<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; Vulnerabilities</title>
	<atom:link href="http://www.fireblog.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>US Based SMBs Targeted by Hackers More Often than International Firms</title>
		<link>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/</link>
		<comments>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 14:00:52 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1816</guid>
		<description><![CDATA[Panda Security's most recent report indicates that thirty percent of small and medium size businesses worldwide have been infected with malware, and businesses based in the US are even more susceptible.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1905" title="usSmbs_targeted" src="http://www.fireblog.com/wp-content/uploads/2009/08/usSmbs_targeted1.jpg" alt="usSmbs_targeted" width="195" height="120" /><a href="http://www.pandasecurity.com/usa/about/company-profile/" target="_blank">Panda Security</a>&#8216;s most recent report indicates that thirty percent of small and medium size businesses worldwide have been infected with malware, and businesses based in the US are even more susceptible. Close to half (44%) of US based SMBs have lost time and productivity due to some form of cybercrime.</p>
<p>A lack of threat awareness is not the problem. The study shows that almost all businesses in this category have installed anti-virus programs and kept security systems up to date, but a large number of SMBs still become victims of cyber crimes. When disaster strikes, viruses (41%) followed by spyware (26%) are most often the cause.</p>
<p>In a conversation with <a href="http://www.scmagazineus.com/A-rise-in-cybercrime-hits-SMBs/article/140666/" target="_blank">SC Magazine</a>, Luis Corrons, PandaLabs technical director suggested, “these companies often lack the in-house staff and resources to fight off increasingly sophisticated and exponentially more targeted Internet attacks.&#8221;<span id="more-1816"></span></p>
<p>The study&#8217;s results support Mr. Corrons claim that SMBs are not or able (or willing) to allocate the appropriate resources to close vulnerabilities and properly secure their environment.</p>
<ul>
<li>52% of survey respondents have no web filtering solution</li>
<li>39% are untrained/unaware of IT threats</li>
<li>29% have no anti-spam solution</li>
<li>22% are without anti-spyware technology</li>
<li>16% do not have a firewall</li>
</ul>
<p>So what should small and medium size business owners do?</p>
<p>Network <a href="http://www.firehost.com/secure-hosting/vulnerability-audit" target="_blank">vulnerability scans</a> provide extremely high value. A thorough scan of your website(s), database(s), and application(s) can identify disasters waiting to happen. With a starting pricepoint around <a href="http://www.firehost.com/secure-hosting/vulnerability-audit" target="_blank">$100 each</a>, vulnerability scans provide SMBs an affordable way to identify open ports, SQL injections, cross-site scripting (XSS) attempts, holes in JavaScript and web forms, and much more.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/us-based-smbs-targeted-by-hackers-more-often-than-international-firms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why You Need SQL Injection Protection</title>
		<link>http://www.fireblog.com/why-you-need-sql-injection-protection/</link>
		<comments>http://www.fireblog.com/why-you-need-sql-injection-protection/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 11:25:59 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website Hacking]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=58</guid>
		<description><![CDATA[SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university. SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, [...]]]></description>
			<content:encoded><![CDATA[<p>SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university.</p>
<p>SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, Drupal, .NET, classic ASP, PHPBB websites have all been hit with SQL Injections. Do NOT roll the dice on this one! Every web site big or small is vulnerable to injection by automated scripts attempting SQL-Injections through your webforms, dynamic URLs, etc.</p>
<p>This video from Graham Cluley of Sophos discusses the impact of a SQL Injection that hit BusinessWeek.</p>
<p><object id="viddler" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="545" height="347" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent" /><param name="src" value="http://www.viddler.com/player/30f164a6/" /><param name="allowfullscreen" value="true" /><embed id="viddler" type="application/x-shockwave-flash" width="545" height="347" src="http://www.viddler.com/player/30f164a6/" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>What can you do NOW to help secure your website?</strong></p>
<ol>
<li>Ensure all logins use strong passwords</li>
<li>Employ web form validation and/or <a href="http://en.wikipedia.org/wiki/Captcha" target="_blank">CAPTCHA</a></li>
<li>If you&#8217;re using a CMS or website platform, ensure it&#8217;s up-to-date (including all plug-ins)</li>
<li>Ensure all components are current (ASPupload, etc)</li>
<li>Use static URLs instead of dynamic URLs</li>
</ol>
<p><strong>FireHost takes SQL Injection protection to the next level by:<br />
</strong></p>
<ol>
<li><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">Analyzing</a> your website and web applications to assess the potential for SQL Injections and other hacking vulnerabilities</li>
<li><a href="http://www.firehost.com/secure-hosting">Protecting</a> your website using our secure and transparent Web Application Firewall</li>
<li><a title="Vulnerability Monitoring" href="http://www.firehost.com/secure-hosting/vulnerability-monitoring">Monitoring</a> your website for new vulnerabilities</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/why-you-need-sql-injection-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
