Showing posts with label Sucuri. Show all posts
Showing posts with label Sucuri. Show all posts

Friday, 6 November 2015

Exploit For vBulletin Serious Flaw Made Public


Internet is an exploit for a serious vulnerability in the popular forum software vBulletin appeared, allowing attackers simply unpatched websites can take over. Last week vBulletin's website was hacked. Then followed a password reset to 345 000 users.

Last Monday vBulletin published a security update. According to security firm Sucuri vulnerability has been attacked since the end of October and that are easy to abuse. Through the vulnerability allows an attacker to execute arbitrary commands on a vulnerable website. Sucuri also states that vBulletin.com last week using this vulnerability has been hacked and defaced.

Now the exploit was made public administrators advised to get their website as soon as possible to patch. Through the attack, an attacker can completely take over the website viz. At present there are only perceived attacks against several large websites, but Daniel Cid Sucuri warns that this is likely to change soon as the exploit is included in automated attack programs.

Monday, 27 April 2015

Still 88,000 Shops Vulnerable Magento Leak



A critical vulnerability in the popular shopping cart software Magento allow an attacker to completely take over the shop is still in 88,000 merchants present, even though the update since early February. The vulnerability is now being used to attack shops.

In addition, security company Check Point has released details about the leak. Researchers from the company warned Magento on 14 January this year about the problem they had found. A few weeks later, a security Magento. Still, many merchants decided not to install it. The Dutch hosting company Byte warned a week ago that still 140,000 merchants risked because they were not patched. Meanwhile, a significant portion of the vulnerable Magento shops install the update, but are still vulnerable 88,000 shops, according to the last census of Byte.

That census took place last Friday, the same day that the Magento developers a warning afgaven for the leak. Security firm Sucuri reported Friday that it had now perceived attacks that made ​​abuse of the leak. In addition, the company claimed that merchants who had rolled the patch not yet been hacked or that would be only a matter of time. Below is a video demonstration of Check Point which shows how online stores can be robbed by setting the price of goods at zero through the leak.

Friday, 16 January 2015

Google Adsense Used For Malicious Ads


Cybercriminals have used Google Adsense to display ads on all sorts of malicious websites that visitors to these sites for several scam sites by sent. Numerous webmasters complained about the ads that ensured that visitors were redirected automatically.

The scam sites where visitors ended up offered all kinds of products to lose weight, aging combat, combat skin problems or improve IQ. The websites looked like blogs and magazines with so-called scientific studies and research on the products, complemented by all kinds of false responses from people who supposedly had tried the products.

The problem with the malicious ads would play since mid-December, but was last Friday, January 9th widely felt. On the Google AdSense forum, more than 180 responses from angry webmasters inside. Webmasters who use Google Adsense on their websites and see how visitors were redirected by the malicious ads.

On January 10, Google would have solved the problem. According to security firm Sucuri used the attackers behind the attack two legitimate AdSense campaigns, they probably via guessed or stolen credentials managed to hijack. However, it is not excluded that the scammers Adsense accounts have created yourself and initially did occur that it was legitimate campaigns.
Code

Researcher Denis Sinegubko of Sucuri is wondering why Google allows advertisers may use this type of potentially dangerous code. "I realize that Google advertisers flexibility in managing their campaigns and the use of scripts will give their own pages. And I realize that at the first check these scripts did nothing malicious, and is only misbehaved after they were approved. But there would have to be more in control of third-party scripts. "

Sinegubko further notes that nobody likes ads, but they are indispensable for many websites. "I will not tell you to remove all ads from your site," he says to webmasters. "But I ask you to think about the safety and reputation effects that may have bad ads for your site. Consider each script from a third party that you place on your website as a potential threat. Especially those scripts that others who do not knows, allow you to place content on your site. "

Friday, 26 December 2014

Google disables 39,000 WordPress sites for malware



Google has already put more than 39,000 Wordpress websites on a blacklist because they are infected with malware. Attackers use a leak in the WordPress Slider Revolution Premium plug-in attempts to infect to get access to the sites and then add malicious code that visitors with malware. The leak in the plug-in has long been known, and a patch is available. Many sites that have not been installed.

According to security firm Sucuri involves three different campaigns where the SoakSoak campaign is responsible for most infections. According to Google, the malware of this website to over 17,000 detected domains. Through the wpcache blogger campaign are spacious 12,000 sites have come to the blacklist of the search giant. Finally, there is an IP address that the attackers and code to 8500 was found websites.

Once Internet users to visit these Web sites via eg Google Chrome or Firefox they'll see a warning. Sucuri Commission on the basis of own research that more than 50,000 websites have been infected, but they have not all been indexed by Google.

Affected websites are advised to do a "complete cleaning" of the website, since installing WordPress alone is not enough again. The attackers would in fact leave too many backdoors. Additionally WordPress administrators are urged to update their plugins. With over 74 million websites WordPress is the most popular online content management system.

Monday, 15 December 2014

'SoakSoak' Malware Infected 100,000+ Wordpress Websites




At over 100,000+ WordPress sites researchers have found malicious code that attempts to infect visitors with malware. The code is loaded from the Russian domain SoakSoak. Google would now more than 11,000 infected websites have put on a blacklist.


Visitors who use Firefox or Chrome receive when visiting these WordPress sites a warning that the site contains malware. According to security firm Sucuri is the number of affected sites much larger and would amount to more than 100,000 WordPress installations. Also on the forum WordPress complain many users SoakSoak on their website.

How the attackers managed to get the malicious code on the WordPress sites is still unknown, but it is suspected that the sites a vulnerable version of the WordPress Slider Revolution use premium plugin. By September WordPress sites with a vulnerable version of the plug-in even though the target of attacks.