Archive for June, 2009

As Mitnick Knows, Security Not Always in Your Control

by FireHost Evangelist on June 30th, 2009

Kevin Mitnick, the most well known hacker of the 1990′s had his personal and business websites compromised and defaced recently, and if you query Mitnick’s domain today, you still see remnants of the hack. Words like:mitnickHacked2

$ whois mitnicksecurity.com

MITNICKSECURITY.COM.HACKED.BY.NERD.FROM.WEB-HACK.COM
MITNICKSECURITY.COM

In a phone conversation today, Mitnick disclosed to FireHost’s Chief Security Officer that he was using secure hosting practices on his site, but the hackers got to his website through his hosting company’s DNS provider. They compromised the control panel for his domain names and redirected his site to a defaced version.

(more…)

Security Investments Top IT Budgets

by FireHost Evangelist on June 30th, 2009

Despite a challenging economy, many companies are making room in their budgets for investments in information security initiatives.

According to a survey by Robert Half Technology, seven out of ten CIOs interviewed reported their companies would be investing in new information technology initiatives over the next year. 43% of the respondents overall reported information security as a top priority, and in the budgetfinancial services and transportation sectors, information security was cited most often as the top priority.

“Although times are lean, many companies are finding that they can’t afford to postpone IT investments that lead to increased security, efficiencies or revenues,” stated Dave Willmer, Executive Director of Robert Half Technology. “Organizations also are trying to make sure they are prepared for growth when conditions improve, and enhancing their IT infrastructure is part of that process.”

Over the past year, there has been a significant rise in the number of malicious attacks on company websites. Symantec identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.

(more…)

Nine-Ball Mass Injection Attack has Compromised 40,000 Websites to Date

by FireHost Evangelist on June 23rd, 2009

9ballWebsense security labs have been tracking the Nine-Ball mass compromise attack since early June. They report to date, that over 40,000 legitimate Web sites have been compromised and are actively infected with an information-stealing trojan.

The Nine-Ball attack is deployed when a user visits a legitimate website that has been infected with the malicious code. From the legitimate website, unsuspecting users are redirected behind the scenes through a series of different sites owned by the Nine-Ball’s hackers.

(more…)

Drupal Open Source Popularity on the Rise

by FireHost Evangelist on June 19th, 2009

DrupalRiseJust three years ago, Drupal was a little-known, open source content management system (CMS) predominately used by nonprofits and small businesses who were enticed by the ability to create dynamic content for free using Drupal’s open source software platform. Since then, Drupal has become a staggering success with thousands of professional and casual users around the world.

Drupal’s Massive Appeal to Companies
The list of entities using Drupal includes large companies, like Sony and Warner Brothers. Organizations such as Human Rights Watch and the federal government’s Recovery.gov use Drupal too. The reasons for Drupal’s widespread appeal are many. Aside from being completely free to use, Drupal’s open source nature encourages active enhancement by thousands of developers around the world. The bottom line is simple, Drupal is constantly becoming better and better, without costing a dime.

The vibrant Drupal developer community includes dozens of “Drupal Camps” throughout the world, each with hundreds of attendees. Hosted by experienced Drupal users and developers who volunteer their time and knowledge, these camps are designed to foster innovation of the Drupal platform, educate new users, and spread the use of Drupal among web developers.

(more…)

Journalist Turns Hacker in Under One Hour

by FireHost Evangelist on June 16th, 2009

hackerIn less than one hour last Thursday, Internet security journalist Elinor Mills mastered the tools of the hacker trade at McAfee’s Malware Experience event.

It takes “as little as $300 to infect several Windows clients and take complete control of them in a test environment,” Mills reports. By using real samples of malicious code, she was able to infect PCs with a Sub Seven Trojan and gain remote access to the machines. Once inside the computers, she was exposed to some of the malicious tricks hackers can play on unsuspecting malware victims.

(more…)