<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; Prevent Hackers</title>
	<atom:link href="http://www.fireblog.com/tag/prevent-hackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Are YOU Your Biggest Security Threat? 5 Ways to Close Holes that Hackers Can Easily Breach.</title>
		<link>http://www.fireblog.com/are-you-your-biggest-security-threat-5-ways-to-close-holes-that-hackers-can-easily-breach/</link>
		<comments>http://www.fireblog.com/are-you-your-biggest-security-threat-5-ways-to-close-holes-that-hackers-can-easily-breach/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 13:00:00 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacker Prevention]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Virtual Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=3257</guid>
		<description><![CDATA[YOU May be Your Company's Biggest Security Threat. 5 Ways to Close Holes that Hackers Can Easily Breach.]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"></script><strong></strong>If I wanted to hack your eCommerce business, I’d have your help. It’s a fact that no one runs a business from one location (or one computer) anymore. In today’s world work gets done everywhere &#8211; in offices, at home, in a hotel, at the airport, while sipping mocha and siphoning Internet connectivity from a coffee shop.</p>
<p>Security risks increase when your business moves outside of the safety net of your main workplace. Mobile executives carry sensitive data around with them, and often times open it up to vulnerabilities just for the sake of convenience.</p>
<p>It all seems perfectly innocent. Connecting to wireless Internet in your hotel room, or syncing up to free wi-fi in a restaurant just to get a little work done. Convenient? Yes. Necessary? Sometimes. Is working remotely a down trending habit? Absolutely not. And so, we must learn (and educate our workforce) about how to work remotely more safely.</p>
<p>Protecting your mobile workforce is essential to protecting your business. And it can be accomplished (or at least done more successfully) by following a few simple tips to help keep your business safe from hackers, no matter where you go:</p>
<p><strong>Stay Off the Free, Open Wireless</strong></p>
<p>More and more public places are providing free, or shared wireless Internet. These open networks are dangerous. They’re risky for personal communications, but they are absolutely not suitable for conducting business without protection.</p>
<p>When jumping on public shared wireless connections, it’s essential to do so using a secure VPN connection with the latest encryption methods. This will funnel all your online activities (email, surfing, chat, etc) through this secure connection so prying eyes can’t see what you’re doing. Several companies offer this service but we’ve heard good things about <a href="http://www.anonymizer.com/" target="_blank">Anonymizer</a>.</p>
<p>As an alternative, <a href="http://www.verizonwireless.com/b2c/mobilebroadband/" target="_blank">Verizon</a>, <a href="http://shop.sprint.com/en/solutions/mobile_broadband/index.shtml" target="_blank">Sprint</a>, <a href="http://www.wireless.att.com/businesscenter/plans/dataconnect.jsp?wtLinkName=DataConnectPlans&amp;wtLinkLoc=S1&amp;WT.svl=2" target="_blank">AT&amp;T</a>, and others have mobile broadband services available for a reasonable monthly subscription. Spring for the mobile Internet access card. It’s a small expense for what you get in exchange – the ability to conduct business more securely outside the office.</p>
<p>Bonus Tip – turn off your wireless connection at all times when not in use so you are 100 percent sure about when you are connected to the Internet. If you’ve previously connected to default network names (like Linksys) then anytime that network name reappears at another location, you will be automatically connected to the network opening you up for risks.</p>
<p><span id="more-3257"></span></p>
<p><strong>Let Hardware Do the Hard Part</strong></p>
<p>We’re joined at the hip to our laptops, mobile devices, iPads, and other mobile gadgets. These crafty handheld devices help us work more effectively, and their processing capabilities and compatibilities increase every day. There’s no turning back from the convenience they provide, and believe me, we wouldn’t want to because the benefits in most cases far outweigh the risk.</p>
<p>Next time you’re packing for a trip, or just to work remotely for the day, think twice about your hardware requirements.</p>
<ul>
<li>Use a “travel only” laptop. A stripped down version of your of your regular workhorse but with limited history and minimal applications installed. Of course, passwords and all the “conveniences” of your regular machine won’t be readily available, but do you really need it all when you’re on the road? For some trips, perhaps, but always weigh the risks against the convenience.</li>
<li>Use Web access rather than physical software for email when possible. Obviously, this is more convenient if you subscribe to the “travel only” laptop model. Either way, take pause to consider all the confidential information that may be stored on your physical machine’s email software if it fell into the wrong hands.</li>
<li>Clear browser history every time you close Safari, FireFox, Chrome, etc. If anything, this will make it more difficult for cyber thieves to retrace your steps.</li>
<li>Don’t store documents, presentations, spreadsheets, PDFs, etc, locally. Always connect to your designated location on an approved network and put your information there. The goal is to make your physical hardware as useless as possible. This way, if your laptop goes missing, none of the important information goes with it.</li>
<li>Don’t store or “remember” passwords, type them in every time unless you want to give unlimited free passes to cyber criminals.</li>
<li>Don’t leave home without “lojack-like” software, such as <a href="http://www.absolute.com/products/lojackforlaptops" target="_blank">Computrace</a>, that can wipe the contents of your mobile device. This provides an extra layer of protection in case your phone or laptop falls into the wrong hands.</li>
<li>Anti-virus software can be installed on most laptops. There are several reputable virtual security companies that provide reliable service, but in a pinch you can download a <a href="http://free.avg.com/us-en/download-avg-anti-virus-free" target="_blank">free version</a> that is better than nothing, as they say.</li>
</ul>
<p><strong>Pull the Fire Alarm</strong></p>
<p>Two-factor authentication (aka 2FA or “the fire alarm”) provides an additional layer of protection and awareness for user systems. It’s incredibly simple, affordable, and effective, so there’s no excuse to not have this service for your users 100 percent of the time, but it can easily be enabled for users on the road.</p>
<p>It works like this: When (stolen or legitimate) credentials are successfully entered into a login prompt, the “fire alarm” software places a phone call to the authorized user to 1) alert the authorized user that a designated system is being accessed and to 2) retrieve a secret pin and complete the authentication. With this service enabled, attempted security breaches can be identified quickly, snuffing our suspicious activity before a full-blown crisis ensues.</p>
<p><strong>Watch Your Back, Jack</strong></p>
<p>Your coffee cup is empty, so you grab your wallet and ask the nice person next to you to “watch” your laptop while you go refuel. For an experienced cyber criminal, it takes just second to grab some data off of your computer, phone, or tablet. And lesser skilled (however not necessarily less malicious) hackers could just grab your goods and run. Thieves are everywhere and they park themselves in places where people work for this very purpose.</p>
<p>The coffee shop isn’t the only crime scene. Airports, car rental shuttle, hotels, and the back seat of your car are equally susceptible to theft. Check your bags at every turn. Make sure you’ve got the correct luggage and account for all your personal and professional belongings. Report any stolen items to the police and your IT staff at once.</p>
<p><strong>Be Responsible. Your Business Depends on It.</strong></p>
<p>Anytime you’re doing business on the road without security in place, you’re open for business, but for the wrong customers. You wouldn’t take your customers’ money and let it hang out of your pockets for anyone to grab would you? By leaving data access points open to hackers, you’re essentially doing just that.</p>
<p>Be conscious of how easy it is for hackers to take your company’s valuable information. Take the time to ensure that your company, and your customers’ data, is always protected and accountable, no matter where you are in the world.</p>
<p><em>A <a href="http://www.ecommercetimes.com/story/YOU-May-Be-Your-Companys-Biggest-Security-Threat-70254.html" target="_blank">version</a> of this article appeared in eCommerce Times on June 22, 2010.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/are-you-your-biggest-security-threat-5-ways-to-close-holes-that-hackers-can-easily-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Exploitation Trends: Web Applications Outpace Operating Systems</title>
		<link>http://www.fireblog.com/vulnerability-exploitation-trends/</link>
		<comments>http://www.fireblog.com/vulnerability-exploitation-trends/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 14:00:50 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Vulnerability Exploitation]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2154</guid>
		<description><![CDATA[According to a report by SANS.org, OS vulnerabilities are patched more quickly than client-side vulnerabilities on average. As a result, hackers have found exploiting popular client-side applications such as Adobe PDF Reader, QuickTime, Adobe Flash, and Microsoft Office to be quite lucrative.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2190" title="vulnerabilityTrend" src="http://www.fireblog.com/wp-content/uploads/2009/09/vulnerabilityTrend.jpg" alt="vulnerabilityTrend" width="148" height="124" />According to a report by <a href="http://www.sans.org/top-cyber-security-risks/" target="_blank">SANS.org</a>, OS vulnerabilities are patched more quickly than client-side vulnerabilities on average. In addition, some client-side software remains unpatched or is not updated throughout it&#8217;s lifespan. As a result, hackers have found exploiting popular client-side applications such as Adobe PDF Reader, QuickTime, Adobe Flash, and Microsoft Office to be quite lucrative.</p>
<p>Attacks against popular web applications such as these constitute more than 60% of all attacks on the internet, and some of the exploits don&#8217;t even require a user to open the downloaded document or file. Victims&#8217; computers may be compromised by simply visiting an infected website masked with the perception of being a trustworthy, big, software brand.</p>
<p>Client-side vulnerabilities are so powerful because they give hackers a mask behind which to carry out exploits. Users feel confident downloading files from trusted sources or using tools and applications such as Microsoft SQL, FTP, and SSH that are perceived to be safe because of popularity and industry-wide user-acceptance.</p>
<p><span id="more-2154"></span></p>
<p>Did you know that:</p>
<ul>
<li>websites are most often compromised by SQL injection, Cross-site Scripting (XSS), and PHP File Include attacks.</li>
<li>web servers are primarily exploited and compromised  by brute force password guessing attacks and web application attacks.</li>
</ul>
<p>It&#8217;s scary, but true; there are a number of automated tools designed to make it easier for even novice hackers and script kiddies to carry out such attacks. Once deployed, these attack methods give cyber criminals the ability to quickly discover and infect thousands of  websites or computers at once in such a way that will propagate infections across other computers and servers around the globe.</p>
<p>Most importantly however, client-side vulnerabilities provide an open doorway through which many hackers can achieve their ultimate goal &#8211; stealing sensitive data for financial gain.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/vulnerability-exploitation-trends/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Networks Targeted by Hackers More Often than Government &amp; Law Agencies in &#8217;09</title>
		<link>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/</link>
		<comments>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 14:00:41 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1943</guid>
		<description><![CDATA[Security experts believe social networks like Twitter and Facebook are targeted because of the sheer number of users. Defacement is the most common motivation for ego-driven hackers, and these high traffic, high involvement communities are a great way to disrupt many victims at once.]]></description>
			<content:encoded><![CDATA[<p>This year, social networking sites have become popular  targets for cyber crime according to a <a href="http://www.pcworld.com/businesscenter/article/170287/hackers_put_social_networks_such_as_twitter_in_crosshairs.html" target="_blank">study of hacking episodes</a> by Web Hacking Incidents Database (WHID). This is a shift from 2008 when government and law enforcement agencies were the most enticing targets.</p>
<p><img class="alignright size-full wp-image-1961" style="margin-left:22px;" title="socialTargets" src="http://www.fireblog.com/wp-content/uploads/2009/08/socialTargets.jpg" alt="socialTargets" width="169" height="104" /></p>
<p>Security experts believe social networks like Twitter and Facebook are targeted because of the sheer number of users. Defacement is the most common motivation for ego-driven hackers, and these high traffic, high involvement communities are a great way to disrupt many victims at once.</p>
<p>A <a href="http://www.pcworld.com/article/167511/beware_identity_thieves_harvest_social_networks.html?tk=rel_news" target="_blank">study by Webroot</a> sheds light on a few other reasons why social networks make a ripe targets for hackers.</p>
<ul>
<li>36% of social networkers admit they don&#8217;t hide personal information</li>
<li>33% admit to using the same password for all of their online accounts</li>
<li>28% accept &#8220;friend requests&#8221; from strangers</li>
</ul>
<p>With such a high percent of social networking users being unaware of the dangers, &#8220;hackers lure users into taking actions they shouldn&#8217;t by making it appear as if a friend within their social netowrk has sent them a message &#8211; only the message is from a hacker who has hijacked the friend&#8217;s account,&#8221; warns Mike Kronenberg CTO of Webroot&#8217;s Consumer Business division.</p>
<p><span id="more-1943"></span></p>
<p>The technique described by Mr. Kronenberg is known as <a href="http://security.firehost.com/terms/phishing" target="_blank">phishing</a>, and it&#8217;s one of the most preventable ways hackers obtain access to confidential information. <a href="http://security.firehost.com/terms/sql-injection" target="_blank">SQL injections</a>, Cross-site Scripting <a href="http://security.firehost.com/terms/cross-site-scripting" target="_blank">(XSS)</a>, and Cross-site Forgery Requests (CSFR) are more covert, technical methods that hackers use to get the infomation they need.</p>
<p>&#8220;As a web service or SaaS provider, you can help protect your users from these attacks by hosting your applications in a <a href="http://www.firehost.com/secure-hosting" target="_blank">secure environment</a>. Users need to be savvy, and when they can&#8217;t stay up to speed on all the risks, community users should be weary and overly cautious at all times,&#8221; suggests Chris Drake, CEO of FireHost.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Ways Hackers Obtain Confidential Data</title>
		<link>http://www.fireblog.com/top-10-ways-hackers-obtain-confidential-data/</link>
		<comments>http://www.fireblog.com/top-10-ways-hackers-obtain-confidential-data/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 14:00:02 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Confidential Data]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Website Protection]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1848</guid>
		<description><![CDATA[Many security vulnerabilities require more than software patches and basic anti-virus software to keep your network and data safe from hackers, and most companies don't have all the resources available necessary to provide complete protection. Instead of relying on costly, in-house expertise, many firms are looking outward to goal-focused security consultants to help identify openings hackers could easily exploit.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1951" title="top10" src="http://www.fireblog.com/wp-content/uploads/2009/08/top10.jpg" alt="top10" width="142" height="131" />Two and a half years after retail giant TJX Companies, Inc (parent company to TJ Maxx, Marshalls, and Home Goods) experienced one of the <a href="http://www.securitymanagement.com/news/tjx-settles-data-breach-97-million-005941" target="_blank">largest data breaches</a> in history, the firm is still paying. This time, the settlement provides $9.7MM across 41 states to help protect consumers from payment card negligence. One quarter of those funds are devoted to creating a national fund that will investigate future data breaches.</p>
<p>In reality, the latest sum TJX has to pay is small potatoes compared to the capital outlay the retailer has made since 2007 to mitigate the security breach that exposed 45 million credit and debit card numbers. When the leak was discovered, TJX set aside $107MM to deal with the fallout and the expenditures to date are in that range. In two of the largest settlements, they&#8217;ve paid $24MM to MasterCard and $41MM to Visa banks. In addition, TJX has been ordered to undergo costly external audits every other year for 20 years by the FTC.</p>
<p>Is it 100% possible for companies to avoid costly and negative public facing situations such as this?</p>
<p><span id="more-1848"></span>Maybe not, but there is quite a lot you can learn from past system compromises to help prevent making the same mistakes. In fact, PCWorld Canada has compiled a &#8220;top ten&#8221; list of vulnerabilities companies maintaining a serious presence online should know about.</p>
<ol>
<li>Operating System Flaws</li>
<li>SQL Injections</li>
<li>Drive-by Downloads</li>
<li>Compromised Password(s)</li>
<li>Social Engineering</li>
<li>Malicious Email</li>
<li>Physical Access</li>
<li>Compromised Network</li>
<li>Wireless Hacking</li>
<li>Weak Access Points</li>
</ol>
<p>These vulnerabilities require more than software patches and basic anti-virus software to keep your network and data safe from hackers, and most companies don&#8217;t have all the resources available necessary to provide complete protection.</p>
<p>&#8220;Instead of relying on costly, in-house expertise, many firms are looking outward to goal-focused <a href="http://www.firehost.com/services/security-consulting" target="_blank">security consultants</a> to help identify openings hackers could easily exploit,&#8221; said Chris Drake, FireHost CEO. &#8220;We recommend that every client undergo a <a href="http://www.firehost.com/services/security-consulting" target="_blank">security audit</a> just to ensure everything within your power is being done to help prevent confidential internal and consumer data from leaking into the wrong hands.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/top-10-ways-hackers-obtain-confidential-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Obama Administration Inviting Hackers to Help Fight Cybercrime</title>
		<link>http://www.fireblog.com/obama-administration-inviting-hackers-to-help-fight-cybercrime/</link>
		<comments>http://www.fireblog.com/obama-administration-inviting-hackers-to-help-fight-cybercrime/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 14:00:20 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1580</guid>
		<description><![CDATA[The US Department of Homeland Security is turning to hackers to help the 16-person advisory council (HSAC) obtain alternative viewpoints on cybercrime.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1712" title="homeland" src="http://www.fireblog.com/wp-content/uploads/2009/07/homeland.jpg" alt="homeland" width="156" height="140" />The US <a href="http://www.dhs.gov/index.shtm" target="_blank">Department of Homeland Security</a> is turning to hackers to help the 16-person advisory council (HSAC) obtain alternative viewpoints on cybercrime.</p>
<p>An article on <a href="http://www.foxnews.com/story/0,2933,525428,00.html" target="_blank">FoxNews.com</a> revealed the most recent committee member to be Jeff Moss, aka Dark Tangent. Mr. Moss is widely recognized as founder of the <a href="http://www.defcon.org/" target="_blank">DefCon</a> and <a href="http://www.blackhat.com/" target="_blank">Black Hat</a> hackers&#8217; conferences. He has worked in information security for accounting giant Ernst &amp; Young and presently works as an independent cybersecurity consultant for a variety of corporations.</p>
<p>Mr. Moss looks forward to bringing  &#8220;a skeptical outsider&#8217;s view&#8221; to the HSAC, but admits he was surprised by President Obama&#8217;s invitation to join the council stating, &#8220;I always figured that because of my associations in the past that I would be kind of out of the running for anything like this.&#8221;</p>
<p><span id="more-1580"></span>The US&#8217; strategy of inviting hackers to join governmental agencies is not unique. <a href="http://www.foxnews.com/story/0,2933,529094,00.html?sPage=fnc/scitech/cybersecurity" target="_blank">Britain</a> is taking a precautionary stance on cyber warfare as well by hiring former computer hackers to join a newly formed security unit aimed at protecting cyberspace from foreign spies, thieves, and terrorists.</p>
<p>The cyber security prevention unit will be based at Britain&#8217;s Government Communications HQ (GCHQ) <span id="intelliTXT">in Cheltenham, western England. </span>Britain&#8217;s Security Minister, Lord Admiral Alan West said British government systems have probably come under cyber attack, but that he did not know of any specific cases where sensitive data had been lost.</p>
<p>Private organizations, individuals, and corporations should take a proactive stance on cyber crime and identity theft as well.</p>
<p>Chris Drake, FireHost&#8217;s Chief Executive Officer recommends every individual and professional organization maintaining a presence online to align themselves with experts in web site security. Speaking from experience he states, &#8220;You can prevent negative press, unnecessary expense, downtime and a ton of headache by identifying and resolving website security risks before problems strike.&#8221;</p>
<p>Read more about how FireHost can help identify vulnerabilities in your web site by visiting our <a href="http://www.firehost.com/services/security-consulting" target="_blank">Website Security Consulting</a> services page.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/obama-administration-inviting-hackers-to-help-fight-cybercrime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>As Mitnick Knows, Security Not Always in Your Control</title>
		<link>http://www.fireblog.com/as-mitnick-knows-security-not-always-in-your-control/</link>
		<comments>http://www.fireblog.com/as-mitnick-knows-security-not-always-in-your-control/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 17:42:32 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Kevin Mitnick Hacked]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1620</guid>
		<description><![CDATA[In a phone conversation today, Mitnick disclosed to FireHost's Chief Security Officer, Greg Martin, that he was using secure hosting practices on his site, but the hackers got to his website through his hosting company's DNS provider.]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Kevin_Mitnick" target="_blank">Kevin Mitnick</a>, the most well known hacker of the 1990&#8242;s had his personal and business websites <a href="http://www.thetechherald.com/article.php/200927/3953/Kevin-Mitnick-suffers-classic-Web-defacement-NSFW" target="_blank">compromised and defaced</a> recently, and if you query Mitnick&#8217;s domain today, you still see remnants of the hack. Words like:<em><img class="alignright size-full wp-image-1635" title="mitnickHacked2" src="http://www.fireblog.com/wp-content/uploads/2009/06/mitnickHacked2.jpg" alt="mitnickHacked2" width="170" height="157" /></em></p>
<p><em>$ whois mitnicksecurity.com</em></p>
<p><em>MITNICKSECURITY.COM.HACKED.BY.NERD.FROM.WEB-HACK.COM<br />
MITNICKSECURITY.COM</em></p>
<p>In a phone conversation today, Mitnick disclosed to FireHost&#8217;s Chief Security Officer that he was using secure hosting practices on his site, but the hackers got to his website through his hosting company&#8217;s DNS provider. They compromised the control panel for his domain names and redirected his site to a defaced version.</p>
<p><span id="more-1620"></span></p>
<p>FireHost&#8217;s CSO responded to the event, &#8220;DNS security has been a hot button since last summer&#8217;s poisoning attack discovered by Dan Kaminsky. Mitnick&#8217;s attack was much more straight forward, and this is an example of why we don&#8217;t rely on third party providers to secure our customers. By maintaining the infrastructure in-house, we can help ensure the integrity and security of our customers&#8217; web sites.&#8221;</p>
<p>We reached out to <a href="http://www.fireblog.com/exclusive-interview-with-strongwebmails-10000-hacker/" target="_blank">Lance James</a>, CTO of Secure Science and author of <a href="http://www.amazon.com/Phishing-Exposed-Lance-James/dp/159749030X" target="_blank">Phishing Exposed</a> for a comment on how he recommends protecting website from a similar attack. Lance says part of the answer is partnering with a secure web host that can provide protection from DNS vulnerabilities.</p>
<p>&#8220;Control Panel software has a history of successful attacks, and it is not surprising that a high-profile site such as mitnicksecurity.com is susceptible to vulnerabilities. His site is a natural target, and unfortunately, it can be extremely embarrassing when an expert in security chooses a hosting provider with such vulnerabilities,&#8221; Lance James.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/as-mitnick-knows-security-not-always-in-your-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Investments Top IT Budgets</title>
		<link>http://www.fireblog.com/security-investments-top-it-budgets/</link>
		<comments>http://www.fireblog.com/security-investments-top-it-budgets/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 14:00:16 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=869</guid>
		<description><![CDATA[Over the past year, there has been a significant rise in the number of malicious attacks on company websites. Symantec identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.]]></description>
			<content:encoded><![CDATA[<p>Despite a challenging economy, many companies are making room in their budgets for investments in information security initiatives.</p>
<p>According to a survey by <a href="http://www.csoonline.com/article/489109/Report_Security_Tops_IT_Budget_Priorities" target="_blank">Robert Half Technology</a><span style="font-family: Arial;">, s</span>even out of ten CIOs interviewed reported their companies would be investing in new information technology initiatives over the next year. 43% of the respondents overall reported information security as a top priority, and in the <img class="alignright size-full wp-image-1567" title="budget" src="http://www.fireblog.com/wp-content/uploads/2009/07/budget.jpg" alt="budget" width="121" height="215" />financial services and transportation sectors, information security was cited most often as the top priority.</p>
<p>&#8220;Although times are lean, many companies are finding that they can&#8217;t afford to postpone IT investments that lead to increased security, efficiencies or revenues,&#8221; stated Dave Willmer, Executive Director of Robert Half Technology. &#8220;Organizations also are trying to make sure they are prepared for growth when conditions improve, and enhancing their IT infrastructure is part of that process.&#8221;</p>
<p>Over the past year, there has been a significant rise in the number of malicious attacks on company websites. <a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport" target="_blank">Symantec</a> identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.</p>
<p><span id="more-869"></span>Vulnerable targets are numerous, however increased threat awareness and security investments can help stem the tide. The two biggest threats to website security are <a href="http://www.firehost.com/secure-hosting/platforms" target="_self">open source vulnerabilities</a> and injection attacks, which often allow the disruption and infiltration of web servers. The results can be devastating for companies and their customers, ranging from the theft of confidential information to the insertion of <a href="http://security.firehost.com/terms/malware" target="_self">malware</a>.</p>
<p>Properly securing your company&#8217;s website and online databases can reduce the risk of a hacking attempt. FireHost uses enterprise, web application firewalls, traffic monitoring, threat detection, automated attack mitigation, and constant monitoring by human personnel to help prevent the serious application-level attacks that negatively impact hundreds of companies and millions of customers every year.</p>
<p>Click <a href="http://www.firehost.com/secure-hosting">here</a> to learn more about our advanced secure web hosting techniques.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/security-investments-top-it-budgets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USA Today: &#8220;SQL Injection Attacks Hit 450,000 a Day&#8221;</title>
		<link>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/</link>
		<comments>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 14:00:11 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=312</guid>
		<description><![CDATA[SQL attacks are preventable when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. FireHost has taken industry-leading measures to make enterprise-level security attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.]]></description>
			<content:encoded><![CDATA[<p>Modern cybercriminals are out to do harm. Simple as that. They penetrate vulnerable websites, steal private customer information, and commit identity theft every day. Hacker tools and methods of attack have become more sophisticated and wider in scope in recent months.</p>
<p><span class="inside-head"><span style="background-color: #ffffff;"><a href="http://www.usatoday.com/money/industries/technology/2009-03-16-sql-attacks-cyber-security_N.htm">USA Today reports</a>:</span></span></p>
<div style="margin-left: 40px;">SQL attacks take aim at the database layer of websites. They typically were manual attacks designed to pilfer customer data from merchant websites. But last June someone figured out how to automate the attacks, and use them to plant infections. By mid-June, daily attacks spiked to 25,000; by October they topped 450,000 a day.</div>
<div style="margin-left: 40px;">
<p>Holly Stewart, IBM ISS threat response manager, says the infections take advantage of security flaws in cool website features, such as online-delivered video, music, photos, documents and work files.</p></div>
<div style="margin-left: 40px;">
<p>Giant financial institutions and online merchants have put up strong defenses, says Phil Neray, vice president of security strategy at Guardium, a database security firm. &#8220;The same is not necessarily true of regional banks and credit unions, smaller online retailers and state government agencies.&#8221;</p></div>
<p>FireHost is in business to address website security needs of the &#8220;smaller guys&#8221; Mr. Neray mentions above. It&#8217;s imperative your company respond to the threat of cybercriminals swiftly and effectively because SQL attacks strike <a href="http://www.theregister.co.uk/2008/04/24/mass_web_attack/">governments</a> and <a href="http://www.usatoday.com/money/perfi/credit/2009-01-20-heartland-credit-card-security-breach_N.htm">credit card companies</a> every day. FireHost can help your company avoid the negative spotlight.</p>
<p>SQL attacks <strong>are</strong> <strong>preventable </strong>when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. We&#8217;ve taken industry-leading measures to make <a title="Enterprise-level Security" href="http://www.firehost.com/secure-hosting" target="_blank">enterprise-level security</a> attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.</p>
<p>Most hosting providers don&#8217;t invest the resources required to maintain a prevention-focused, secure hosting environment. If your company does business online however, you owe it to your customers and employees to make sure their most important information is protected.</p>
<p>Here&#8217;s just a sample of what puts FireHost secure web hosting in a class of its own:</p>
<p><strong>Network Layer Security</strong><br />
FireHost runs dual Sonicwall internet security devices, providing firewall redundancy for every client. This layer safegaurds websites, emails, and databases from unauthorized intrusions, like SQL attacks.</p>
<p><strong>Application Protection</strong><br />
We also run a web application firewall to close the holes within your website&#8217;s applications, the entry-point for SQL attacks.</p>
<p><strong>Vulnerability Monitoring</strong><br />
FireHost partners with McAfee to provide you with web-based website vulnerability auditing and remediation mangement, completing scans every fifteen minutes.</p>
<p><strong>Register </strong><strong><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">here</a> to have a FireHost Security Agent perform a </strong><strong>vulnerability report for your website. We will contact you shortly with the eye-opening results.<br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
