Showing posts with label Content Management System. Show all posts
Showing posts with label Content Management System. Show all posts

Sunday, 15 November 2015

WordPress Websites Frequent Target Of Attacks


WordPress websites are this year more often been the target of attacks than in previous years and are attacked more frequently than other applications. According to a report (pdf) from security firm Imperva. Researchers at the company looked at attacks against websites and web applications. Then it appears that content management systems (CMS) are attacked three times more often than non-CMS applications.

However, when it came to WordPress 3.5 more attacks. Furthermore, WordPress was seven times more often the target of spam and Remote File Inclusion- (RFI) attacks than non-CMS applications. The problem of WordPress is according to Imperva that all plug-ins and extensions for CMS are developed without security to play a role there. This creates ever new vulnerabilities. In addition, WordPress also based on the PHP programming language, according to the security company.

Thursday, 12 November 2015

US Warns Of 'Cyber Incidents' By Webshells


The Computer Emergency Readiness Team of the US Government (US-CERT) organizations warned of "cyber incident" caused by webshells. A Webshell is a script that sets an attacker on a Web server, so that he can control the machine remotely.

Through the infected Web server can then be attempted to attack systems on the internal network of an organization. Using webshells by Advanced Persistent Threat (APT) and criminal groups has led to major cyber incidents, according to the US-CERT. Webshells can be written in different languages, such as PHP and ASP. Perl, Ruby, Python and Unix shell scripts are also used.

To install the Webshell an attacker must first find already existing vulnerabilities, such as the content management system (CMS) or the Web server software. Once the Webshell is uploaded it can be used for various purposes, such as to steal login credentials, install additional malware, as a communication channel to control systems on internal networks which are not connected to the Internet and as a command and control infrastructure, for instance in the shape of a botnet.

To avoid installing a Webshell advises the US-CERT to keep applications and operating system up-to-date, use reduced duties on the Web server, a demilitarized zone (DMZ) between applying the corporate network and online systems, a reverse proxy to use, scanning systems and applications for vulnerabilities and validating user input.

Friday, 23 October 2015

Magento: Hacked Websites Have Not Installed Update



Monday warned security for thousands of hacked Magento sites used to distribute malware. According Magento websites are not adopted by an unknown vulnerability, but the administrators have not installed an important update.

This update was published in February this year and fixed the so-called "Shop Elevator Bug". Through this vulnerability, attackers execute arbitrary code remotely and gain administrator access. In February Magento warned that webmasters should install the update immediately, but eight months later turn out thousands of merchants to have given no answer to this.

In addition, some merchants have been taken over possible because administrators used a weak password. Owners get a Magento site advised to check their website for the presence of malicious code and malware, rename all administrators in the system and install all available updates immediately.

Wednesday, 21 October 2015

Joomla Warns Very Important Update


The makers of the very popular content management system (CMS) Joomla will next Thursday a "very important security" issue, as they have announced. The update would be for a critical vulnerability in the core of Joomla.

Joomla advises managers to be ready for the update Thursday to roll out immediately. "Understand that we are up to the release of the release can provide any further information," according to the developers.

Monday, 19 October 2015

Thousands Hacked Magento Sites Spread Malware


In recent days, thousands of Magento sites are hacked and include malicious scripts that attempt to infect visitors with malware. How websites are hacked exactly is still unknown, so let security firm Sucuri in an analysis know.

According to the company, Google has been hacked 7000 Magento sites blocked. Magento is a popular open source content management system for web shops. Anti-malware company Malwarebytes reports that the attackers script on the hacked websites sites visitors unnoticed to a page with the Neutrino-exploitkit. This exploitkit uses a known vulnerability in Adobe Flash Player to put the Andromeda malware on the system. This malware can steal login details for internet banking and make your computer part of a large botnet.

Friday, 19 June 2015

Critical Vulnerability In CMS Software Drupal Poem


There is an important security update for the popular content management system (CMS) Drupal appeared that fixes multiple vulnerabilities, including a vulnerability that allows attackers websites can take over completely. The leak is in the OpenID module and makes it possible for an attacker as any user to log in, including the manager, and their account hijacking.

Via the other vulnerabilities, it was possible to determine certain information, and to send user via an "open redirect" to a third party website through. This could, for example, can be used for a social engineering attack. Administrators are advised to upgrade to Drupal 6.36 or 7.38.

Sunday, 7 June 2015

Drupal Praises To $ 1,000 For Bugs In Drupal 8


The creators of the popular content management system (CMS) Drupal is a temporary program started with hackers and researchers who find vulnerabilities in Drupal 8 and reporting are rewarded financially.The final version of Drupal 8 is coming and contains major changes to the architecture. To ensure that any security issues and vulnerabilities are found in time the developers on the platform of Bugcrowd launched a so-called "bug bounty" program.

Until August 31 this year to vulnerabilities in Drupal 8, such as cross-site scripting, SQL injection and cross-site request forgery, to be reported. Depending on the impact of the bug guard a reward of between 50 and 1,000 dollars. The rewards are only for Drupal 8 and run until August 31, although the program can be extendable. The program was started last Wednesday, and there are no bug reports received yet until now.

Wednesday, 13 May 2015

Website Chef Jamie Oliver Hacked For Third Time


Attackers are there for the third time succeeded in hacking the website of the British chef Jamie Oliver and use for distributing malware. Previously it had been hit in February and March . As with these incidents the attackers malicious code added to jamieoliver.com.

This code sends visitors unnoticed to another website through which uses known vulnerabilities in Adobe Flash Player and Java to infect visitors with malware. It is malware that attempts to steal passwords. In case the software of visitors up-to-date, they are not at risk. The team that know the website of Oliver would be responsible of the incident and take measures to solve the "once and for all", says anti-virus company Malwarebytes . How the attackers were able to gain access to site is unknown.

Monday, 20 April 2015

Drupal.org Accidentally Leaked Email Addresses Users


The website Drupal.org this week inadvertently leaked the email addresses of hundreds of logged in users. Drupal is a popular content management system with a vibrant community. An adjustment to the permissions of the web site on April 15 was a "small" part of the user to see a list of email addresses of users logged.

It would be a total of some 44 IP addresses that the information at that time approached. According Drupal went mainly to managers of Drupal.org and community participants who reported the incident. The problem was 13 hours after being rectified and introduced within 3 hours after such notice was made. The complete solution was made ​​to be within 24 hours after the onset. According Drupal were visible the email addresses of less than 500 people, all of which will be informed immediately. However, all users are advised to be careful with emails that ask for personal information.

Thursday, 9 April 2015

FBI Warns Of Attacks On WordPress sites


The FBI has warned webmasters attacks on WordPress sites by supporters of IS terror. It comes to news organizations websites, businesses, religious institutions, government agencies and foreign governments that were recent months.

According to the FBI, the attacks are anything but certainly not refined and complex, but they can be disruptive and costly, for example because of the cost for the repair of compromised systems. The attackers use vulnerabilities in all kinds of plug-ins for WordPress, the popular content management system used for tens of millions of websites. Through these leaks can attackers to take over the websites, for example, customize the content and install malware.

The American investigative late warning to webmasters know that the attackers are not members of IS. "These individuals are relatively simple methods that hackers use to exploit vulnerabilities and use of IS the name to get more recognition than otherwise could be achieved through the underlying offense." To prevent the attacks succeed webmasters get the advice system, WordPress plugins and other installed software to keep up-to-date.

Sunday, 15 March 2015

Website Chef Jamie Oliver Spreading Malware Again


The website of the British chef Jamie Oliver has been hacked again and again spreading malware. The site places attackers malicious code that visitors unnoticed forward to another site. This site contains the Fiesta exploitkit which makes abuse of vulnerabilities in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. In addition, the malware is signed, even though the certificate used now no longer valid, as reported anti-virus company Malwarebytes. The virus fighter discovered the first hack the website and then warned webmasters that it fixed the problem. Or so it seemed.

The structure used by the attackers to now placed malicious code is very similar to that of the first attack. "That's why we think this is the same infection that was not completely removed or perhaps that a vulnerability in the server or content management system (CMS) is still present," said the researchers. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Sunday, 1 March 2015

Security Firm Warns Of Hype About WordPress Leak


An American security company has warned the hyping of leaks in the content management system WordPress. Following are reports on various websites about a leak in a WordPress plug-in which more than one million websites were exposed to risk.

The vulnerability was in the plugin called WP Slim Stat. Via the leak would be a "blind" SQL Injection attack are possible.Allows an attacker could read information from the database. According to security firm WhiteFir design these types of vulnerabilities are not used in automated attacks, which most WordPress sites have to deal with. In addition, the leak at the time of news coverage already patched.

"The chances that the leak is abused are quite small compared to a vulnerability that affects PHP files can be uploaded to a website, which will surely be attacked," said the IT security officer. The company also criticizes said plurality of more than 1 million Web sites. The plug-in in question has been downloaded over 1 million times, but downloads does not mean that there are as many websites with the plug-in.

In the case of WordPress are namely also updates to plugins counted as a download. The number of actual users is therefore much lower than the number of downloads. According WhiteFir Design have also the media the opportunity to harm the security of WordPress sites. Users should keep their plugins namely always up-to-date, especially since developers do not always mention that they have remedied vulnerabilities.

Monday, 23 February 2015

TYPO3 Warns Of Critical Vulnerability In CMS


The developers of the popular content management system (CMS) TYPO3 have warned of a critical flaw in the software that only can be logged in with a user name. To also carry out the attack, the CMS software must be set in a certain way.

The system extension must "rsaauth" are loaded and configured in a particular way for frontend use. Furthermore, there must be a vulnerable CMS version installed. The leak, which has not yet CVE number, is present in versions 4.3.0 t / m 4.3.14, 4.4.0 t / m 4.4.15, 4.5.0 t / m 5.4.39 and 4.6.0 t / m 04/06/18. Users have strongly advised to upgrade to 5.4.40 or use a specially crafted shell script that vulnerable TYPO3 versions patches.