Monthly Archives: June 2010

Bluehost Talks Down Malware Percentages – Offers Sucuri a Forum Ban

On Sunday we reported that a number of sites hosted by Bluehost had been hacked (including their CEO’s blog). On Monday while browsing through some of their forums, we noticed a thread regarding the exploit with remarks from forum moderators … Read more


Posted in awareness, bluehost, hacked, malware, sucuri | Tagged , , , | 25 Comments

Bluehost CEO blog & others exploited by domainameat.cc

We’re seeing that a good number of sites hosted at Bluehost have been hacked and infected with malware from domainameat.cc. The blog of Matt Heaton, CEO of Bluehost was also exploited (mattheaton.com). After analyzing some of these sites, they were … Read more


Posted in hacked, malware, security, sucuri | Tagged , , , , | 46 Comments

Brazilian Government Websites Hacked with Spam

In the last few months we’ve been tracking a common technique being used by attackers: They hack a web site and use that as part of their link farm to build page rank for them on search engines. We posted … Read more


Posted in brazil, hacked, security, spam | Tagged , , , | 6 Comments

Web sites hacked with malware from iopap.upperdarby26.com

We are seeing today a good number of sites hacked with malware from http://iopap.upperdarby26.com. The malicious javascript is added to the bottom of every index.php file and to the bottom of a few javascript files as well. The malware is … Read more


Posted in blacklist, hacked, malware, security | Tagged , , , | 2 Comments

Cleaning SPAM from your WordPress blog.

A common trend lately is SPAM getting added to WordPress blogs. Attackers are using this to increase their page rank on search engines like Google, Yahoo, etc. So, if you search for your site on Google do you see a … Read more


Posted in malware, spam, sucuri, wordpress | Tagged , , , , | 2 Comments

The Mission of Security Awareness

This article was written by Christopher Vera, CISSP, HISP, GCFA, GLEG for Sucuri. Of all the elements of a successful cyber security program, security awareness is probably one of the least understood. Some cyber security professionals have even gone as … Read more


Posted in awareness, communications, corporate, enterprise, security, sucuri | Tagged , , , , | 6 Comments

Attack of WordPress blogs on Rackspace

Update: It is not a “mass” attack as we described. Sorry about that. A good number of sites were affected (we don’t have a clear number yet), but nothing massive or crazy as our post sounded. If you follow our … Read more


Posted in hacked, malware, rackspace, spam | Tagged , , , , | 9 Comments

Mass infection of IIS/ASP sites – 2677.in/yahoo.js

A large number of sites have been hacked again in the last few hours with a malware script pointing to http://2677.in/yahoo.js . Not only small sites, but some big ones got hit as well. It is the same SQL injection … Read more


Posted in hacked, iis, malware | Tagged , , , | 13 Comments

GoDaddy sites hacked with cloudisthebestnow

If you thought your problems at GoDaddy were over, well, not yet. We’ve confirmed that today at around 3pm EST, GoDaddy servers were hacked again. Malware pointing to cloudisthebestnow.com/kp.php was inserted on thousands of sites hosted by the provider. This … Read more


Posted in cloudisthebestnow, godaddy, hacked, malware, wordpress | Tagged , , , | 12 Comments

Mass infection of IIS/ASP sites – robint.us

An incredibly large number of sites have been hacked in the last day with a malware script pointing to http://ww.robint.us/u.js. Not only small sites, but some big ones got hit as well: http://www.intljobs.org (still hacked) http://www.servicewomen.org (still hacked) http://online.wsj.com (partially … Read more


Posted in hacked, malware, security, sucuri | Tagged , , , | 57 Comments