Blog Search
Like Box
Comments
- The WPCandy Podcast #32: "Uncle Ben's plugin list" | WPCandy on Official WordPress Plugin Directory – Forcing Plugin Updates
- Is your website clean? | Life Currents on Links Injection on WordPress – Blackhat SEO Spam (basicpills) update
- Technology News on Blog Comments – Analysing 100,000 Comments and Spammers
- user on Removing Malware from a WordPress blog – Case Study
- Brand Development on Walmart web site hacked and hosting spam
Tags
alexa apache ask awareness backdoors blacklist blacklisted bluehost data dns education fox godaddy google guides hacked history honeypot htaccess iis joomla logs malware malware_updates netsol openx oscommerce ossec passwords pharma phishing php plugin scan security spam stats sucuri twitter updates vbulletin virus vulnerability walmart wordpressArchives
- May 2012 (7)
- April 2012 (15)
- March 2012 (12)
- February 2012 (6)
- January 2012 (6)
- December 2011 (4)
- November 2011 (4)
- October 2011 (7)
- September 2011 (8)
- August 2011 (16)
- July 2011 (5)
- June 2011 (10)
- May 2011 (10)
- April 2011 (15)
- March 2011 (18)
- February 2011 (13)
- January 2011 (7)
- December 2010 (7)
- November 2010 (9)
- October 2010 (12)
- September 2010 (10)
- August 2010 (7)
- July 2010 (10)
- June 2010 (15)
- May 2010 (19)
- April 2010 (16)
- March 2010 (15)
- February 2010 (8)
- January 2010 (7)
- December 2009 (4)
- November 2009 (1)
- October 2009 (2)
- September 2009 (1)
- August 2009 (6)
- July 2009 (11)
- June 2009 (7)
- May 2009 (4)
- April 2009 (1)
Monthly Archives: May 2011
VBulleting SQL injection vulnerability – Update now
A serious SQL injection vulnerability was reported on Vbulletin (4.0.x, 4.1.0, 4.1.1 and 4.1.2) last month and we are starting to see it being used to attack and infect forums using it. The vulnerability is very simple and explained here: … Read more
Understanding .htaccess attacks – Part 1
Attackers have been using the .htaccess file for a while. They use this file to hide malware, to redirect search engines to their own sites (think blackhat SEO), and for many other purposes (hide backdoors, inject content, to modify the … Read more
Posted in htaccess, malware, malware_updates, vulnerability
Tagged hacked, htaccess, malware, malware_updates
10 Comments
WordPress 3.1.3 available (security fixes)
If you are using WordPress, make sure to upgrade it now. The version 3.1.3 was just released with a few security fixes: * Various security hardening by Alexander Concha. * Taxonomy query hardening by John Lamansky. * Prevent sniffing out … Read more
LizaMoon SQL injections (ur.php) – Now vcvsta.com, asweds.com, etc.
A couple of months ago the Lizamoon malware / Mass SQL injection was getting a lot of news coverage that it could be affecting hundreds of thousands of sites. The media mostly forgot about it, but we kept tracking those … Read more
Posted in hacked, iis, malware, malware_updates
Tagged hacked, iis, malware, malware_updates
3 Comments
osCommerce malware: Cannot redeclare corelibrarieshandler
We have been posting for a while about attacks targeting and infecting thousands of osCommerce sites (CreateCSS, div_colors, etc) and the importance of keeping it updated and secure. If you think things have been improving, just for the last few … Read more
Posted in malware, malware_updates, oscommerce
Tagged malware, malware_updates, oscommerce
2 Comments
ASK Sucuri: Why does my site keep getting reinfected?
If you have any question about malware, blacklisting, or security in general, send it to us: contact@sucuri.net and we will answer here. For all the “ask sucuri” answers, go here. Question: Why does my site keep getting hacked / reinfected? … Read more
LastPass hacked? Forcing users to change their master passwords
If you are a LastPass user, you will be forced to change your master password in order to continue using the service. We just read some worrying news that they might be hacked. Yes, “might”. It is more worrying because … Read more
WP-DBManager Security update (serious issue)
Just a quick note that if you are using the WordPress WP-DBManager plugin, make sure to update it as soon as possible. Old versions of the plugin (
Are WordPress users taking care of their security? State of Blog Security – Part I
Almost two years ago we published an article on the “state of blog security” (focused on WordPress) where we checked the percentage of blogs that were taking care of their security properly. We checked if they had WordPress updated and … Read more
TheWebbyAwards hacked and compromised with Blackhat SEO
The WebbyAwards web site ( www.webbyawards.com/ ) is currently hacked and compromised with Blackhat SEO. If you try to search for it on Google you will get a warning saying that “This site may be compromised”: And if you look … Read more