Tag Archives: compromised websites

Webmasters Struggle With Hacked Sites – A Commtouch, StopBadware Report

imageI’m often asked why I host this Blog on WordPress.com – why I don’t self host, and maybe make a few dollars, while I’m at it, by running ads. So, I’ll start with the back-end first.

It’s not about money – far from it. I write this Blog to have a little bit of fun; to help keep my mind sharp (often a failing exercise  Smile  ) – and, to be part of a community which recognizes the need to educate computer users that the Internet is not all sweetness and light.

That’s the back-end – but, it’s the front-end that’s most important. WordPress does all the heavy lifting. All elements are taken care of: setup, upgrades, spam, backups, and site security. Site security might be last in the previous sentence but, it was the most important factor in my decision to use WordPress as my blogging platform.

Just a few of the security reasons:

Potential harmful activity is constantly monitored.

Blog PHP code can’t be modified.

Plugins can’t be uploaded.

JavaScript embed codes and CSS, are restricted.

I’m not suggesting that WordPress can’t, or won’t be hacked (nothing on the Internet is invulnerable to cyber criminals) – but, should sites hosted by WordPress.com fall to  the bad guys, those of us who rely on WP, will at least have a fighting chance to recover. This is not always the case for self-hosted sites.

Recent statistics indicate (surprise, surprise) – cybercriminals are increasing their targeting of websites for identity theft, virus distribution, and spamming. And, according to a newly released survey (Compromised Websites: An Owner’s Perspective), from Commtouch and StopBadware – in which webmasters were queried on their fight against hacking – almost half of the survey participants (who had been hacked), had no idea until they received a warning from their own computer’s protection technology.

More particularly, according to the Commtouch/StopBadware report – “about half of site owners discovered the hack when they attempted to visit their own site and received a browser or search engine warning.”  Not a very effective method of discovering one’s site has been hacked. As opposed to WP’s – “Potential harmful activity is constantly monitored.”

Highlights from analysis of the survey’s responses include:

Over 90% of respondents didn’t notice any strange activity, despite the fact that their sites were being abused to send spam, host phishing pages, or distribute malware.

Nearly two-thirds of the webmasters surveyed didn’t know how the compromise had happened.

Twenty six percent of site owners had not yet figured out how to resolve the problem at the time they completed the survey.

Forty percent of survey respondents changed their opinion of their web hosting provider following a compromise.

The report includes several examples of hacked websites, as well as the spam emails that may trick users into visiting these sites. In addition to analysis and quotes from site owners, the report provides tips to help webmasters prevent their sites from being compromised.

The following graphic illustrates why cyber criminals target web sites.

image

Courtesy – Commtouch

The full report is available for download (PDF format) at:

Commtouch

StopBadware

10 Comments

Filed under Blogging Tips, Cyber Crime, Malware Reports, Reports, Web Hosting

BitDefender TrafficLight – Real-time Anti-virus, Anti-phishing Browser Add-on

imageSurfing the Internet without a site reputation Browser add-on is not much different than stumbling down a set of stairs in the dark – while blindfolded. At a minimum, a risky venture.

As with all applications designed to enhance Internet safety however, site reputation Browser add-ons are not without there shortcomings. One particular issue that raises concern is – reputation add-ons are site specific and not page specific. In other words, the site may have passed the test for safety and yet contain a page, or pages, that harbor threats.

BitDefender’s recently released (March 24, 2011), beta – TrafficLight Browser add-on, attempts to address this page specific issue by utilizing “the BitDefender scanning engines to check, and rate, every page and link from the users’ web traffic, blocking unsafe content before it reaches the user’s browser.” In an effort to cover all the bases, TrafficLight is active in in search engines, and social networking sites (Facebook and Twitter), as well.

Control Panel screen capture.

image

Fast facts:

TrafficLight works with virtually any Windows-compatible browser. It even keeps look, feel and functionality consistent if you switch browsers.

TrafficLight intercepts and scans web traffic before it even reaches the browser, effectively blocking disguised or stealth attacks before it’s too late.

TrafficLight scans the pages you visit for malware and phishing attempts each and every time you access them to avoid the threat of legitimate but recently compromised websites.

TrafficLight won’t block an entire website if just some pages within are malicious. Only the potentially harmful elements are blocked, leaving you free to view the rest of the site if you so choose.

TrafficLight relies on intelligence provided by BitDefender Cloud services to flag malware and phishing attempts in search results from Google or Bing. Not only that, but it also checks links in popular social network platforms and blocks them if they are suspect.

TrafficLight does not add a toolbar to your already-cluttered browser interface. Its interface remains invisible until your input is needed or it’s called up with a simple mouse gesture.

Supported Operating systems: Microsoft Windows XP SP2, Windows Vista SP2, Windows 7.

Supported Browsers:
Internet Explorer 7+, Opera, Mozilla Firefox, Google Chrome, Safari.

image

Download free TrafficLight at: BitDefender

Note: As with all beta, or release candidates, take sensible precautions prior to installation. This should include setting a new restore point.

Additional reading:

WOT Beta for Social Media – Facebook, Twitter Protection And More

Free BufferZone Pro – Maybe The Best Surfing Virtualization Application At Any Price

If you found this article useful, why not subscribe to this Blog via RSS, or email? It’s easy; just click on this link and you’ll never miss another Tech Thoughts article.

12 Comments

Filed under Anti-Malware Tools, BitDefender, Browser add-ons, Browsers, Cyber Crime, Don't Get Hacked, downloads, FaceBook, Free Internet Protection, Freeware, Internet Safety Tools, Malware Protection, Online Safety, Safe Surfing, Software, Spyware - Adware Protection, System Security, Twitter, Windows Tips and Tools