Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Month: February 2015

10 posts

Malware Cleanup to Arbitrary File Upload in Gravity Forms

  • Rodrigo Escobar
  • February 26, 2015
During our regular cleanup process we came across a reinfection case that caught our attention. This particular environment didn’t have anything special or fancy, it…
Read the Post
Why Do Websites Get Hacked
  • Security Education
  • Website Security

Why Websites Get Hacked

  • Tony Perez
  • February 26, 2015
I spend a good amount of time engaging with website owners across a broad spectrum of businesses. Interestingly enough, unless I’m talking large enterprise, there…
Read the Post
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Security Advisory – WP-Slimstat 3.9.5 and Lower

  • Marc-Alexandre Montpas
  • February 24, 2015
WP-Slimstat users should update as soon as possible! During a routine audit for our WAF, we discovered a security bug that an attacker could, by…
Read the Post
  • Security Education
  • Vulnerability Disclosure
  • Website Security

Vulnerability Disclosures – A Note To Developers

  • Daniel Cid
  • February 18, 2015
This post is entirely for developers. Feel free to read, but approach it with that in mind. There is no such thing as bug-free code.…
Read the Post

Analysis of the Fancybox-For-WordPress Vulnerability

  • Marc-Alexandre Montpas
  • February 16, 2015
We were alerted last week of a malware outbreak affecting WordPress sites using version 3.0.2 and lower of the fancybox-for-wordpress plugin. As announced, here are some of the…
Read the Post
The Dynamics of Passwords
  • Security Education
  • Website Security

The Dynamics of Passwords

  • Alycia Mitchell
  • February 13, 2015
How often do you think about the passwords you’re using? Not only for your website, but also for everything else you do on the internet…
Read the Post

Analyzing Malicious Redirects in the IP.Board CMS

  • Denis Sinegubko
  • February 10, 2015
Although the majority of our posts describe WordPress and Joomla attacks (no wonder, given their market-share), there are still attacks that target smaller CMS’s and…
Read the Post

Zero-day in the Fancybox-for-WordPress Plugin

  • Daniel Cid
  • February 4, 2015
Update: We posted an analysis of the vulnerability following this post. Our research team was alerted to a possible malware outbreak affecting many WordPress websites.…
Read the Post
  • Security Advisory
  • Vulnerability Disclosure
  • WordPress Security

Advisory – Dangerous “nonce” Leak in UpdraftPlus

  • Marc-Alexandre Montpas
  • February 3, 2015
If you’re a user of the UpdraftPlus plugin for WordPress, now is the time to update. During a routine audit of our Website Firewall (WAF),…
Read the Post

Creative Evasion Technique Against Website Firewalls

  • Lee Howarth
  • February 3, 2015
During one of our recent in-house Capture The Flag (CTF) events, I was playing with the idea of what could be done with Non-Breaking Spaces.…
Read the Post
Search
What is SQL injection and how to prevent attacks sidebar
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'