Showing posts with label Hacking News. Show all posts
Showing posts with label Hacking News. Show all posts

Sunday, 11 March 2018

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Wednesday, 28 February 2018

Veil System: Researchers Make Private Browsing More Private


All modern browsers now have private browsing, a function that ensures that the surfing behavior is not stored on the computer. However, the information that is accessed during private browsing can still be retrieved from the computer by a motivated attacker. Reason for researchers from MIT and Harvard to develop a new system called Veil that should make private browsing more private.

Browsers should delete all stored data after closing a private browsing session. However, modern memory management is complex and can ensure that data is left in the memory somewhere. Veil tries to tackle this problem by encrypting all data that the browser loads into memory until it is displayed on the screen.

The use of Veil

To use Veil, the Veil user goes to the Veil website and enters the url of a website. A special "blinding server" then sends a version of the requested page in the Veil format. The Veil page is similar to a normal web page, but contains code that executes a decryption algorithm. The data on the page is unreadable until it is decrypted by the algorithm. Once the data has been decrypted, it must be loaded into the computer's memory to be displayed on the screen. This temporarily stored data should be much harder to trace when the browsing session is over.

In order not to give attackers a chance, Veil takes an additional security measure. The blinding server adds meaningless code to every loaded page. This code has no effect on how the page before the user looks, but does change the underlying source file. Every page that is loaded by a blinding server, even if it is the same page, looks different. An attacker who manages to obtain part of the decrypted code after closing a Veil session is therefore unlikely to say which website the user visited.

When these measures are not enough, Veil also offers the option to have the blinding server take a picture of the requested page. In this case, the blinding server opens the requested page, makes a screenshot of it and sends it to the user. This prevents executable code from ending up on the user's system. If the user then clicks on the image somewhere, the browser registers this and sends the new request to the blinding server, which then loads a new zoomed image and sends it back to the user.In order to use the system, websites do have to create a Veil version of their website, but the researchers have developed a compiler for this that automatically performs the conversion. A bigger challenge is hosting the blinding servers, which can be done by volunteers, as is the case with the Tor network, or by companies that, for example, want to offer their visitors more privacy. No adjustments to the browser are required for the implementation of Veil.

Researchers Warn Of Android Malware RedDrop



Security researchers warn of a new type of malware for Android phones called RedDrop. Hackers can not only steal a lot of information from the infected smartphone, sounds can be recorded and photos can be taken and Premium SMS messages can be sent.

Security company Wandera has researched the new malware and observes that RedDrop is now nestled in at least 53 Android apps. When such an infected app is opened, at least seven new APKs are installed in the background, each with malicious functions.


With the help of spyware, all kinds of information about the user is collected and then sent to a Dropbox account of the attacker. The data collected includes local files, such as photos, live sound recordings, device and SIM information (IMEI, IMSI, MNC, MCC) and information from the application and Wi-Fi networks in the area.

Also, if a user uses the infected app, a text message is sent to a payment service in the background, which is immediately removed to prevent discovery.

The creators of RedDrop use a content distribution network with more than 4000 domain names to distribute the malware. The researchers suspect that a lot is referred to domains to hide the source of the malware as well as possible.

Malware Infection Chain:



According to Michael Covington, VP Product Strategy at Wandera, this is very sophisticated malware . "The criminals very cleverly offer a seemingly handy app that performs all sorts of complex malicious activities in the background. The attacker not only uses a wide range of malicious applications to tempt the victim, they have also perfected every little detail to ensure that their actions are difficult to trace. This is one of the more persistent malware variants we've seen. "

Monday, 11 December 2017

German Secret Service Warns Against Fake Profiles On LinkedIn



The German secret service BfV warns against fake profiles on LinkedIn that would be used by Chinese intelligence services to gather information about politicians and policymakers. Over a period of nine months more than 10,000 Germans were approached via the fake profiles, according to the BfV.

The profiles occur as headhunters, consultants or scientists with the names "Rachel Li" and "Alex Li". They claim to have, among other things, vacancies at a Dutch HR company. After contact has been made, the fake profiles try to collect information about habits, hobbies and political interests. "Chinese intelligence services are active on networks such as LinkedIn and in this way try to gather information and find sources of information," said a spokesperson.


Many of the profiles are provided with photographs of attractive men and women. One of the photos would even be taken directly from an online fashion catalog, according to Reuters . The fake profiles have mainly provided for European diplomats and politicians. German citizens are called upon to report suspicious profiles and not to share valuable personal information via social media. "This is an extensive attempt to infiltrate certain parliaments, ministries and government agencies," says Hans-Georg Maassen, head of the BfV.

Conficker Worm Still Active On 150,000 Computers After 9 Years


The Conficker worm that infected nine million computers at its peak has been operating on 150,000 computers since its first appearance on 21 November 2008, anti-virus company Trend Micro said. Conficker is distributed in a variety of ways, including a vulnerability in the Windows Server service, shared network folders, and the Autorun feature of Windows.

The vulnerability in the Windows Server service was patched by Microsoft on October 23, 2008. In January 2009, Conficker also started distributing itself through the Autorun feature of Windows, something for which Microsoft released an update in February 2011. According to Trend Micro, Conficker is mainly active in China, Brazil and India. These three countries together account for more than half of all infections. Most infections were found in government systems, followed by production companies and health care.

After an infection, Conficker tries to connect every day with all kinds of domains to see if there are new instructions from the makers. ICANN, the organization that is responsible for the distribution of ip numbers and domains, has, however, taken measures so that these domains can not be registered. Thus, the infected computers can not be used for criminal purposes.

According to Trend Micro, Conficker can also be labeled as "background malware" that is mainly active on legacy systems. "Although it is not as interesting to the general public as more modern malware such as WannaCry and Petya, it remains a persistent threat and will remain so as long as unsupported, unpatched legacy systems are still part of corporate networks," says researcher the virus fighter .

Sunday, 10 December 2017

Strong Increase Of Phishing Sites That Use Https



Not only legitimate websites use https more and more, phishing sites also have more and more access to a secure connection. There is even a strong increase in the number of https phishing sites, according to security company PhishLabs . In the third quarter of this year almost 25 percent of the observed phishing sites had a https connection.

A quarter earlier was still about 12 percent, while a year ago less than 3 percent of the phishing sites had a ssl certificate. According to the security company, there are two reasons why there is an increase in https usage among phishing sites. The first reason is that phishing sites are regularly offered via hacked, legitimate websites. When a legitimate website with a ssl certificate is hacked, the phishing page that is offered via the website will also have a secure connection.


The second reason according to PhishLabs is that criminals register domains for their phishing site and then enable https themselves. This then happens via certificate authorities that offer free ssl certificates, such as Let's Encrypt and Comodo. In this way, the phishing site looks more legitimate, says Crane Hassold of PhishLabs. Chrome automatically displays the "Safe" message at https sites. This refers to the secure connection, but end users think the website they are visiting is safe, Hassold notes.

"The misunderstanding about the meaning of https among the general public and the confusing appointment of https websites in browsers are the main reasons why it is a popular preference of phishers in hosting phishing sites," Hassold continues. "Combined with the rapid growth of https among website owners, we expect the number of https phishing sites to grow further."

Explanation How To Remove The Microphone From Your iPhone And MacBook



Those who do not want to risk using a hacked iPhone or MacBook as a listening device can choose to remove the built-in microphone. Calls can then only be made by connecting a headset with a microphone, for example.

"There is no reason why these devices need those sensors to function," says Kyle Wiens from repair company iFixit opposite Wired . "And taking them apart to remove the microphone is not more difficult than repairing them." Users can switch off the microphone or even insert a cut-off jack in the microphone socket if it is already present, but according to experts this does not offer sufficient protection.

According to Richard George, a former technical director of the NSA who was involved in the design of the secure BlackBerry of President Obama, the trick with the microphone jack is not enough. A malicious application could bypass the fake microphone and still enable the real microphone. Anyone who wants to be sure of his case can also remove the microphone or have it done.

In the case of a MacBook, this appears to be fairly simple. So iFixit even has a manual for it. The microphone can also easily be connected again. The same operation with the iPhone is a lot more difficult and permanent. The iPhone also has four built-in microphones. Once again, iFixit offers extensive instructions for doing this yourself. A repair company that Wired spoke costs 75 dollars and says twice for privacy-oriented customers.

Last year whistleblower Edward Snowden advised that people who do not want to be spied or tapped would be wise to remove the microphone and camera from their smartphone. Recently, however , the Public Prosecutor announced that legitimate users have no reason to "demolish" the microphone from their device. The verdict was made in connection with the investigation into Ennetcom, a company that supplied custom BlackBerry smartphones to communicate encrypted. The microphone was removed from these phones.

Tuesday, 24 October 2017

Well-known British Clinic For Plastic Surgery Hacked



Attackers hacked a well-known British clinic for plastic surgery, taking off all sorts of sensitive patient data including photos. Opposite The Daily Beast, the attackers, known as The Dark Overlord, claim that they stole terabytes of data.

Information about members of the royal family would also be available in the stolen databases. The attackers shared information and operation photos with a journalist from The Daily Beast . The attackers' emails were sent from a hacked clinic's e-mail account. The attackers are threatening to make the stolen images public.

On its own website , London Bridge confirms Plastic Surgery and states that it has taken measures to stop the attack. It is now investigating what data the attackers have taken precisely. How the attack could take place do not let the clinic know, but on Twitter it speaks of a " refined cyber attack ". Earlier, a Hollywood studio was also squeezed by the group after Orange's episodes have not yet appeared, the New Black had been stolen.

Man Charged For Hacking 550 Gmail And iCloud Accounts


In the United States, a 32-year-old man is charged with hacking over 550 Gmail and iCloud accounts, including Hollywood star and other celebrity accounts. According to the charge, the man sent phishing emails from April 2013 until the end of August 2014 in which recipients were asked to return their username and password.

If the recipient responded and returned the credentials, the man used to log in to the victim's iCloud and Gmail account. As soon as the man logged in, he searched for sensitive personal information, including photos and videos. The case against the man arises from the search for 'Celebgate' or 'The Fappening', which loads all kinds of nude photos of celebrities. However, the FBI has not found evidence that the accused man is responsible for leakage of the naked photos or that he has shared or uploaded the information obtained.

The man has now signed a "plea" agreement with Justice and is expected to acknowledge debt, as soon as the US Department of Justice knows. Earlier this year, a 29-year-old American was sentenced to a nine-month imprisonment for hacking the iCloud and Gmail accounts of more than 300 people, including at least thirty Hollywood stars. According to the FBI, this man was not responsible for Celebgate.

Monday, 23 October 2017

Attack Via Office DDE Feature Also Works In Microsoft Outlook



The Microsoft Office DDE feature currently used to attack Internet users through Word documents also works in Microsoft Outlook, so researchers have shown. The attack can be performed by sending emails and calendar invitations set up in Rich Text Format (RTF).

The Dynamic Data Exchange (DDE) feature of Microsoft Office makes it possible to inject data from, for example, an Excel document into a Word document. This will add code to one document that points to the data in the other document. Instead of a document, malicious code may also be linked. Attackers now use this feature to infect internet users through Word documents with ransomware and other malware.

The attackers send emails that have attached a Word document. As soon as the recipient opens the document, he will see several dialog boxes asking for permission to run the code that is linked. However, it is not necessary to send Word documents, so researchers have shown . Researcher Kevin Beaumont found a way to use the DDE feature in Microsoft Outlook via e-mail. In this case, users get the same notification as with Word asking for permission to execute code.


In addition to a RTF-generated email, the attack can also be performed via a calendar invitation. According to anti-virus company Sophos , the attack is easy to stop, users need to click on no-click in the first window asking for code execution. If the user clicked yes in the first window, a second dialog will appear for permission. Only when yes is clicked is the code called through DDE executed. Another option that users can apply to protect themselves is to display emails in plain text.

Tuesday, 10 October 2017

ISC Warns Usb Cable With Built-In Sim Card


The Internet Storm Center (ISC) warns of usb cables that are sold and have a built-in sim card, mobile phone and microphone. Attackers could perform attacks or stolen data through such cables, according to Johannes Ullrich of the ISC.

For example, the $ 30-usb usb cable responds to text messages and can send those GPS coordinates. It is also possible to activate and listen to the microphone via a text message. "The main risk is to leave systems (and cables) left unattended in places with some public access," Ullrich notes. This applies, for example, to systems in hotel rooms or classrooms.

Users therefore get the advice to mark their cables so that they can not be replaced by other cables. In addition, the cables must be fastened. In conclusion, Ullrich states that the "usb spy cable" in question is easy to recognize when users know what to look for. "But I'm sure they can make a smaller cable and maybe a version that's a bit more expensive and not so easy to show the sim card."

Sleep Pattern WhatsApp Users Easy To Follow


It's easy to follow WhatsApp usage and sleep patterns of WhatsApp users. For example, information that can be sold to health insurers and credit agencies, says software engineer Robert Heaton . Using only the WhatsApp user's phone number, it is possible to read his status, as if he is online and when he was last seen.

It is not necessary to be friends with the WhatsApp user. Only a phone number is sufficient. Heaton wrote a simple script that requests information every 10 seconds at WhatsApp. Then he processed the data in a graph, making it clear that the sleep pattern of the WhatsApp user he wanted to follow became clear. Users can set to see their "last seen" status show. By default, however, this status is visible to everyone. Additionally, users can not hide their "online" status.


According to Heaton, it is so easy to make graphs of both theirs and strangers using their WhatsApp use and sleep patterns. Information that can be sold to health insurers and credit agencies that are interested in "deviant behavior", for example, let the engineer know. Other scenarios are outlined at Hacker News , which allows the status information to communicate which friends communicate in a contact list via the status information. For example, it may be outdated whether people are cheating or having an affair.

Monday, 9 October 2017

Infected Pornhub Ads Spread Kovter Malware



On the popular porn site Pornhub, infected advertisements appeared to infect visitors with malware. According to market researchers, the porn site is ranked in the top 30 of most visited websites in the world. Pornhub claims itself to get 75 million unique visitors a day.

The infected ads were spread through Traffic Junky's ad network. The ads passed users to a website that believed that there was an important update for the browser or Adobe Flash Player. When users clicked on the page, a JavaScript file was downloaded that installed the final malware. It was about malware that caused the computer advertising fraud. After being informed, both Traffic Junky and Pornhub have removed the ads, according to security company Proofpoint.


"The combination of large scale malvertising campaigns on print-enabled websites with sophisticated social engineering that convinces users to infect themselves means that potential exposure to malware is quite high and millions of Internet users are reached," says the Proofpoint researcher with the alias Caffeine. "Once again, we see that attackers exploit the human factor as they adapt their tools and approaches to a landscape where traditional exploits are less effective." The investigator thus targets the fact that attacking vulnerabilities in browsers and Adobe Flash Player causes ever fewer infections to cyber criminals.


Indicators of Compromise (IOCs):


IOC
IOC Type
Description
www.advertizingms[.com|204.155.152.173
domain|IP
Suspicious Epom server 2017-10-01
*-6949.kxcdn.com
domains
Subdomain from a rogue KeyCDN customer 2017-10-01
phohww11888[.org|192.129.215.155
domain|IP
KovCoreG soceng host  2017-10-01
cipaewallsandfloors[.net|192.129.162.107
domain|IP
KovCoreG soceng host  2017-10-01
b8ad6ce352f502e6c9d2b47db7d2e72eb3c04747cef552b17bb2e5056d6778b9
sha256
            T016d6n7t96x2hc43r5f3u6gs61d.zip (zipped runme.js)  2017-10-01

4ebc6eb334656403853b51ac42fb932a8ee14c96d3db72bca3ab92fe39657db3
sha256
FlashPlayer.hta
 2017-10-01
a9efd709d60e5c3f0b2d51202d7621e35ba983e24aedc9fba54fb7b9aae14f35
sha256
Firefox-patch.js
 2017-10-01

0e4763d4f9687cb88f198af8cfce4bfb7148b5b7ca6dc02061b0baff253eea12
sha256
 Kovter 2017-10-01

f449dbfba228ad4b70c636b8c46e0bff1db9139d0ec92337883f89fbdaff225e
sha256
 Kovter 2017-10-01

WordPress Sites Vulnerable By Leak Into Postman SMTP Plug-In



Over 100,000 WordPress sites are vulnerable due to a vulnerability in the Postman SMTP plug-in, and a developer security update is not yet available. Postman is an SMTP mailer that helps send emails generated by the WordPress site.

The plug-in is vulnerable to reflected cross-site scripting, which allows an attacker to steal the content of cookies from, for example, the administrator, according to security company White Fir. Due to the unpatched vulnerability, WordPress decided to remove the plug-in from the database with available plug-ins on WordPress.org . Meanwhile, GitHub has published a patched version of Postman, but it has not been developed by the original author. The original developer would have been informed about the problem.

Thursday, 5 May 2016

German Government Launches Test Plan For Security Routers


In order to ensure that routers that individuals and small businesses purchase are safe, the Bundesamtes für Sicherheit in der Informationstechnik (BSI), part of the German Ministry of the Interior, today a comprehensive test plan ( pdf ) launched broadband routers.

The test plan, especially for Internet service providers and manufacturers intended, which describes a secure router to meet.In this way, potential buyers can more easily compare models in the field of security with each other. According to the BSI, the security of a router, an important factor when choosing a particular manufacturer or type. The German federal government has recently abolished the so-called router obligation. Thereby German internet users can choose yourself which soon modem and router that they want to use their broadband connection.

"Routers are a central part in the digitalization and networking. They are the heart of the home network, but protect at the same time against Internet threats. The abolition of the router obligation have internet August this this year more choice in choosing their router. users should make use of this by looking at the safety when choosing a router, "said Arne Schönbohm, head of the BSI.

In the test plan different parts are discussed, such as the presence of security measures. Thus, each router must sort the BSI have a firewall and there should be no default port forwarding enabled. In addition, made several recommendations, such as the presence of an automatic update feature. Furthermore, the test plan contains examples of common vulnerabilities and attack scenarios.

UK Hospitals Receive 230,000 Euro Fine For Data Leak


A collective of UK hospitals has been fined more than 230,000 euros since it had placed the private information of staff inadvertently on its website. It was the national insurance number, date of birth, religion and sexual orientation of 6,500 employees.

The collective discovered the data breach after 10 months and had another 5 months to inform the affected employees. The information was provided voluntarily by the staff, so that collectively an annual overview of diversity and equality could publish within hospitals. The spreadsheets were found to contain hidden data simply became visible by double-clicking on a table. Because of the data breach, the UK data protection authority ICO now fined 185,000 pounds (the equivalent of more than 230,000 euros).

Wednesday, 4 May 2016

Many Websites Vulnerable ImageMagick Leak


A serious vulnerability in ImageMagick , a popular software library to handle with graphics, ensures that a large number of websites are vulnerable and at risk of being hacked. In case a website allows users to upload an image and using ImageMagick, an attacker can, at worst, run arbitrary code on the Web server.

Several plug-ins for image processing depend on the ImageMagick library, such as PHP's imagick, Ruby's RMagick and paperclip and NodeJS's imagemagick. The vulnerability is called " ImageTragick received" and was discovered by security researcher Nikolay Ermishkin . According to researcher Ryan Huber, it's easy to make abuse and will exploit them for short term appear.

The prediction Huber yesterday evening did turned out to be correct, because now such exploits include published. The developers of ImageMagick have a solution available that prevents the attack. Administrators should add a few lines of code in this case a file used by ImageMagick. A security will be released this weekend.

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Google: Sharp Drop In Android Malware On Google Play


The number of malicious apps in Google Play has dropped sharply last year, says Google in a new report. For the second time the Internet giant published the Android Security annual report ( pdf ). Compared to 2014 took the risk of the installation of malicious applications by 40% in 2015.

The malicious apps are divided by Google in various categories like apps that collect data, spyware, Trojans and apps to download additional software. The percentage of apps which collects data decreased by 40%, to 0.08% of all installations.Spyware decreased by 60% to 0.02% of the installations and malicious downloaders saw a 50% decrease to 0.01% of all installations. However, the category of Trojans rose from 0.01% to 0.02%. Eventually it was less than 0.15% of all Android Devices that download malicious apps from Google Play only apps installed.

About 0.5% of the devices that was downloaded from Google Play apps as well as other resources to deal with malicious apps. In addition, Google says that it also protects users download these apps from other sources. For this, use the Verify Apps. Warnings Verify apps were improved last year, which was an increase of 50% of users decided not to install the app in question after a warning. End of 2014 Android Phones got to it first with ransomware. This category of malware was according to Google last year found only outside of Google Play.

Google Helps Owners Hacked Websites With Maid


If Google webmasters and owners of a hacked website helps to existing vulnerabilities and malicious code quickly resolved, according to research. According to Google , more than 10 million Internet users every week with malicious Web sites in touch.

It often involves hacked websites which install owner or webmaster failed security updates or to choose a strong password.This makes it easy for cyber criminals to take over a website and use for example distributing malware. Google warns Internet users of such web sites, but many webmasters do not follow the Internet giant by that something is wrong.

And even if they are informed of the security incident, they miss to overcome the knowledge to solve the problem. Google therefore decided to look together with the University of California at Berkeley how webmasters can be best informed and the problem as soon as possible can be resolved. From the research shows that if Google cooperates directly with the webmaster, 75% of webmasters manages to secure their website. A process that takes an average of three days.

To help webmasters soon be considered by investigators three important steps. The first and most difficult step is to inform the webmaster. In the case webmasters their website via Webmaster Tools have registered a Google mail ensures that 75% of webmasters secures the website. In the case of the webmaster is unknown the e-mail address, have browser warnings and alerts in the search engine a success rate of 54% and 43%.

The second step in the process is to give hints about the harmful content. Attackers often hide their files, which complicates the cleaning process. In the event Google tips on the infection to the webmaster e-mailed this made sure that the cleaning sheet was 62% faster than warnings without tips. The third step is to make sure that continues to clean the site. Google investigated and cleaned hacked websites and found that 12% had been hacked again within 30 days. That shows, according to the Internet giant how important it is to find the cause of a hack rather than to remedy the effects.