<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog by FireHost &#187; Website Vulnerabilities</title>
	<atom:link href="http://www.fireblog.com/tag/website-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Fri, 16 Dec 2011 00:52:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Introducing Security View: Real-Time Reporting for Blocked Web Application Attacks</title>
		<link>http://www.fireblog.com/reporting-for-blocked-application-attacks/</link>
		<comments>http://www.fireblog.com/reporting-for-blocked-application-attacks/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 13:48:31 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Cloud Hosting]]></category>
		<category><![CDATA[FireHost News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Hacker Prevention]]></category>
		<category><![CDATA[Prevent DoS Attack]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Hacking]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=3520</guid>
		<description><![CDATA[At FireHost we are continually striving to make the secure hosting services that we provide to our customers even better, so that they can have the luxury of running securely and worry-free around the clock. We are happy to announce our latest addition to the MyFireHost customer portal – Security View. Today is just the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="float: right; margin-left: 25px;" title="securityViewScreen" src="http://www.fireblog.com/wp-content/uploads/2011/01/securityViewAnnouncement_6.png" alt="FireHost Security View" width="221" height="200" /></p>
<p>At FireHost we are continually striving to make the <a href="http://www.firehost.com" target="_blank">secure hosting</a> services that we provide to our customers even <em><strong>better</strong></em>, so that they can have the luxury of running securely and worry-free around the clock.</p>
<p>We are happy to announce our latest addition to the MyFireHost <a href="http://www.firehost.com/secure-hosting/customer-portal" target="_blank">customer portal</a> – Security View. Today is just the beginning of an impressive line up new features and enhancements that we’ll be integrating into our service in 2011.</p>
<p>Through Security View, you will have a  front row seat to monitor  your  blocked attacks, in real-time with charts and graphs  that help you visualize  how  frequently hackers attempt to breach your  secure servers, websites  and  web-based applications.</p>
<p>Founder and CEO of FireHost, <a href="http://revolutionblog.com/" target="_blank">Chris Drake</a> voices his concern for web security and the fundamental need for the new enhancements, “<em>Most    companies don’t realize how many attackers attempt to breach their    websites and applications on a daily basis. We are so confident in our    ability to block cybercrime that we’re opening the curtain and inviting    our customers to see how well we protect their websites. Security  View   exposes the reality of cybercrime and lets our customers know  we’re   really looking out for them.</em>”</p>
<p>Here a few of the key features Security View provides:</p>
<ul>
<li>View blocked application layer attacks (SQL Injections, XSS Attacks, Email Hoarding Events, Directory Traversals, and more)</li>
<li>Sort and filter malicious activity by hour, day, week, month, or year</li>
<li>View attack origins by region in real time, for each of your IPs</li>
<li>Customize views to see attacks on your entire network, all the way down to an individual IP</li>
</ul>
<p>Security View is a standard feature available to all customers with Secure Servers virtualized with <a href="http://www.firehost.com/secure-hosting/managed/vps" target="_blank">VMWare</a>. The next time you login to <a href="https://my.firehost.com/login">MyFireHost</a>, simply navigate the tab labeled “Security” and check it out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/reporting-for-blocked-application-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL Injection Vulnerability Exposes Sensitive Details about Ride Share Users in S. California</title>
		<link>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/</link>
		<comments>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 14:00:50 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[security bugs]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2134</guid>
		<description><![CDATA[Programming errors on RideMatch.info allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service's users.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2145" title="rideshareFinal" src="http://www.fireblog.com/wp-content/uploads/2009/09/rideshareFinal.jpg" alt="rideshareFinal" width="140" height="115" />Programming errors on <a href="https://www.ridematch.info/service.asp" target="_blank">RideMatch.info</a> allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service&#8217;s users according to an <a href="http://www.theregister.co.uk/2009/09/08/ridematch_website_vulnerability/" target="_blank">article</a> featured in The Register.</p>
<p>The RideMatch.info flaw provides inadequate scrutiny of user-generated text entered in search boxes and fields throughout the website. Hackers exploit the SQL injection vulnerability by passing commands directly into the back end database.</p>
<p>The vulnerability was identified and reported in August by Kristian Hermansen, a security researcher who was required by his employer to sign up for the service. His report to The Register stated, &#8220;The reason I am bringing this to your attention is that the issue is not being fixed by the admins and most companies don&#8217;t even know that their employee&#8217;s personal and corporate information may be been compromised.&#8221;</p>
<p>To date, the exploit has exposed hundreds of employees&#8217; sensitive information across several organizations in S. California, including at least one military entity.</p>
<p><span id="more-2134"></span></p>
<p>The Ride Match website is a joint project between five regional transit authorities. The service pairs commuters based on home and office destinations as well as departure times. The Riverside County Transportation Commission, an agency responsible for the website, reported to have reached out to the Trapeze Group (a Canada-based development company that designed the software) right after the vulnerability was reported.</p>
<p>Once identified, SQL injection vulnerabilities can often be patched by changing a line or two of code, but The Register spoke to a Trapeze spokesperson on 9/8, and at that time she was unaware of any security bugs being reported on the software. She promised that any vulnerabilities brought to their attention would be investigated and resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Alert: Protecting Your Website from New Hacker Threats</title>
		<link>http://www.fireblog.com/protecting-your-website-from-new-hacker-threats/</link>
		<comments>http://www.fireblog.com/protecting-your-website-from-new-hacker-threats/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 14:00:38 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[FireHost News]]></category>
		<category><![CDATA[cyber criminals]]></category>
		<category><![CDATA[Hacker Prevention]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1763</guid>
		<description><![CDATA[FireHost&#8217;s CEO, Chris Drake will host a website security webinar for Business Owners and CTOs on Tuesday, August 18th at 11am CDT. During the presentation, we will demonstrate how easily cyber criminals can compromise a website and provide real &#8220;is hacked&#8221; examples that have taken businesses offline. We will also reveal some common (and easily [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1915" title="webinar" src="http://www.fireblog.com/wp-content/uploads/2009/08/webinar.jpg" alt="webinar" width="138" height="134" />FireHost&#8217;s CEO, Chris Drake will host a website <a href="https://www2.gotomeeting.com/register/926658051">security webinar</a> for Business Owners and CTOs on Tuesday, August 18th at 11am CDT.</p>
<p>During the presentation, we will demonstrate how easily cyber criminals can compromise a website and provide real &#8220;is hacked&#8221; examples that have taken businesses offline. We will also reveal some common (and easily patched) website vulnerabilities so you leave armed with key defense tactics that can be put in place immediately.</p>
<p>Session Agenda Includes:</p>
<ul>
<li>Hacker Profiles and Motives</li>
<li>Open Source Vulnerabilities</li>
<li>The Security Ecosystem</li>
<li>Hot to Protect Your Website</li>
</ul>
<p>Do not miss this opportunity. Take the first step toward protecting your business&#8217; online identity. One lucky audience member will receive 6 months free, <a href="http://www.firehost.com/secure-hosting" target="_blank">secure website hosting</a>, so <a href="https://www2.gotomeeting.com/register/926658051" target="_blank">register now</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/protecting-your-website-from-new-hacker-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec CEO Identifies Three Key Security Risks</title>
		<link>http://www.fireblog.com/symatec-ceo-discusses-website-security-risks/</link>
		<comments>http://www.fireblog.com/symatec-ceo-discusses-website-security-risks/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 14:00:31 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[protect open source applications]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[Security Threats]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=951</guid>
		<description><![CDATA[Data from <a href="https://tms.symantec.com/Default.aspx" target="_blank">Symantec's</a> Global Intelligence Network indicates we have reached the point where there are more malicious programs created than legitimate programs every day, and that cyber attackers leverage vulnerabilities fueled by application code.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.fireblog.com/wp-content/uploads/2009/07/enriqueSalem_02.jpg" alt="enriqueSalem_02" title="enriqueSalem_02" width="166" height="182" class="alignright size-full wp-image-1728" />In an interview with <a href="http://www.scmagazineus.com/QA-The-New-Security-Agenda-Changing-the-Game/article/131026/" target="_blank">SC Magazine</a>, Symantec&#8217;s CEO and President Enrique Salem discussed the new security threats facing companies doing business on the internet. When asked about the top security threats, he responded with three.</p>
<p>&#8220;In 2009, we see three key trends that could impact IT security – a continued explosion of new <a href="http://security.firehost.com/terms/malware" target="_self">malware</a> variants, advanced web threats, and an uptick in threats related to social networking sites.&#8221; Mr. Salem reinforced that &#8220;<a href="http://security.firehost.com/terms/cyber-crime" target="_self">cybercriminals</a> are more sophisticated and driven than ever, and they operate in an increasingly profitable underground economy that makes it easy for them to not only buy and sell stolen information such as credit card data or even identities.&#8221;</p>
<p>Data from <a href="https://tms.symantec.com/Default.aspx" target="_blank">Symantec&#8217;s</a> Global Intelligence Network indicates we have reached the point where there are more malicious programs created than legitimate programs every day, and that cyber attackers leverage vulnerabilities fueled by application code. Hackers compromise specific (often <a href="http://www.firehost.com/secure-hosting/platforms" target="_self">open source</a>) websites, and then use them as a means for launching other attacks across the internet.<span id="more-951"></span></p>
<p>Hosting websites in a secure environment helps prevent malicious hackers from breaching files and applications and stealing confidential information, but you can to more to protect your identity. Partnering with a web host who also has expertise in <a href="http://www.firehost.com" target="_self">website security</a> is critical. FireHost&#8217;s team of security engineers works directly with clients to help identify and close vulnerabilities in programming and design that hackers can use to exploit your company.</p>
<p>To learn more about how we help remedy JavaScript and open source vulnerabilities, visit our <a href="http://www.firehost.com/services" target="_self">Services</a> page.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/symatec-ceo-discusses-website-security-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Investments Top IT Budgets</title>
		<link>http://www.fireblog.com/security-investments-top-it-budgets/</link>
		<comments>http://www.fireblog.com/security-investments-top-it-budgets/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 14:00:16 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=869</guid>
		<description><![CDATA[Over the past year, there has been a significant rise in the number of malicious attacks on company websites. Symantec identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.]]></description>
			<content:encoded><![CDATA[<p>Despite a challenging economy, many companies are making room in their budgets for investments in information security initiatives.</p>
<p>According to a survey by <a href="http://www.csoonline.com/article/489109/Report_Security_Tops_IT_Budget_Priorities" target="_blank">Robert Half Technology</a><span style="font-family: Arial;">, s</span>even out of ten CIOs interviewed reported their companies would be investing in new information technology initiatives over the next year. 43% of the respondents overall reported information security as a top priority, and in the <img class="alignright size-full wp-image-1567" title="budget" src="http://www.fireblog.com/wp-content/uploads/2009/07/budget.jpg" alt="budget" width="121" height="215" />financial services and transportation sectors, information security was cited most often as the top priority.</p>
<p>&#8220;Although times are lean, many companies are finding that they can&#8217;t afford to postpone IT investments that lead to increased security, efficiencies or revenues,&#8221; stated Dave Willmer, Executive Director of Robert Half Technology. &#8220;Organizations also are trying to make sure they are prepared for growth when conditions improve, and enhancing their IT infrastructure is part of that process.&#8221;</p>
<p>Over the past year, there has been a significant rise in the number of malicious attacks on company websites. <a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport" target="_blank">Symantec</a> identified a 165% in malicious code signatures and cited that the explosive growth can be attributed to the professionalism of malicious code development, supporting the demand for goods and services that facilitate online fraud.</p>
<p><span id="more-869"></span>Vulnerable targets are numerous, however increased threat awareness and security investments can help stem the tide. The two biggest threats to website security are <a href="http://www.firehost.com/secure-hosting/platforms" target="_self">open source vulnerabilities</a> and injection attacks, which often allow the disruption and infiltration of web servers. The results can be devastating for companies and their customers, ranging from the theft of confidential information to the insertion of <a href="http://security.firehost.com/terms/malware" target="_self">malware</a>.</p>
<p>Properly securing your company&#8217;s website and online databases can reduce the risk of a hacking attempt. FireHost uses enterprise, web application firewalls, traffic monitoring, threat detection, automated attack mitigation, and constant monitoring by human personnel to help prevent the serious application-level attacks that negatively impact hundreds of companies and millions of customers every year.</p>
<p>Click <a href="http://www.firehost.com/secure-hosting">here</a> to learn more about our advanced secure web hosting techniques.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/security-investments-top-it-budgets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

