdmin มีระบบ brute-force protection ในตัว ที่จะ block IP โดยอัตโนมัติหลังจากมีการพยายาม login ผิดหลายครั้งเกินกำหนด นอกจากนี้ผู้ใช้ยังสามารถ:

DirectAdmin's IP Manager allows manual IP blocking, login IP whitelisting, login history review, and new-IP login alerts — giving administrators granular control over who can access the control panel.

Password Policy และ Account Security

DirectAdmin บังคับใช้ password policy ที่เข้มแข็ง โดย password จะต้องมีความซับซ้อนเพียงพอและมีความยาวขั้นต่ำ นอกจากนี้ยังมีระบบ:

DirectAdmin enforces password complexity requirements, provides real-time strength metering, manages separate credentials for FTP/email/databases, and supports session timeout and login port customization.

File Manager Permissions

File Manager ใน DirectAdmin ช่วยให้ตรวจสอบและแก้ไข file permission ได้ง่าย การตั้ง permission ที่ถูกต้องมีความสำคัญมากต่อความปลอดภัย:

Proper file permissions are critical: PHP/HTML files should be 644, directories 755, and sensitive config files like wp-config.php should be 600 — readable and writable only by the owner. DirectAdmin's File Manager makes bulk permission changes straightforward.

6. Firewall และ DDoS Protection

ระดับ network ของ AsiaGB มีการป้องกัน DDoS (Distributed Denial of Service) ซึ่งเป็นการโจมตีที่พยายาม flood traffic จำนวนมหาศาลเข้ามายังเซิร์ฟเวอร์เพื่อทำให้ล่ม การป้องกันในระดับ network นี้ทำงานก่อนที่ traffic จะเข้าถึงเซิร์ฟเวอร์จริงๆ

AsiaGB's network-level DDoS mitigation filters malicious traffic before it reaches the server, protecting against volumetric attacks without requiring any configuration from the account holder.

Firewall ระดับ Server

นอกเหนือจาก DDoS protection ระดับ network แล้ว เซิร์ฟเวอร์ยังมี firewall ระดับ OS ที่ควบคุมการเข้าถึง port ต่างๆ โดย:

The server-level firewall opens only essential ports, blocks all others by default, auto-bans IPs exhibiting suspicious behavior (port scanning, brute-force), and applies HTTP request rate limiting to prevent application-layer DDoS.

ModSecurity Web Application Firewall

เซิร์ฟเวอร์ของ AsiaGB ติดตั้ง ModSecurity WAF (Web Application Firewall) ที่ทำงานในระดับ web server (Apache/LiteSpeed) เพื่อกรอง HTTP request ที่อันตรายออกก่อนที่จะเข้าถึง PHP application ของคุณ ModSecurity ช่วยป้องกัน:

ModSecurity WAF filters HTTP requests at the web server layer, blocking SQL injection, XSS, Remote/Local File Inclusion, and directory traversal attacks before they reach your PHP application.

7. HTTPS บังคับและ Redirect อัตโนมัติ

การบังคับใช้ HTTPS เป็นขั้นตอนสำคัญที่หลายเว็บไซต์มักมองข้าม การมี SSL certificate แต่ไม่บังคับ HTTPS หมายความว่าผู้ใช้ที่พิมพ์ที่อยู่เว็บแบบ http:// จะยังคงเชื่อมต่อโดยไม่เข้ารหัส AsiaGB ช่วยให้ตั้งค่าการบังคับ HTTPS ได้อย่างง่ายดาย

Having an SSL certificate is not enough — enforcing HTTPS is equally critical. Users who type http:// still connect unencrypted unless a redirect is in place. AsiaGB makes HTTPS enforcement straightforward.

วิธีตั้ง Force HTTPS ผ่าน DirectAdmin

จากการทดสอบของเรา การตั้ง Force HTTPS บน AsiaGB ทำได้ใน 2 วิธีหลัก:

วิธีที่ 1 — ผ่าน DirectAdmin: เข้า DirectAdmin → SSL Certificates → เลือกโดเมน → เปิด option "Force SSL with https redirect" ระบบจะตั้ง redirect rule ให้อัตโนมัติโดยไม่ต้องแก้ไข .htaccess ด้วยตัวเอง

วิธีที่ 2 — ผ่าน .htaccess: สำหรับผู้ใช้ที่ต้องการควบคุมเพิ่มเติม สามารถเพิ่มโค้ดต่อไปนี้ใน .htaccess ที่อยู่ใน public_html:

Force HTTPS via DirectAdmin SSL settings (one-click toggle) or .htaccess (301 permanent redirect rule). The DirectAdmin option is recommended as it handles edge cases and subdomain redirects automatically.

www ไปยัง non-www (หรือกลับกัน)

การตั้ง canonical URL ที่ถูกต้องก็เป็นส่วนหนึ่งของความปลอดภัยด้านข้อมูลด้วย เพราะ Google มองว่า www.example.com และ example.com เป็นเว็บคนละเว็บ ผู้ใช้ควรเลือกรูปแบบใดรูปแบบหนึ่งและ redirect อีกรูปแบบมาหา ซึ่งทำได้ง่ายผ่าน DirectAdmin's Domain Pointer หรือ .htaccess

Canonical URL consistency (www vs non-www) matters for both SEO and security. Redirect one form to the other permanently using DirectAdmin's Domain Pointer or .htaccess to avoid duplicate content and potential session hijacking across domains.

HTTP Strict Transport Security (HSTS)

HSTS เป็น security header ที่บอก browser ว่า "เว็บนี้ใช้ HTTPS เท่านั้น จำไว้เป็นเวลา X วัน" เมื่อ browser เห็น header นี้แล้ว แม้ผู้ใช้จะพิมพ์ http:// หรือคลิกลิงก์ HTTP browser จะเปลี่ยนเป็น HTTPS เองโดยอัตโนมัติก่อนส่ง request ออกไป ซึ่งป้องกัน SSL stripping attack ได้อย่างมีประสิทธิภาพ เพิ่มได้ใน .htaccess ด้วย Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

HSTS instructs browsers to always use HTTPS, even if the user types http:// — preventing SSL stripping attacks. Add via .htaccess with Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" to enforce HTTPS at the browser level, not just server-side redirects.

8. แนวปฏิบัติที่ดีสำหรับเจ้าของเว็บ

ระบบความปลอดภัยของ AsiaGB ช่วยได้มาก แต่ความปลอดภัยที่แข็งแกร่งต้องอาศัยความร่วมมือจากเจ้าของเว็บด้วย ต่อไปนี้คือแนวปฏิบัติที่ทีมงาน CloudPicked แนะนำจากประสบการณ์จริง

AsiaGB's server-side security is robust, but the strongest protection comes from combining it with good practices at the application level. Here are the key recommendations from our hands-on experience.

Password ที่แข็งแกร่งและไม่ซ้ำกัน

Password ที่อ่อนแอเป็นสาเหตุอันดับต้นๆ ของการถูก hack แนะนำให้ใช้ password ที่มีความยาวอย่างน้อย 16 ตัวอักษร ผสมตัวพิมพ์ใหญ่-เล็ก ตัวเลข และสัญลักษณ์ และที่สำคัญ ต้องใช้ password ที่แตกต่างกันสำหรับ DirectAdmin, FTP, Email, Database, WordPress admin และ Registrar — ไม่ซ้ำกันเลย เพราะหาก password หนึ่งรั่ว จะได้ไม่กระทบส่วนอื่น แนะนำให้ใช้ Password Manager เช่น Bitwarden หรือ 1Password

Use unique passwords of 16+ characters mixing uppercase, lowercase, numbers, and symbols for every service: DirectAdmin, FTP, email, databases, WordPress admin, and your domain registrar. A password manager like Bitwarden eliminates the need to memorize them.

อัพเดท WordPress และ Plugin สม่ำเสมอ

จากการสำรวจ WordPress คิดเป็นกว่า 90% ของ hosting account ที่ถูก hack ส่วนใหญ่เกิดจาก plugin ที่มีช่องโหว่และไม่ได้อัพเดท ควรปฏิบัติดังนี้:

Outdated plugins are the leading cause of WordPress compromises. Update WordPress core, all plugins, and themes weekly. Delete inactive plugins — they remain vulnerable even when deactivated. Install only from reputable developers with active maintenance histories.

File Permission ที่ถูกต้อง

File permission ที่ตั้งผิดเป็นช่องทางที่แฮกเกอร์มักใช้ประโยชน์ ควรตรวจสอบ permission ผ่าน DirectAdmin File Manager หรือ FTP client และตั้งค่าให้ถูกต้อง: directory 755, file 644, config file 600 อย่าตั้ง permission เป็น 777 (ทุกคนเขียนได้) เด็ดขาด เพราะเป็นช่องโหว่ร้ายแรง

Never set directory or file permissions to 777. Directories should be 755, PHP/HTML files 644, and sensitive configuration files 600. Wrong permissions are a common attack vector that cpGuard and server firewalls cannot fully compensate for.

ลบไฟล์ที่ไม่จำเป็นออก

ไฟล์ที่ไม่ได้ใช้งานแล้วแต่ยังอยู่บน server เช่น ไฟล์ backup (.zip, .tar.gz), ไฟล์ installer ที่ใช้เสร็จแล้ว, ไฟล์ test หรือ development file ควรลบออกทันที ไฟล์เหล่านี้อาจมีข้อมูล config หรือข้อมูลสำคัญที่แฮกเกอร์สามารถเข้าถึงและนำไปใช้ประโยชน์ได้

Remove all unnecessary files from your server: old backup archives (.zip/.tar.gz), completed installer scripts, test pages, and development files. These often contain sensitive configuration data and represent easy targets for automated scanners.

ตรวจสอบ Email Deliverability

Email spam ที่ออกจาก hosting account ของคุณโดยไม่รู้ตัวเป็นสัญญาณสำคัญว่าบัญชีอาจถูก compromise ควรตรวจสอบ email log ใน DirectAdmin เป็นระยะ และหากพบว่ามี email จำนวนมากออกไปผิดปกติ ควรรีบเปลี่ยน password ทุก service และแจ้ง AsiaGB support ทันที

Unexpected outbound email volume is a key indicator of a compromised account. Periodically review email logs in DirectAdmin, and if anomalies appear, change all passwords immediately and contact AsiaGB support via ticket, Line, or email.

9. สรุป

จากการทดสอบของเรา AsiaGB มีระบบความปลอดภัยที่ครบครันสำหรับ shared hosting ในระดับราคาที่จับต้องได้ ฟีเจอร์หลักที่โดดเด่น ได้แก่ cpGuard ที่ทำงานอัตโนมัติตลอด 24 ชั่วโมง, SSL Let's Encrypt ฟรีพร้อม auto-renew ไม่ต้องดูแลเอง, Backup 2 ครั้ง/เดือนที่เก็บไว้นานถึง 1 ปี, และ DirectAdmin ที่มีเครื่องมือความปลอดภัยพร้อมใช้งานทุกอย่าง

In our testing, AsiaGB delivers an enterprise-grade security stack at an accessible price point. The combination of automated cpGuard malware scanning, free auto-renewing SSL, year-long backup retention with self-service restore, and DirectAdmin's built-in security toolset creates a well-rounded protection layer for websites of all sizes.

สำหรับเจ้าของเว็บที่กำลังมองหา hosting ที่ให้ความสำคัญกับความปลอดภัยโดยไม่ต้องเสียค่าใช้จ่ายเพิ่มเติม AsiaGB ด้วยประสบการณ์กว่า 19 ปี เซิร์ฟเวอร์ในไทยและสิงคโปร์ และ SSD storage พร้อม uptime 99% เป็นตัวเลือกที่น่าพิจารณาสำหรับเว็บไทยทุกประเภท ไม่ว่าจะเป็น blog, e-commerce, หรือเว็บองค์กร

For Thai website owners seeking comprehensive security without add-on fees, AsiaGB — with its 19 years of experience, Thailand and Singapore server locations, SSD storage, and 99% uptime — presents a compelling option across all website types from personal blogs to e-commerce and corporate sites.

เริ่มต้นกับ AsiaGB วันนี้

Hosting เริ่มต้น 500฿/ปี รวม cpGuard · SSL · Backup 1 ปี · DirectAdmin · Support ภาษาไทย

ดูแผนและราคา AsiaGB

คำถามที่พบบ่อย (FAQ)

cpGuard ต่างจาก antivirus plugin ของ WordPress อย่างไร?

cpGuard ทำงานในระดับ server โดยตรง ในขณะที่ security plugin ของ WordPress ทำงานในระดับ application layer เท่านั้น ข้อดีของ cpGuard คือสามารถตรวจจับไฟล์อันตรายได้แม้จะอยู่นอก WordPress directory หรือถูกอัพโหลดผ่าน FTP โดยตรง นอกจากนี้ cpGuard ยังทำงานได้แม้ WordPress จะ crash หรือ malware ปิดการทำงานของ plugin ไป

SSL Let's Encrypt ของ AsiaGB จะ renew อัตโนมัติจริงหรือ ต้องทำอะไรเพิ่มไหม?

จากการทดสอบของเรา SSL certificate จะ renew โดยอัตโนมัติก่อนหมดอายุ 30 วัน ผ่าน ACME protocol ผู้ใช้ไม่ต้องทำอะไรทั้งสิ้น ระบบจัดการให้ครบ ยกเว้นกรณีที่โดเมนถูก point ออกไปจาก server ของ AsiaGB แล้ว ซึ่งในกรณีนั้นจะ renew ไม่ได้เพราะ domain validation จะล้มเหลว

Backup ของ AsiaGB ครอบคลุมทุก database ในบัญชีหรือเปล่า?

ใช่ Backup ครอบคลุมทั้งไฟล์ทุกไฟล์และ MySQL database ทุก database ในบัญชี รวมถึงการตั้งค่า email, DNS zone, และ SSL configuration ด้วย สามารถ restore ทั้งหมดหรือเลือก restore เฉพาะส่วนได้ผ่าน DirectAdmin โดยไม่ต้องติดต่อ support

ถ้าเว็บถูก hack ต้องทำอะไรบ้าง และ AsiaGB ช่วยได้แค่ไหน?

ขั้นแรกให้ตรวจสอบ cpGuard report ใน DirectAdmin เพื่อดูว่าไฟล์ไหนถูก flag ว่าอันตราย จากนั้น restore จาก backup ที่เก่าพอ (ก่อนเหตุการณ์), เปลี่ยน password ทุก service, อัพเดท WordPress และ plugin ทั้งหมด และติดต่อ support ของ AsiaGB ผ่าน ticket, Line, หรือ email เพื่อขอความช่วยเหลือเพิ่มเติม ทีม support พูดภาษาไทยได้ครบ

DirectAdmin 2FA รองรับ authenticator app อะไรบ้าง?

DirectAdmin รองรับ TOTP (Time-based One-Time Password) มาตรฐาน ซึ่งใช้งานได้กับ app ทั่วไปทุกตัว ได้แก่ Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, และ app TOTP อื่นๆ เพียงแค่ scan QR code จาก DirectAdmin settings ก็เริ่มใช้งานได้ทันที

Hosting ราคา 500฿/ปี ได้รับ cpGuard และ Backup ครบหรือเปล่า หรือเฉพาะแผนแพง?

ทุกแผนของ AsiaGB ได้รับฟีเจอร์ความปลอดภัยครบเหมือนกันทุกรายการ ไม่ว่าจะเป็นแผน 5GB ราคา 500฿/ปี หรือแผน 35GB ราคา 3,500฿/ปี ต่างได้รับ cpGuard, SSL, Backup 2 ครั้ง/เดือนเก็บ 1 ปี, DirectAdmin พร้อมทุก security feature ความแตกต่างระหว่างแผนอยู่ที่ขนาด storage เท่านั้น