What Happens When Your Website Gets Hijacked part 2

The fine people at WordFence Security have also recently published information on what happens when web sites get hijacked.  They gathered this information by surveying their client and blog readers.  The results are in the infographic below.

what_attackers_do_to_wordpress_sites-1024x573

Taking a site down or site defacement makes up 25% of the malicious actions, which I found surprising.  The other items on the list ...

Continue Reading →
0

What Happens When Your Website Is Hijacked?

I don’t often re-post other people’s web content, but the video below from Sucuri is worth the look if you are interested in learning why an attacker would want your website, and what they could possibly do with it, how that affects your reputation, and most importantly, what you could do to prevent it in the first place.  If you have the time, take a look.  The running time is 25 minutes.  With the Q&A Session, it goes out to 40 ...

Continue Reading →
0

No Fooling – How to Secure WordPress

WordPresslogoI know it’s April Fool’s Day, but this is a straight up serious post.  If you own, operate, host, support, or develop WordPress sites, this article is for you.

We have written a few articles covering the subject of WordPress security.  I recently received an email from John Stevens over at HostingFacts.com, inviting me to review their excellent tutorial, 28 Ways ...

Continue Reading →
0

Crypto-Ransomware Round-Up

cryptolockerSome of the nastiest exploits going around are the many variants of the CryptoLocker and CryptoWall malware that encrypt all your personal files and hold them for ransom.  Payment in bitcoin is required, in amounts starting at $200 and ranging upward to the $17,000 (400 BTC) that Hollywood Presbyterian Hospital just paid to unlock their files.  Or even more.  The amount will be whatever the attackers think they can extract from the victim.

  • The latest ...
Continue Reading →
0

Alert: WPEngine User Credentials Breached

WordPresslogoJust received an email from WordFence, the WordPress security plugin-developer, that popular WordPress hosting company WPEngine had a breach that may have included customer user name and password information.  The full text of the email I received follows.

“We learned about an hour ago that there has been a data breach at WPEngine. Some of their customer login credentials have been exposed. If ...

Continue Reading →
0

000Webhost Loses Plaintext Passwords

000WebHost

This comes under the heading of “know who you are doing business with.”  Web hosting company 000webhost.com was breached this week and over 13 million customer records were stolen and posted for sale on the Internet.  The data includes customer names, emails and passwords in plaintext  (meaning the passwords were unencrypted).  Storing passwords in an unencrypted form should be a criminal act in itself, ...

Continue Reading →
0

When Bad Things Happen To Good Web Sites

website-securityToday we are going to take a deeper dive into the subject of website security.  Web servers can be  breached in a number of ways, but the most common is simply stealing your user ID and password, either through a clever spearphishing email, or an automated brute force password cracking program.  The second most common way is through software vulnerabilities in the web site code itself that opens it up ...

Continue Reading →
0

WordPress Security Tips

WordPresslogoAs we have mentioned in previous postings, WordPress has become one of the world’s leading web design tools, with a 27% share of all web sites, and a 65% share of CMS or Content Management System type websites.  Because it is an open source product that is free to use, it has become hugely popular.  We have been designing in WordPress ourselves for ...

Continue Reading →
0

WordPress Site Owners – Update Now

WordPresslogoJust a quick note to my WordPress pals – the latest update, WordPress 4.2.3, has an import fix for a cross site scripting (XSS) vulnerability that leaves your site vulnerable to attack.  According to Sophos:

“The flaw allows WordPress users who have Contributor or Author roles to add javascript to a site (something normally reserved for Editors and Administrators) using specially crafted shortcodes.

Attackers ...

Continue Reading →
0

Have a WordPress Site? Better Secure It!

WordPresslogoWordPress has become an incredibly popular web design platform, and currently has about a 25% share of all web sites on the Internet.  As an open-source software product that is free to download and use, with a great support and documentation through WordPress.org, and a huge, international development community providing an endless array of themes, plug-ins and widgets, it is easy ...

Continue Reading →
0
Page 2 of 3 123