Your current browser version is too old. We recommend switching to Google Chrome for a better experience.
Email:support@eranet.com WhatsApp:+(852)68882160  +1(302)602-1509

5 Major Malware Threats Facing Web Hosting Providers

  • Release time:2012-02-20

  • Browse:3815

  • Peter Jensen, CEO of website security provider StopTheHacker predicts that about 75 percent of hosted websites are vulnerable, and 2.5 to 5 percent of hosts are infected with malware, statistics that StopTheHacker hopes to change with its website malware scanning service.

    Through the support of Parallels, the company has re-launched with a focus on reselling through web hosts, promising high margins and conversion rates, and a solution that most hosting customers do not have, but certainly need as hackers become more sophisticated at injecting malicious code on websites. It received a $1.1 million round of funding earlier this week from venture capital firm Runa Capital.


    In an email interview with the WHIR, Anirban Banerjee, co-founder and VP of R&D for StopTheHacker, explained five critical malware threats to hosting businesses, and how these threats can jeopardize your brand and customers.


    1. FTP credential compromise


    What is it? Websites injected with web-malware as a result of FTP passwords and usernames being compromised by other malware that sniffs for users connecting to websites to update pages.


    Why is it a big issue? Thousands of sites are compromised daily because keyboard logging trojans can glean login credentials and infect websites with malware code. This type of malicious access cannot be detected by web application firewalls. There is very little hosts can do to protect against this kind of an attack, since there is hardly any way to tell whether an FTP connection is being made by a user or by an automated bot. Constant web-malware scanning is the only way to detect this kind of compromise.


    2. Web application vulnerabilities


    What is it? Websites often let users interact using web 2.0 functions like blog comments, newsletter email forms and support forms. All these are vectors for attack. Attacks such as SQL injection led to the compromise of millions of sites (the famous lizamoon and lilupohilupop attacks) last year. These attacks succeed because the computer code powering and analyzing the input to these forms cannot properly handle unexpected or malicious data pumped into them. This allows a malicious hacker to inject malware into databases and html pages and own the hosting account.


    Why is it a big issue? Websites today are including more and more functionality to let users interact with the – more forms, more dynamic effects – and all these are vectors of attack. SQL injection and cross-site scripting are two time-tested, extremely popular methods to exploit web application vulnerabilities. Consider the fact that with firewalls in place, websites still are vulnerable to SQL injection and cross site scripting. Getting regular vulnerability assessments is very important to keep a website safe.


    3. Outdated CMS vulnerabilities


    What is it? Website admins and designers are using software packages such as WordPress, Joomla, Django and Typo3 to build and maintain websites quickly and with ease. Most web admins neglect to upgrade their packages when security updates are released and fall prey to automated bots that exploit the vulnerabilities in older packages.


    Why is it a big issue? Web admins take an average of 7 days to get the website cleaned up and off blacklists. In these 7 days they lose business and more importantly reputation. There are thousands of old WordPress and Joomla installations in the Internet and they get hacked regularly, proving to be a fertile ground for malicious hackers to create a armies of bots and launch spam campaigns.


    4. Insecure server configurations


    What is it? A lot of web hosting customers do not understand how to configure their VPS instances properly. They leave ports open, install vulnerable software and do not have a good grasp on how to lock down their servers.


    Why is it a big issue? Cloud computing and renting out VPS instances is the way things are progressing in the hosting world. If customers keep falling prey to hackers because they cannot maintain their VPS’s security, it will put pressure on hosters to clean malware, change configurations and manage low price point customers. Regular vulnerability assessments and a good patching schedule can help with this.


    5. Third party add-ons


    What is it? A majority of websites today are using third party add-ons to look more beautiful and provide more flexibility to visitors, such as dynamic resizing of images uploaded to a social network site. These third party add-ons bring with them another set of vulnerabilities because they may not have been tested sufficiently.


    Why is it a big issue? Over 1 million sites were hacked last year because of a vulnerability in the timthumb plugin used across millions of sites powered by WordPress and other software. This is a classic case of hackers using a different modus operandi to infect websites, going for the low hanging fruit and getting maximum bang for the buck.

    SRC: http://www.thewhir.com/web-hosting-news/5-major-malware-threats-facing-web-hosting-providers

    About Eranet
    Todaynic.com International Limited(Eranet.com) was incorporated in Hong Kong in 2005, directly under Todaynic.com, Inc. which was established in 2000. As one of the first ICANN (The Internet Corporation for Assigned Names and Numbers), Verisign, HKDNR, and CNNIC (The China Internet Network Information Center) accredited registrars, Eranet is also a leading provider of services in domain name registration and web hosting.

     

    4 domain names have the lowest price.

    .com  only USD 9.77/year
    .net  only USD 9.77/year
    .asia only USD 20.45/year
    .hk   only USD 22.63/year

    And we provide 10% off discount for hosting right now.


Search

Document