Posts Tagged ‘Website Vulnerabilities’

SQL Injection Vulnerability Exposes Sensitive Details about Ride Share Users in S. California

by FireHost Evangelist on September 15th, 2009

rideshareFinalProgramming errors on RideMatch.info allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service’s users according to an article featured in The Register.

The RideMatch.info flaw provides inadequate scrutiny of user-generated text entered in search boxes and fields throughout the website. Hackers exploit the SQL injection vulnerability by passing commands directly into the back end database.

The vulnerability was identified and reported in August by Kristian Hermansen, a security researcher who was required by his employer to sign up for the service. His report to The Register stated, “The reason I am bringing this to your attention is that the issue is not being fixed by the admins and most companies don’t even know that their employee’s personal and corporate information may be been compromised.”

To date, the exploit has exposed hundreds of employees’ sensitive information across several organizations in S. California, including at least one military entity.

(more…)

Security Alert: Protecting Your Website from New Hacker Threats

by FireHost Evangelist on August 11th, 2009

webinarFireHost’s CEO, Chris Drake will host a website security webinar for Business Owners and CTOs on Tuesday, August 18th at 11am CDT.

During the presentation, we will demonstrate how easily cyber criminals can compromise a website and provide real “is hacked” examples that have taken businesses offline. We will also reveal some common (and easily patched) website vulnerabilities so you leave armed with key defense tactics that can be put in place immediately.

Session Agenda Includes:

  • Hacker Profiles and Motives
  • Open Source Vulnerabilities
  • The Security Ecosystem
  • Hot to Protect Your Website

Do not miss this opportunity. Take the first step toward protecting your business’ online identity. One lucky audience member will receive 6 months free, secure website hosting, so register now!

Symantec CEO Identifies Three Key Security Risks

by FireHost Evangelist on July 17th, 2009

enriqueSalem_02In an interview with SC Magazine, Symantec’s CEO and President Enrique Salem discussed the new security threats facing companies doing business on the internet. When asked about the top security threats, he responded with three.

“In 2009, we see three key trends that could impact IT security – a continued explosion of new malware variants, advanced web threats, and an uptick in threats related to social networking sites.” Mr. Salem reinforced that “cybercriminals are more sophisticated and driven than ever, and they operate in an increasingly profitable underground economy that makes it easy for them to not only buy and sell stolen information such as credit card data or even identities.”

Data from Symantec’s Global Intelligence Network indicates we have reached the point where there are more malicious programs created than legitimate programs every day, and that cyber attackers leverage vulnerabilities fueled by application code. Hackers compromise specific (often open source) websites, and then use them as a means for launching other attacks across the internet. (more…)

Security Investments Top IT Budgets

by FireHost Evangelist on June 30th, 2009

Despite a challenging economy, many companies are making room in their budgets for investments in information security initiatives.

According to a survey by Robert Half Technology, seven out of ten CIOs interviewed reported their companies would be investing in new information technology initiatives over the next year. 43% of the respondents overall reported information security as a top priority, and in the budgetfinancial services and transportation sectors, information security was cited most often as the top priority.

“Although times are lean, many companies are finding that they can’t afford to postpone IT investments that lead to increased security, efficiencies or revenues,” stated Dave Willmer, Executive Director of Robert Half Technology. “Organizations also are trying to make sure they are prepared for growth when conditions improve, and enhancing their IT infrastructure is part of that process.”

Over the past year, there has been a significant rise in the number of malicious attacks on company websites. Symantec identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.

(more…)

WordPress Popularity Soaring Among Companies

by FireHost Evangelist on June 2nd, 2009

wordpressWordPress has quickly become the first name in blogging, transforming from an idea on a kitchen table to a blog platform with more than 12 million users worldwide in a few short years.

The astonishing success of WordPress rests on the shoulders of the open source principle, which provides free access to anyone and everyone with a desire to use the software. This delivers a no-cost environment for users, but also enables absolutely anyone to contribute to the development of the WordPress source code. This has led to a plethora of plug-ins and themes which can take a WordPress blog to amazing new heights, in both function and aesthetics.

(more…)

USA Today: “SQL Injection Attacks Hit 450,000 a Day”

by FireHost Evangelist on March 20th, 2009

Modern cybercriminals are out to do harm. Simple as that. They penetrate vulnerable websites, steal private customer information, and commit identity theft every day. Hacker tools and methods of attack have become more sophisticated and wider in scope in recent months.

USA Today reports:

SQL attacks take aim at the database layer of websites. They typically were manual attacks designed to pilfer customer data from merchant websites. But last June someone figured out how to automate the attacks, and use them to plant infections. By mid-June, daily attacks spiked to 25,000; by October they topped 450,000 a day.

Holly Stewart, IBM ISS threat response manager, says the infections take advantage of security flaws in cool website features, such as online-delivered video, music, photos, documents and work files.

Giant financial institutions and online merchants have put up strong defenses, says Phil Neray, vice president of security strategy at Guardium, a database security firm. “The same is not necessarily true of regional banks and credit unions, smaller online retailers and state government agencies.”

FireHost is in business to address website security needs of the “smaller guys” Mr. Neray mentions above. It’s imperative your company respond to the threat of cybercriminals swiftly and effectively because SQL attacks strike governments and credit card companies every day. FireHost can help your company avoid the negative spotlight.

SQL attacks are preventable when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. We’ve taken industry-leading measures to make enterprise-level security attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.

Most hosting providers don’t invest the resources required to maintain a prevention-focused, secure hosting environment. If your company does business online however, you owe it to your customers and employees to make sure their most important information is protected.

Here’s just a sample of what puts FireHost secure web hosting in a class of its own:

Network Layer Security
FireHost runs dual Sonicwall internet security devices, providing firewall redundancy for every client. This layer safegaurds websites, emails, and databases from unauthorized intrusions, like SQL attacks.

Application Protection
We also run a web application firewall to close the holes within your website’s applications, the entry-point for SQL attacks.

Vulnerability Monitoring
FireHost partners with McAfee to provide you with web-based website vulnerability auditing and remediation mangement, completing scans every fifteen minutes.

Register here to have a FireHost Security Agent perform a vulnerability report for your website. We will contact you shortly with the eye-opening results.