Posts Tagged ‘XSS’

WordPress 2.8.2 Upgrade Addresses XSS Vulnerability

by FireHost Evangelist on July 29th, 2009

wp_securityThe latest upgrade for WordPress addresses an important XSS vulnerability in the open source application, so don’t delay installing it. Upgrading to WordPress 2.8.2 is easy.

WordPress users can get the latest version (which was released about a week ago) three ways:

  1. Download it here to manually upgrade.
  2. Initiate the upgrade automatically by clicking the Upgrade link under the Tools menu in your blog’s admin. (v 2.7 or later)
  3. Host your website with FireHost, and let us take care of the upgrade for you.

We’re glad to see WordPress take action to help prevent hackers from compromising websites built on the their great platform. Kudos to the WordPress team for helping keep everyone safe.

The Nuisance and Threat of Cross-Site Scripting (XSS)

by FireHost Evangelist on June 5th, 2009

misquito2Recently, Brian Krebs from the Washington Post reported that thousands of insecure websites were identified last year, many of which contained cross-site scripting (XSS) vulnerabilities. The stunning revelation in this report is the sheer number of websites that harbor the cross-site scripting (XSS) vulnerability.

Xssed.com lists nearly 13,000 Web pages that hosted cross-site scripting vulnerabilities, including a large number at trusted and high-traffic Web sites such as yahoo.com, google.com, msn.com, myspace.com and facebook.com, and cnn.com.”

(more…)

Are you at risk of a cross-site scripting attack?

by FireHost Evangelist on April 28th, 2009

xss-threat3In basic terms, cross-site scripting (XSS) is a popular method of attacking a website’s application vulnerabilities by injecting target websites with malicious code. The goal is typically to embed a program which steals data, leading to credit card or identity theft. During these attacks, affected websites appear perfectly normal to visitors, who continue to use the website as they normally would.

Consider this example:

Mary frequently visits an online shopping website. One day, hackers use a cross-site scripting attack on the website, embedding malicious code. Mary returns to the website and buys a pair of new shoes, unknowingly passing her confidential information to hackers. Before she realizes what happened, someone has stolen her identity and ruined her credit.

Every business owner has more important things to do than mitigate a very public theft of your customer’s personal data, so make securing your customer data a priority today.

Unfortunately for consumers and businesses, many hosting providers don’t take effective measures to prevent cross-site scripting (XSS) attacks on their clients. If your hosting provider doesn’t address cross-site scripting attacks (XSS) properly, your company’s website could easily fall prey to hackers and expose your customer’s personal information.

Security is the primary focus at FireHost. We pride ourselves on providing industry-leading secure hosting, which includes a WAF to prevent cross-site scripting (XSS). This hardware security device stops hackers from exploiting web applications, securing your website, business, and customers from cross-site scripting (XSS) attacks.

To discover more about our secure hosting and prevention of cross-site scripting (XSS), contact a FireHost Agent today.