Security EducationWeb ProsWebsite Security Phishers Abuse Hosting Temporary URLsDenis SinegubkoJune 7, 2016 Recently we told you how hackers use alternative domain names provided by web hosts to make their URLs look less suspicious. This time we’ll show… Read the Post
Targeted Phishing Against GoDaddy CustomersMarc KranatDecember 11, 2014 I do get a lot of phishing emails, we all do, but as security professionals we tend to recognize them immediately. Either the syntax is… Read the Post
IIS, Compromised GoDaddy Servers, and Cyber Monday SpamDenis SinegubkoDecember 8, 2014 While doing an analysis of one black-hat SEO doorway on a hacked site, I noticed that it linked to many similar doorways on other websites,… Read the Post
Does Sucuri Work With My Host? Yes, Yes We Do.David DedeMay 6, 2014 We’ve been scanning and removing malware from websites for years and in this time frame we have seen the website security domain grow by leaps… Read the Post
Zero Day Vulnerability in OpenX Source 2.8.11 and Revive Adserver 3.0.1David DedeDecember 20, 2013 If you are using OpenX or the new Revive Adserver (fork of OpenX), you need to update it ASAP. Florian Sander discovered a serious SQL… Read the Post
Plesk Vulnerability – In the Wild for Months Before DisclosureDaniel CidJune 17, 2013 A few days ago we published a post about the Plesk 0-day vulnerability that we started to see being probed in the wild. It uses… Read the Post
Plesk 0-day Remote Vulnerability in the WildDaniel CidJune 10, 2013 Just last week another 0-day vulnerability on Plesk was released. It affects Plesk 9.2, 9.3 and 9.5.4 versions. If you have not yet, we recommend… Read the Post
Who Really Owns Your Website? “Please Stop Hotlinking My Easing Script — Use a Real CDN Instead.”Daniel CidMay 3, 2013 For the last few days, we have had some customers come to us worried thinking that their websites were compromised with some type of pop-up… Read the Post
Web Server Compromise – Debian Distro – Identify and Remove Corrupt Apache ModulesTony PerezFebruary 6, 2013 Came across another server compromise this week. Client was complaining that the following kept being injected into their JavaScript files: document.write("<style.vb4brk { position:absolute; left:-1655px; top:-1476px} </style> <div… Read the Post
Vulnerability DisclosureWeb ProsWebsite Malware Infections Compromised Websites Hosting Calls to Java ExploitDaniel CidSeptember 12, 2012 Remember that Java 0 day vulnerability that was discovered a few weeks ago and took a while to get patched by Oracle? You know, the… Read the Post
Dreamhost Clients – Possible 500 Errors During Database MigrationTony PerezJuly 18, 2012 This morning Dreamhost released an email to a number of clients notifying them that a database was being moved to a new server. If you’re… Read the Post