Showing posts with label Daniel Cid Sucuri. Show all posts
Showing posts with label Daniel Cid Sucuri. Show all posts

Friday, 6 November 2015

Exploit For vBulletin Serious Flaw Made Public


Internet is an exploit for a serious vulnerability in the popular forum software vBulletin appeared, allowing attackers simply unpatched websites can take over. Last week vBulletin's website was hacked. Then followed a password reset to 345 000 users.

Last Monday vBulletin published a security update. According to security firm Sucuri vulnerability has been attacked since the end of October and that are easy to abuse. Through the vulnerability allows an attacker to execute arbitrary commands on a vulnerable website. Sucuri also states that vBulletin.com last week using this vulnerability has been hacked and defaced.

Now the exploit was made public administrators advised to get their website as soon as possible to patch. Through the attack, an attacker can completely take over the website viz. At present there are only perceived attacks against several large websites, but Daniel Cid Sucuri warns that this is likely to change soon as the exploit is included in automated attack programs.

Friday, 18 September 2015

Increase In Brute Force Attacks Against WordPress Sites


WordPress sites get more and more to do with brute force attacks, in which it tries to log in using common passwords on the website. According to figures from security firm Sucuri that brute force attacks keep on WordPress websites.

According to Daniel Cid Sucuri his brute force attacks is still one of the main reasons why websites are hacked. "If you have you have to do with brute force attempts to make an unsecure login page", he tells. Administrators of a WordPress website can according to Cid take various measures against these types of attacks, such as setting captchas, only allowing certain IP addresses (IP whitelisting) and two-factor authentication.

Other WordPress administrators say that the attacks can be prevented simply by changing the URL of the login page and block in the .htaccess / IIS configuration. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. Regular security reports about large numbers of WordPress sites that have been hacked and used to spread malware.