<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; Application Protection</title>
	<atom:link href="http://www.fireblog.com/tag/application-protection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Hackers Exploit Microsoft Vulnerabilities</title>
		<link>http://www.fireblog.com/hackers-exploit-microsoft-vulnerabilities/</link>
		<comments>http://www.fireblog.com/hackers-exploit-microsoft-vulnerabilities/#comments</comments>
		<pubDate>Tue, 19 May 2009 14:00:21 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability Exploitation]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1008</guid>
		<description><![CDATA[In just the last few months, Microsoft has announced two vulnerabilities discovered in their popular Office application suite. This is a good example of a vulnerability in programs on your computer, and similar holes exist for web applications.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1263" title="windows-hack3" src="http://www.fireblog.com/wp-content/uploads/2009/05/windows-hack3.jpg" alt="windows-hack3" width="190" height="198" />On FireBlog, we&#8217;ve discussed several vulnerabilities found in open source applications, but it&#8217;s important to mention that vulnerabilities exist in even the most protected application code. Even Microsoft, which has a 1:1 ratio of programmers to quality control analysts, cannot always prevent their software from containing exploitable vulnerabilities.</p>
<p>In just the last few months, Microsoft has announced two vulnerabilities discovered in their popular Office application suite. Specifically, these vulnerabilities affect Excel and PowerPoint, and both flaws allow hackers to install malicious software or even hijack a computer completely. For more information about resolving these two vulnerabilities, read the <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security_hardware_and_software&amp;articleId=9131040&amp;taxonomyId=145&amp;intsrc=kc_top" target="_blank">full report by <em>Computer World</em></a>.</p>
<p><span id="more-1008"></span></p>
<p>This is a good example of a vulnerability in programs on your computer, and similar holes exist for web applications. As we&#8217;ve explained previously, web application vulnerabilities found in Drupal or WordPress can just as easily be used by malicious hackers to exploit your website and customers. It&#8217;s important to take an active role in securing your website, with secure hosting such as FireHost.</p>
<p>Although every application will contain vulnerabilities of some kind, you can still guard against the exploitation of your website&#8217;s applications by malicious hackers. <a href="http://www.firehost.com/" target="_blank">FireHost</a> protects your company and valued customers with industry-leading security, including sophisticated web application firewalls to prevent hackers from exploiting the applications running your website.</p>
<p>The value of making your customers feel secure when dealing with your company website is immeasurable. Discover the difference FireHost secure web hosting will make for your company, visit <a href="http://www.firehost.com/" target="_blank">FireHost.com</a> and <a href="http://www.firehost.com/company/contact-us" target="_blank">contact a FireHost Agent today</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/hackers-exploit-microsoft-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Imposes Strict Data Loss Policies</title>
		<link>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/</link>
		<comments>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/#comments</comments>
		<pubDate>Fri, 15 May 2009 14:00:31 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Online Backup]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[Content Management Solution]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Customer Relationship Management]]></category>
		<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[FireVault]]></category>
		<category><![CDATA[UK Data Loss Policy]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=949</guid>
		<description><![CDATA[Following serious breaches in data security, most notably a loss of 25 million records on two unencrypted discs from Britain's Revenue &#038; Customs, the United Kingdom is implementing strict data loss policies on governmental organizations in the UK. Although your company may not deal in national secrets, your company should consider similar measures to prevent data loss, which can prevent the loss of confidential information, trade secrets, and vital business and customer records.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1219" title="uk-data-loss1" src="http://www.fireblog.com/wp-content/uploads/2009/05/uk-data-loss1.jpg" alt="uk-data-loss1" width="220" height="231" />Following serious breaches in data security, most notably a <a href="http://www.computerweekly.com/Articles/2008/06/27/231267/hmrc-left-the-door-open-to-data-loss.htm" target="_blank">loss of 25 million records on two unencrypted discs</a> from Britain&#8217;s Revenue &amp; Customs, the United Kingdom is implementing strict data loss policies on governmental organizations in the UK.</p>
<p>These new strict data loss prevention measures include file encryption, digital rights management, storage policies, data classification, and new staff security procedures. For the interesting specifics, <a href="http://www.computerweekly.com/Articles/2009/04/24/235776/stamp-out-data-loss.htm" target="_blank">click here</a>.</p>
<p>Although your company may not deal in national secrets, your company should consider similar measures to prevent data loss, which can prevent the loss of confidential information, trade secrets, and vital business and customer records.</p>
<p><span id="more-949"></span></p>
<p><a href="http://www.firehost.com/" target="_blank">Protecting your business</a> online means you have consciously taken a look at the cost risk and business risk of having all your data compromised. Can you afford to have your lead-generating website down for a period of time? Is there a competitor that would benefit from knowing your company&#8217;s intellectual property? Can you afford to have your clients&#8217; entrusted data hacked and made public, or worse exploited?</p>
<p>With growing eCommerce and so many companies using Content Management Solutions and Customer Relationship Management solutions, protecting your company in its industry requires industry-leading security measures. Some advanced security measures are not found with over 90% of hosting providers including advanced web application firewalls, dynamic intrusion detection, and sophisticated traffic analysis software. Proper security hardware, software, dedicated personnel and proactive protection prevents malicious hackers from stealing information from you and your clients.</p>
<p>Another part of protecting your business online is reviewing your business continuity plan. What happens when a fire occurs in your building destroying your local computers or servers, or a natural disaster or a virus takes out a vital source of information? You can protect your records, files, and databases using <a href="http://www.firevault.com" target="_blank">FireVault</a>, which encrypts and backs up your data from any number of computers and servers to a secure, cloud sever in the U.S. or UK.</p>
<p>Be leary of hosting companies that provide only hacker reports as their measure of protection. Your business cannot afford to wait until after a breach occurs to be told there&#8217;s a problem. The damage is done. Real secure hosting protects you proactively, mitigating and eliminating attacks starting at the HTTP level against your data before they get to your servers. The consequences of inaction could be insurmountable for businesses of any size. Online threats require businesses of all sizes to ensure they <a title="Secure Web Hosting" href="http://www.firehost.com/company/contact-us" target="_blank">have secure web hosting</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Maximize Joomla CMS with Secure Web Hosting</title>
		<link>http://www.fireblog.com/maximize-joomla-cms-with-secure-web-hosting/</link>
		<comments>http://www.fireblog.com/maximize-joomla-cms-with-secure-web-hosting/#comments</comments>
		<pubDate>Tue, 12 May 2009 14:00:57 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[CMS Web Hosting]]></category>
		<category><![CDATA[Joomla Hosting]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=210</guid>
		<description><![CDATA[Despite an odd sounding name, Joomla is an award-winning content management system (CMS), enabling users to build dynamic websites and powerful online applications. Nearly anyone can build and manage a site after finding a good, secure web host.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1198" title="joomla-hosting" src="http://www.fireblog.com/wp-content/uploads/2009/05/joomla-hosting1.jpg" alt="joomla-hosting" width="229" height="205" />Despite an odd sounding name, <a href="http://www.joomla.org" target="_blank">Joomla</a> is an award-winning content management system (CMS), enabling users to build dynamic websites and powerful online applications.</p>
<p>If you&#8217;re not familiar, a content management system (CMS) is software that tracks, manages and displays every piece of content on your website. Content can include simple text, photos, music, videos, documents, or anything else you want on your website.</p>
<p>Joomla is one of the most popular website building and management software platforms due in large part to it&#8217;s ease-of-use and deep extensibility. Joomla is suitable for a wide variety of applications like powering corporate websites, online magazines, e-commerce portals, and small business websites around the world. This is just a handful of the popular websites powered by Joomla.</p>
<p><span id="more-210"></span></p>
<ul>
<li>IHOP (Restaurants) &#8211; <a href="http://www.ihop.com/" target="_blank">http://www.ihop.com</a></li>
<li>Harvard University &#8211; <a href="http://gsas.harvard.edu/" target="_blank"> http://gsas.harvard.edu</a></li>
<li>MTV Networks Quizilla  &#8211; <a href="http://www.quizilla.com/" target="_blank">http://www.quizilla.com</a></li>
<li>L.A. Weekly &#8211; <a href="http://www.laweekly.com/" target="_blank"> http://www.laweekly.com</a></li>
</ul>
<p>The major advantage of an open source CMS like Joomla is that it&#8217;s free <em><strong>and</strong></em> it requires almost zero technical skill or knowledge to manage. Security can be a key disadvantage for open source solutions however because open source applications are often targets for <a href="http://www.cmswire.com/cms/web-cms/harvard-hack-betrays-joomla-vulnerabilties-002332.php" target="_blank">exploitation by hackers</a> or virus deployments.</p>
<p>FireHost&#8217;s secure web hosting environment helps Joomla users sleep peacefully at night by delivering advanced web application firewall (WAF) protection. Additionally, installing Joomla on a FireHost-managed hosting solution is a simple one-click process that empowers your company to start building a dynamic website immediately.</p>
<p>It couldn&#8217;t be easier to get started. With Joomla, nearly anyone can build and manage a site. With FireHost&#8217;s <a title="Joomla Hosting" href="http://www.firehost.com/secure-hosting/joomla" target="_blank">secure web hosting environment</a>, Joomla users can have a secure, worry-free site built on a great open-source platform. More information on secure Joomla hosting is available on our website, or you can <a href="http://www.firehost.com/company/contact-us" target="_blank">contact a FireHost consultant</a> now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/maximize-joomla-cms-with-secure-web-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How do you steal a fighter jet?</title>
		<link>http://www.fireblog.com/how-do-you-steal-a-fighter-jet/</link>
		<comments>http://www.fireblog.com/how-do-you-steal-a-fighter-jet/#comments</comments>
		<pubDate>Fri, 08 May 2009 14:00:27 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Hacker Prevention]]></category>
		<category><![CDATA[Redundant Network Infrastructure]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Virus Protection]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=947</guid>
		<description><![CDATA[It's an astonishing question. How would someone go about stealing the most advanced fighter jet in the American military arsenal? The answer: You break into the most secure computer network in the world and steal the plans.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1117" title="jsf-352" src="http://www.fireblog.com/wp-content/uploads/2009/05/jsf-352.jpg" alt="jsf-352" width="200" height="271" />It&#8217;s an astonishing question. How would someone go about stealing the most advanced fighter jet in the American military arsenal? The answer: You break into the most secure computer network in the world and steal the plans.</p>
<p>According to <a href="http://www.cnn.com/2009/US/04/21/pentagon.hacked/" target="_blank">recent reports</a>, hackers have systematically stolen thousands of files about the U.S. military&#8217;s new Joint Strike Fighter, our most advanced fighter in history. Specifically, hackers stole files concerning the design and electrical system of the new fighter, by infiltrating Pentagon and defense contractor computers.</p>
<p>Additionally, hackers were able to break into air traffic control systems operated by the U.S. Air Force. This gave them the opportunity to view the location of any U.S. military aircraft, in real time. While Department of Defense and Pentagon officials believe attacks such as these are the result of foreign states, rather than the work of individuals or small groups, such extraordinary attacks raise numerous questions about computer security in general.</p>
<p><span id="more-947"></span></p>
<p><em>&#8220;If hackers can infiltrate the Pentagon, what could they do to my small business?&#8221;</em></p>
<p>For malicious hackers, the potential of billions in profit from the theft of information from businesses of all sizes presents an extraordinary opportunity. Considering the relative ease of penetrating a small businesses credit card database, the limited risk of exposure to legal action, and a plentiful supply of easy targets, it&#8217;s becoming a matter of &#8220;when&#8221; not &#8220;if&#8221; your business will be attacked.</p>
<p>The time to protect your business is before an attack occurs, rather than afterwards. Attacks resulting in compromised data could mean disaster for your business. If your company does business online, you will need comprehensive security measures from a secure web hosting provider. Protection of your business online is a comprehensive strategy, much of which is executed at the hosting level. As a secure hosting provider, FireHost offers unparalleled protection for clients, including redundant network infrastructure, application protection, and virus protection to completely safeguard your website.</p>
<p>To learn more visit <a href="http://www.firehost.com/" target="_blank">FireHost.com</a>, and <a href="http://www.firehost.com/company/contact-us" target="_blank">contact a FireHost Agent</a> today.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/how-do-you-steal-a-fighter-jet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Drupal Hosting</title>
		<link>http://www.fireblog.com/secure-drupal-hosting/</link>
		<comments>http://www.fireblog.com/secure-drupal-hosting/#comments</comments>
		<pubDate>Tue, 05 May 2009 14:00:51 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[CMS Web Hosting]]></category>
		<category><![CDATA[Drupal Hosting]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=207</guid>
		<description><![CDATA[Using Drupal, your website can provide beneficial features such as an internet forum, blogging platform, customizable layouts, individual user accounts, RSS feeds, and many more exciting possibilities. Since Drupal is an open source application, it is completely free to use, making it essentially priceless. However, like all open source applications, there is one potential drawback. Since it's code is freely available to anyone, hackers have the opportunity to analyze and exploit the code running Drupal. This enables malicious attacks on vulnerable websites when a hosting provider doesn't adequately prevent and protect their clients.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1098" title="drupal-hosting" src="http://www.fireblog.com/wp-content/uploads/2009/05/drupal-hosting.jpg" alt="drupal-hosting" width="229" height="237" />Even if you&#8217;ve never heard of Drupal, there&#8217;s a good chance you&#8217;ve experienced it.</p>
<p><a href="http://drupal.org/" target="_blank">Drupal</a> is a powerful and popular open source CMS (content management system) which enables users to build and showcase dynamic website applications. Becoming a favored tool in website development, Drupal is utilized by thousands of companies, such as <a href="http://research.yahoo.com/" target="_blank">Yahoo</a>, <a href="http://warnerbrothersrecords.com/" target="_blank">Warner Bros</a>, and <a href="http://www.observer.com/" target="_blank">The New York Observer</a>. Equipped with a powerful blend of features, Drupal supports a variety of websites ranging from personal weblogs to large community-driven websites.</p>
<p>By using Drupal plug-ins, your website can provide beneficial features such as an internet forum, blogging platform, customizable layouts, individual user accounts, RSS feeds, and many more exciting possibilities. Since Drupal is an open source application, it is completely free to use, making it essentially a &#8220;priceless&#8221; CMS.</p>
<p><span id="more-207"></span></p>
<p>As with all open source applications however, security can be a drawback. Since Drupal&#8217;s code is readily available to anyone, hackers have an easy opportunity for exploitation and malicious attacks. If your hosting provider doesn&#8217;t provide adequate protection and prevention, your website will be at risk.<span style="background-color: #ffffff;"> </span><span style="background-color: #ffffff;">Traditional firewalls only provide network-layer protection, leaving website applications vulnerable to exploitation. </span><span style="background-color: #ffffff;"><a href="http://www.firehost.com/">FireHost</a> addresses this security risk by providing three layers of application security.</span></p>
<p>For our clients, this means an easily managed and content-rich website thanks to Drupal, and the &#8220;sleep at night&#8221; confidence which comes with FireHost secure hosting. More information on secure Drupal hosting is available on our <a title="Secure Drupal Hosting" href="http://www.firehost.com/secure-hosting/drupal" target="_blank">website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/secure-drupal-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybercriminals Poison Basketball Fans&#8217; Search Results</title>
		<link>http://www.fireblog.com/cybercriminals-poison-basketball-fans-search-results/</link>
		<comments>http://www.fireblog.com/cybercriminals-poison-basketball-fans-search-results/#comments</comments>
		<pubDate>Fri, 01 May 2009 14:00:21 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[March Madness]]></category>
		<category><![CDATA[Search Engine Poisoning]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SEO Attacks]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=842</guid>
		<description><![CDATA[During the height of March Madness, college basketball fans around the country performed hundreds of thousands of searches for brackets, inside scoops, roster information, breaking news, pools, and more. In their hunt for information, many visited unfamiliar websites which promised what they sought, only to have their computer infected and their private data stolen.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1027" title="march-madness" src="http://www.fireblog.com/wp-content/uploads/2009/05/march-madness-300x201.jpg" alt="march-madness" width="300" height="201" />During the height of March Madness, college basketball fans around the country performed hundreds of thousands of searches for brackets, inside scoops, roster information, breaking news, pools, and more. In their hunt for information, many visited unfamiliar websites which promised what they sought, only to have their computer infected and their private data stolen.</p>
<p>Investigators have now concluded that cybercriminals <a href="http://blogs.usatoday.com/technologylive/2009/03/hackers-poison.html" target="_blank">were poisoning Google search results</a>, misdirecting innocent sports fans to websites which automatically downloaded and installed malicious programs on the victim&#8217;s computer.</p>
<p>These SEO (Search Engine Optimization) attacks have become increasingly popular among cyber gangs, who had been redirecting hapless victims to sales pitches for worthless antispyware subscriptions. Recently, however, these cybercriminals have expanded their malicious attacks to infect your computer with code as soon as you load a compromised web page, turning your computer into an unwitting accomplice in spreading malicious software and stealing your private data in the process.</p>
<p>Cybercriminals have also begun <a href="http://www.usatoday.com/tech/news/computersecurity/2008-03-31-javascript-hackers_N.htm" target="_blank">poisoning Google search results for legitimate websites</a>, taking advantage of poorly written Javascript code on websites such as USAToday.com and Wired.com, exploiting the site&#8217;s Javascript by injecting their own malicious code. Unfortunately, experts believe these attacks will continue to spread to thousands of websites in the near future, which means your website could soon become a victim.</p>
<p>Having a <a title="Website Security" href="http://www.firehost.com/secure-hosting" target="_blank">security-focused</a> web hosting provider can help prevent your website from becoming the malicious tool of another. Before you trust <em><em>any</em></em> hosting provider with your website, ask them how they handle security for your website. At FireHost, we use three layers of <a title="Security Services" href="http://www.firehost.com/secure-hosting" target="_blank">application protection</a> to catch, stop, and prevent attacks and manipulation. Our first priority is providing security to our clients, which we deliver through dynamic intrusion prevention.</p>
<p>Once you have taken the appropriate measures to secure your website, FireHost can help provide your customers assurance that your website is secure and safe. We will purchase and install McAfee Secure Seals and SSL Certificates on your website, clearly demonstrating your website&#8217;s security and giving your customers confidence in doing business through your website.</p>
<p>To protect your website and business with industry leading secure hosting, visit <a href="http://www.firehost.com" target="_blank">FireHost.com</a> and <a href="http://www.firehost.com/company/contact-us" target="_blank">contact a FireHost Agent today</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/cybercriminals-poison-basketball-fans-search-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USA Today: &#8220;SQL Injection Attacks Hit 450,000 a Day&#8221;</title>
		<link>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/</link>
		<comments>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 14:00:11 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=312</guid>
		<description><![CDATA[SQL attacks are preventable when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. FireHost has taken industry-leading measures to make enterprise-level security attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.]]></description>
			<content:encoded><![CDATA[<p>Modern cybercriminals are out to do harm. Simple as that. They penetrate vulnerable websites, steal private customer information, and commit identity theft every day. Hacker tools and methods of attack have become more sophisticated and wider in scope in recent months.</p>
<p><span class="inside-head"><span style="background-color: #ffffff;"><a href="http://www.usatoday.com/money/industries/technology/2009-03-16-sql-attacks-cyber-security_N.htm">USA Today reports</a>:</span></span></p>
<div style="margin-left: 40px;">SQL attacks take aim at the database layer of websites. They typically were manual attacks designed to pilfer customer data from merchant websites. But last June someone figured out how to automate the attacks, and use them to plant infections. By mid-June, daily attacks spiked to 25,000; by October they topped 450,000 a day.</div>
<div style="margin-left: 40px;">
<p>Holly Stewart, IBM ISS threat response manager, says the infections take advantage of security flaws in cool website features, such as online-delivered video, music, photos, documents and work files.</p></div>
<div style="margin-left: 40px;">
<p>Giant financial institutions and online merchants have put up strong defenses, says Phil Neray, vice president of security strategy at Guardium, a database security firm. &#8220;The same is not necessarily true of regional banks and credit unions, smaller online retailers and state government agencies.&#8221;</p></div>
<p>FireHost is in business to address website security needs of the &#8220;smaller guys&#8221; Mr. Neray mentions above. It&#8217;s imperative your company respond to the threat of cybercriminals swiftly and effectively because SQL attacks strike <a href="http://www.theregister.co.uk/2008/04/24/mass_web_attack/">governments</a> and <a href="http://www.usatoday.com/money/perfi/credit/2009-01-20-heartland-credit-card-security-breach_N.htm">credit card companies</a> every day. FireHost can help your company avoid the negative spotlight.</p>
<p>SQL attacks <strong>are</strong> <strong>preventable </strong>when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. We&#8217;ve taken industry-leading measures to make <a title="Enterprise-level Security" href="http://www.firehost.com/secure-hosting" target="_blank">enterprise-level security</a> attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.</p>
<p>Most hosting providers don&#8217;t invest the resources required to maintain a prevention-focused, secure hosting environment. If your company does business online however, you owe it to your customers and employees to make sure their most important information is protected.</p>
<p>Here&#8217;s just a sample of what puts FireHost secure web hosting in a class of its own:</p>
<p><strong>Network Layer Security</strong><br />
FireHost runs dual Sonicwall internet security devices, providing firewall redundancy for every client. This layer safegaurds websites, emails, and databases from unauthorized intrusions, like SQL attacks.</p>
<p><strong>Application Protection</strong><br />
We also run a web application firewall to close the holes within your website&#8217;s applications, the entry-point for SQL attacks.</p>
<p><strong>Vulnerability Monitoring</strong><br />
FireHost partners with McAfee to provide you with web-based website vulnerability auditing and remediation mangement, completing scans every fifteen minutes.</p>
<p><strong>Register </strong><strong><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">here</a> to have a FireHost Security Agent perform a </strong><strong>vulnerability report for your website. We will contact you shortly with the eye-opening results.<br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why You Need SQL Injection Protection</title>
		<link>http://www.fireblog.com/why-you-need-sql-injection-protection/</link>
		<comments>http://www.fireblog.com/why-you-need-sql-injection-protection/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 11:25:59 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website Hacking]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=58</guid>
		<description><![CDATA[SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university. SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, [...]]]></description>
			<content:encoded><![CDATA[<p>SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university.</p>
<p>SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, Drupal, .NET, classic ASP, PHPBB websites have all been hit with SQL Injections. Do NOT roll the dice on this one! Every web site big or small is vulnerable to injection by automated scripts attempting SQL-Injections through your webforms, dynamic URLs, etc.</p>
<p>This video from Graham Cluley of Sophos discusses the impact of a SQL Injection that hit BusinessWeek.</p>
<p><object id="viddler" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="545" height="347" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent" /><param name="src" value="http://www.viddler.com/player/30f164a6/" /><param name="allowfullscreen" value="true" /><embed id="viddler" type="application/x-shockwave-flash" width="545" height="347" src="http://www.viddler.com/player/30f164a6/" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>What can you do NOW to help secure your website?</strong></p>
<ol>
<li>Ensure all logins use strong passwords</li>
<li>Employ web form validation and/or <a href="http://en.wikipedia.org/wiki/Captcha" target="_blank">CAPTCHA</a></li>
<li>If you&#8217;re using a CMS or website platform, ensure it&#8217;s up-to-date (including all plug-ins)</li>
<li>Ensure all components are current (ASPupload, etc)</li>
<li>Use static URLs instead of dynamic URLs</li>
</ol>
<p><strong>FireHost takes SQL Injection protection to the next level by:<br />
</strong></p>
<ol>
<li><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">Analyzing</a> your website and web applications to assess the potential for SQL Injections and other hacking vulnerabilities</li>
<li><a href="http://www.firehost.com/secure-hosting">Protecting</a> your website using our secure and transparent Web Application Firewall</li>
<li><a title="Vulnerability Monitoring" href="http://www.firehost.com/secure-hosting/vulnerability-monitoring">Monitoring</a> your website for new vulnerabilities</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/why-you-need-sql-injection-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
