<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; cyber security</title>
	<atom:link href="http://www.fireblog.com/tag/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>US Based SMBs Targeted by Hackers More Often than International Firms</title>
		<link>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/</link>
		<comments>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 14:00:52 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1816</guid>
		<description><![CDATA[Panda Security's most recent report indicates that thirty percent of small and medium size businesses worldwide have been infected with malware, and businesses based in the US are even more susceptible.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1905" title="usSmbs_targeted" src="http://www.fireblog.com/wp-content/uploads/2009/08/usSmbs_targeted1.jpg" alt="usSmbs_targeted" width="195" height="120" /><a href="http://www.pandasecurity.com/usa/about/company-profile/" target="_blank">Panda Security</a>&#8216;s most recent report indicates that thirty percent of small and medium size businesses worldwide have been infected with malware, and businesses based in the US are even more susceptible. Close to half (44%) of US based SMBs have lost time and productivity due to some form of cybercrime.</p>
<p>A lack of threat awareness is not the problem. The study shows that almost all businesses in this category have installed anti-virus programs and kept security systems up to date, but a large number of SMBs still become victims of cyber crimes. When disaster strikes, viruses (41%) followed by spyware (26%) are most often the cause.</p>
<p>In a conversation with <a href="http://www.scmagazineus.com/A-rise-in-cybercrime-hits-SMBs/article/140666/" target="_blank">SC Magazine</a>, Luis Corrons, PandaLabs technical director suggested, “these companies often lack the in-house staff and resources to fight off increasingly sophisticated and exponentially more targeted Internet attacks.&#8221;<span id="more-1816"></span></p>
<p>The study&#8217;s results support Mr. Corrons claim that SMBs are not or able (or willing) to allocate the appropriate resources to close vulnerabilities and properly secure their environment.</p>
<ul>
<li>52% of survey respondents have no web filtering solution</li>
<li>39% are untrained/unaware of IT threats</li>
<li>29% have no anti-spam solution</li>
<li>22% are without anti-spyware technology</li>
<li>16% do not have a firewall</li>
</ul>
<p>So what should small and medium size business owners do?</p>
<p>Network <a href="http://www.firehost.com/secure-hosting/vulnerability-audit" target="_blank">vulnerability scans</a> provide extremely high value. A thorough scan of your website(s), database(s), and application(s) can identify disasters waiting to happen. With a starting pricepoint around <a href="http://www.firehost.com/secure-hosting/vulnerability-audit" target="_blank">$100 each</a>, vulnerability scans provide SMBs an affordable way to identify open ports, SQL injections, cross-site scripting (XSS) attempts, holes in JavaScript and web forms, and much more.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The US Cyber Army Takes Shape</title>
		<link>http://www.fireblog.com/the-us-cyber-army-takes-shape/</link>
		<comments>http://www.fireblog.com/the-us-cyber-army-takes-shape/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 14:00:34 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1773</guid>
		<description><![CDATA[National Defense Contractor Raytheon is actively hiring hundreds of "Cyber Warriors" in response to President Obama's announcement that cybersecurity is one of our country's most urgent priorities.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.fireblog.com/wp-content/uploads/2009/08/helpwanted-adjusted.jpg" alt="helpwanted-adjusted" title="helpwanted-adjusted" width="181" height="176" class="alignright size-full wp-image-1889" /><a href="http://raytheon.com/" target="_blank">Raytheon</a>, a National Defense Contractor is actively hiring hundreds of &#8220;Cyber Warriors&#8221; in response to President Obama&#8217;s <a href="http://news.cnet.com/8301-13578_3-10252154-38.html" target="_blank">announcement</a> that cybersecurity is one of our country&#8217;s most urgent priorities.</p>
<p>Steve Hawkins, Raytheon&#8217;s VP of Information Security Solutions, told <a href="http://www.foxnews.com/story/0,2933,534806,00.html" target="_blank">FoxNews.com</a> that there are more than 30 different job descriptions available, and applicants must pass the most stringent security clearances. Qualified individuals must understand computer systems and have a handle on the interaction between hardware and software down to the nitty-gritty. Additionally, applicants should know how the adversary [ cybercriminals ] thinks and adopt their perspective, but in an ethical way.</p>
<p>Raytheon isn&#8217;t alone in the movement to beef up the US cyber army. The Center for Strategic and International Studies recently kicked off a nationwide talent search for high school and college students to encourage cybersecurity as a career path.<span id="more-1773"></span></p>
<p>Aptly named, the <a href="http://csis.org/uscc" target="_blank">US Cyber Challenge</a> has set out to find 10,000 young Americans interested in becoming cyber guardians and cyber warriors. The program will nurture and develop participants&#8217; skills and provide access to advanced education.</p>
<p>&#8220;We&#8217;re glad to see online security become a public concern. These competitions and recruitment activities reinforce our core belief that everyone is entitled to maintain an identity online without the threat of being hacked or defaced. Having more qualified individuals working to make the internet safer is only going to make our secure hosting services more effective,&#8221; states FireHost CEO, <a href="http://twitter.com/chrisdrake" target="_blank">Chris Drake</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/the-us-cyber-army-takes-shape/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nine-Ball Mass Injection Attack has Compromised 40,000 Websites to Date</title>
		<link>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/</link>
		<comments>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 14:00:58 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Nine-Ball]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1523</guid>
		<description><![CDATA[Websense security labs have been tracking the Nine-Ball mass compromise attack since early June. They report to date, that over 40,000 legitimate Web sites have been compromised and are actively infected with an information-stealing trojan.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1538" title="9ball" src="http://www.fireblog.com/wp-content/uploads/2009/06/9ball.jpg" alt="9ball" width="154" height="179" /><a href="http://www.websense.com/content/Home.aspx" target="_blank">Websense</a> security labs have been tracking the <a href="http://securitylabs.websense.com/content/Alerts/3421.aspx" target="_blank">Nine-Ball</a> mass compromise attack since early June. They report to date, that over 40,000 legitimate Web sites have been compromised and are actively infected with an information-stealing trojan.</p>
<p>The Nine-Ball attack is deployed when a user visits a legitimate website that has been infected with the malicious code. From the legitimate website, unsuspecting users are redirected behind the scenes through a series of different sites owned by the Nine-Ball&#8217;s hackers.</p>
<p><span id="more-1523"></span></p>
<p>The diagram below depicts a typical url progression that happens behind the scenes during a Nine-Ball deployment.</p>
<div class="wp-caption aligncenter" style="width: 518px"><img title="Nine-Ball Progression" src="http://www.fireblog.com/wp-content/uploads/2009/06/9balldiagram.jpg" alt="Nine-Ball Progresstion" width="508" height="89" /><p class="wp-caption-text">Nine-Ball Progresstion</p></div>
<p>When an infected site is visited for the first time, the user is directed to the ninetoraq.in exploit payload site where the visitor&#8217;s IP address is recorded and the trojan download is installed.</p>
<dl style="width: 443px;"> </dl>
<p>If a user on the same IP visits the legitimate website again, he or she is directed to the benign site of <em>ask.com</em>. Security experts speculate that the Nine-Ball hackers are using a benign destination url to throw cyber security investigators and cyber crime analysts off track.</p>
<p><span>The scary part is that most antivirus applications will not detect Nine-Ball&#8217;s malicious code. Websense experts report, that &#8220;the exploit is detected by only three of the 41 most commonly used AV programs.&#8221;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
