SlideShare une entreprise Scribd logo
1  sur  4
Website Attacks and Hacks

Imagine the following scenario:
You’ve just had a brand new website built for your business, and before you know it you are getting a
warning from Google that your website has been hacked.

It would, undoubtedly, evoke anger towards the pests that are hacking your site, and resentment
towards the guys who built your site and, in your mind, didn’t put the measures in place to avoid this
from happening!

We have, on numerous occasions, come across “Virus Attacks” or “Hacks” as they are sometimes called.
They commonly occur in Open Source Websites & are one of the few risks that come with using Open
Source platforms.

While your IT Team should be able to fix this predicament in almost all cases they have very little to do
with the originating problem (i.e. equipping the site against these types of attacks). In general, a Google
warning is the first notification of such a problem to them, as well as to you.

What is at Risk?
The most common reason for a website hack in the case of a small to medium scale website is link-
farming for SEO gains. Moreover, Hackers go after E-commerce sites for customer & possibly credit card
data. Email addresses of customers are also up there in the list of things hackers are after.

How it Works?
There are two common ways that hacks occur. Of course, there are many other types of hacks as well
but these two are the most common in small to medium sized websites:



1) SQL Injection
In this way, the hacker is very familiar with the database schema (or data model) of the site and creates
a script that enters malicious code directly into the database table that carries the page content.
SQL Injection can occur in most open source platforms because open source systems database schemas
are common public knowledge.

In Hosted platforms the risk of SQL injections is close to negligible as the databases are well protected &
use connection methods / models known only to the company that runs the platform

Cleaning a SQL injection means searching the database and removing the code, which at times can cause
service disruptions, layouts or breaks in website functionality?

2) File System Infection
In this way a hacker enters via an FTP or other channel for server vulnerability and actually modifies the
source code files in order to place malicious code into the system

This type of hack is very tough to fix because the scripting can be intelligent, spread quickly and continue
to replicate even after clean-ups. Sometimes hackers will plant “receptor” scripts that go undetected
and look very normal until they connect to the hackers’ own servers and pull down malicious code.

  Cleaning this hack means effectively looking at each file individually and systematically cleaning up the
code. Your IT team can undertake a mass “Find & Replace” approach to clean the code if they are able
to locate the malicious code, but shortcuts almost always mean that they will miss out the “receptor”
script that is infecting the files. This effort is extensive and can involve various elements:

Your base WordPress install version 3.0.1 has 756 Files! Version 3.4 has 1400+ files!

Your Joomla 2.5 install has 6000+ files with a standard set of components & plugins!

Sometimes clean up can also affect the functionality of the site or layouts, which result in a lot of lost
productivity to the site




How do we fix it?
While your IT team doesn’t bear the responsibility for the hacking, which is, in many cases, hard to
predict and potentially unavoidable, there are certain measures that can be taken to prevent it from
happening (please see details in the next paragraph). For starters, the password selection for the Admin
panel or FTP must be as hard to detect as possible. Once the hacking has taken place you will have to
work with a very skilled System Administrator and a Programmer (both skills are a must) to clean the
infected website and reestablish functionality.

Once this action has been completed, the site must be re-submitted to Google as there are high chances
that Google still has it detected as an “infected” site.

How do we prevent hacking from happening in the first place?
There are many things that can be done at the website production stage to prevent- or at least reduce –
the risks.

       Your IT team can use a non-standard data model in with a regular CMS module – This can be a
       fairly expensive solution and will need a talented developer to execute. The cost, however, may
       be prohibitive.
       Upgrade to the latest version of your platform. This may also be a costly affair depending on
       how much customization has been done to your website. Most platform providers will release
       security updates frequently because they are familiar with the common threats against their
       platform
       Use secure passwords and change them frequently. Use combinations of upper case, lower case,
       numbers and special characters, and make your passwords at least 8-10 characters long. NOTE:
       numbers-only passwords are the easiest to hack
       Try not to send out passwords by email, send user names and use SMS / texting to send the
       passwords
       Invest in a dedicated server



        o   Shared servers are very risky, mostly because you don’t know who your neighbors are and
            you are sharing everything with them. Potentially you could be on the same file system as a
            highly infected site and the virus will spread very easily to your site. In such cases your IT
            Team cleaning up the virus is completely wasting their time as they can’t clean the rest of
            the server, and it’s only a matter of time before the infection comes back
        o   On Dedicated servers your IT Team will have access to the root file system and base
            modules so they can install a lot of tools & scripts to “harden” the server and secure it. This
            is not possible on shared servers
        o   Dedicated servers are more expensive to own & maintain
        o   Highly recommended: PaaS (Platform as a Service) hosting is the next generation of web
            hosting, which is highly secure
        o   You can consider the use of Reverse proxies & other advanced security tools, a few of these
            are now available on a service basis (SaaS)



Conclusion
We recommend Dedicated Servers to our customers along with a proper security and support package
to help prevent such problems. It is very difficult for any IT team to guarantee that hacking won’t
happen, but we can certainly warn of contributing factors such as shared servers / weak passwords /
outdated software, etc. and make recommendations for the best ways to prevent hacking from
happening. http://clicktecs.com/
Website Attacks and Hacks

Contenu connexe

En vedette

Ngss implementation plan state of delaware
Ngss implementation plan state of delawareNgss implementation plan state of delaware
Ngss implementation plan state of delawareC.R. McLeod
 
MyRingCard #bigliettodavisitaelettronico
MyRingCard #bigliettodavisitaelettronicoMyRingCard #bigliettodavisitaelettronico
MyRingCard #bigliettodavisitaelettronicoFrancesco Pieragostini
 
Cibes lift's presentation at BIMobject LIVe 2014
Cibes lift's presentation at BIMobject LIVe 2014Cibes lift's presentation at BIMobject LIVe 2014
Cibes lift's presentation at BIMobject LIVe 2014BIMobject
 
Intervento renza luigi_contratto
Intervento renza luigi_contrattoIntervento renza luigi_contratto
Intervento renza luigi_contrattoRenza Cambini
 
February 2015 UK Commercial Bulletin
February 2015 UK Commercial BulletinFebruary 2015 UK Commercial Bulletin
February 2015 UK Commercial BulletinHML Ltd
 
Law of non resistance all stories
Law of non resistance all storiesLaw of non resistance all stories
Law of non resistance all storiesNeel Bajpai
 
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...Parsons Behle & Latimer
 
Bluekens Presentatie Nw Opzet2012
Bluekens Presentatie Nw Opzet2012Bluekens Presentatie Nw Opzet2012
Bluekens Presentatie Nw Opzet2012Bluekens01
 

En vedette (10)

2470620 data-warehouse
2470620 data-warehouse2470620 data-warehouse
2470620 data-warehouse
 
Ngss implementation plan state of delaware
Ngss implementation plan state of delawareNgss implementation plan state of delaware
Ngss implementation plan state of delaware
 
MyRingCard #bigliettodavisitaelettronico
MyRingCard #bigliettodavisitaelettronicoMyRingCard #bigliettodavisitaelettronico
MyRingCard #bigliettodavisitaelettronico
 
Cibes lift's presentation at BIMobject LIVe 2014
Cibes lift's presentation at BIMobject LIVe 2014Cibes lift's presentation at BIMobject LIVe 2014
Cibes lift's presentation at BIMobject LIVe 2014
 
Intervento renza luigi_contratto
Intervento renza luigi_contrattoIntervento renza luigi_contratto
Intervento renza luigi_contratto
 
February 2015 UK Commercial Bulletin
February 2015 UK Commercial BulletinFebruary 2015 UK Commercial Bulletin
February 2015 UK Commercial Bulletin
 
Law of non resistance all stories
Law of non resistance all storiesLaw of non resistance all stories
Law of non resistance all stories
 
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...
Investigating_Prosecuting_and_Defending_Environmental_Crimes_What_You_Need_to...
 
Harmony Ambassador Tour 2012
Harmony Ambassador Tour 2012Harmony Ambassador Tour 2012
Harmony Ambassador Tour 2012
 
Bluekens Presentatie Nw Opzet2012
Bluekens Presentatie Nw Opzet2012Bluekens Presentatie Nw Opzet2012
Bluekens Presentatie Nw Opzet2012
 

Dernier

Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...AliaaTarek5
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityIES VE
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Mark Goldstein
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 

Dernier (20)

Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a reality
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 

Website Attacks and Hacks

  • 1. Website Attacks and Hacks Imagine the following scenario: You’ve just had a brand new website built for your business, and before you know it you are getting a warning from Google that your website has been hacked. It would, undoubtedly, evoke anger towards the pests that are hacking your site, and resentment towards the guys who built your site and, in your mind, didn’t put the measures in place to avoid this from happening! We have, on numerous occasions, come across “Virus Attacks” or “Hacks” as they are sometimes called. They commonly occur in Open Source Websites & are one of the few risks that come with using Open Source platforms. While your IT Team should be able to fix this predicament in almost all cases they have very little to do with the originating problem (i.e. equipping the site against these types of attacks). In general, a Google warning is the first notification of such a problem to them, as well as to you. What is at Risk? The most common reason for a website hack in the case of a small to medium scale website is link- farming for SEO gains. Moreover, Hackers go after E-commerce sites for customer & possibly credit card data. Email addresses of customers are also up there in the list of things hackers are after. How it Works? There are two common ways that hacks occur. Of course, there are many other types of hacks as well but these two are the most common in small to medium sized websites: 1) SQL Injection In this way, the hacker is very familiar with the database schema (or data model) of the site and creates a script that enters malicious code directly into the database table that carries the page content.
  • 2. SQL Injection can occur in most open source platforms because open source systems database schemas are common public knowledge. In Hosted platforms the risk of SQL injections is close to negligible as the databases are well protected & use connection methods / models known only to the company that runs the platform Cleaning a SQL injection means searching the database and removing the code, which at times can cause service disruptions, layouts or breaks in website functionality? 2) File System Infection In this way a hacker enters via an FTP or other channel for server vulnerability and actually modifies the source code files in order to place malicious code into the system This type of hack is very tough to fix because the scripting can be intelligent, spread quickly and continue to replicate even after clean-ups. Sometimes hackers will plant “receptor” scripts that go undetected and look very normal until they connect to the hackers’ own servers and pull down malicious code. Cleaning this hack means effectively looking at each file individually and systematically cleaning up the code. Your IT team can undertake a mass “Find & Replace” approach to clean the code if they are able to locate the malicious code, but shortcuts almost always mean that they will miss out the “receptor” script that is infecting the files. This effort is extensive and can involve various elements: Your base WordPress install version 3.0.1 has 756 Files! Version 3.4 has 1400+ files! Your Joomla 2.5 install has 6000+ files with a standard set of components & plugins! Sometimes clean up can also affect the functionality of the site or layouts, which result in a lot of lost productivity to the site How do we fix it? While your IT team doesn’t bear the responsibility for the hacking, which is, in many cases, hard to predict and potentially unavoidable, there are certain measures that can be taken to prevent it from happening (please see details in the next paragraph). For starters, the password selection for the Admin panel or FTP must be as hard to detect as possible. Once the hacking has taken place you will have to work with a very skilled System Administrator and a Programmer (both skills are a must) to clean the infected website and reestablish functionality. Once this action has been completed, the site must be re-submitted to Google as there are high chances that Google still has it detected as an “infected” site. How do we prevent hacking from happening in the first place?
  • 3. There are many things that can be done at the website production stage to prevent- or at least reduce – the risks. Your IT team can use a non-standard data model in with a regular CMS module – This can be a fairly expensive solution and will need a talented developer to execute. The cost, however, may be prohibitive. Upgrade to the latest version of your platform. This may also be a costly affair depending on how much customization has been done to your website. Most platform providers will release security updates frequently because they are familiar with the common threats against their platform Use secure passwords and change them frequently. Use combinations of upper case, lower case, numbers and special characters, and make your passwords at least 8-10 characters long. NOTE: numbers-only passwords are the easiest to hack Try not to send out passwords by email, send user names and use SMS / texting to send the passwords Invest in a dedicated server o Shared servers are very risky, mostly because you don’t know who your neighbors are and you are sharing everything with them. Potentially you could be on the same file system as a highly infected site and the virus will spread very easily to your site. In such cases your IT Team cleaning up the virus is completely wasting their time as they can’t clean the rest of the server, and it’s only a matter of time before the infection comes back o On Dedicated servers your IT Team will have access to the root file system and base modules so they can install a lot of tools & scripts to “harden” the server and secure it. This is not possible on shared servers o Dedicated servers are more expensive to own & maintain o Highly recommended: PaaS (Platform as a Service) hosting is the next generation of web hosting, which is highly secure o You can consider the use of Reverse proxies & other advanced security tools, a few of these are now available on a service basis (SaaS) Conclusion We recommend Dedicated Servers to our customers along with a proper security and support package to help prevent such problems. It is very difficult for any IT team to guarantee that hacking won’t happen, but we can certainly warn of contributing factors such as shared servers / weak passwords / outdated software, etc. and make recommendations for the best ways to prevent hacking from happening. http://clicktecs.com/