Monthly Archives: December 2010

Attacks against GoDaddy – acrossuniverseitbenet + Hilary Kneber + HardSoft

For the last few days we’ve tracking another large scale attack against GoDaddy shared-hosted sites. GoDaddy has been a target for a while, with mass infections happening often. This time, the attackers changed tactics and instead of infecting the PHP … Read more


Posted in godaddy, hacked, malware, malware_updates | Tagged , , , | 28 Comments

Weekly malware update – 2010/Dec/17

Starting this week, we’re going to begin posting a weekly malware update about the issues (always malware-related ) that arise throughout the week. This is the first one and you will be able to track those by following our malware_updates … Read more


Posted in blacklisted, malware, malware_updates | Tagged , , | Leave a comment

Analysis of the Gawker compromise

As most of you probably know, Gawker media’s servers were compromised, resulting in a security breach at Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin, and Fleshbot. It means that if you’ve ever had an account on any of those … Read more


Posted in gawker, hacked | Tagged , | 2 Comments

Malware update: publifacil.org – htaccess changes and PE*.php

The last few days we’ve been tracking a large number of sites infected with a very interesting piece of malware. All the sites hacked so far contain the following in their .htaccess file (PEcasas.php could be many names like PEtherm.php, … Read more


Posted in hacked, malware, malware_updates | Tagged , , | 3 Comments

WordPress 3.0.3 released (security update)

Running WordPress? Time to update it again! Version 3.0.3 has been released fixing some security vulnerabilities. If you can’t upgrade, make sure to disable remote publishing by going to the page “Settings → Writing” to see if it is disabled. … Read more


Posted in vulnerability, wordpress | Tagged , | 3 Comments

WordPress 0 day exploit (version 3.0.1 and older)

We posted last week about the release of WordPress 3.0.2 that fixes a few security vulnerabilities. Today, full details of the vulnerability and exploit code have been released. So if you haven’t upgraded yet, make sure to do so now … Read more


Posted in vulnerability, wordpress | Tagged , | 2 Comments

Alexa top sites – Blacklist for November

Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For Nov-2010, the number is pretty … Read more


Posted in alexa, blacklisted | Tagged , | 1 Comment