Online Services

Category: Security

  • An Interview with a Wordfence Senior Security Analyst

    An Interview with a Wordfence Senior Security Analyst

    Colette Chamberland is one of our two Senior Security Analysts who mentor and guide the rest of our team of analysts. She works closely with our site cleaning team to maintain our forensic investigation processes that ensure we deliver excellent and timely service to our customers while ensuring their data and credentials stay secure and their site is recovered and back in production as quickly as possible.

    Colette is a Certified Ethical Hacker (CEH) and a Computer Hacking Forensic Investigator (CHFI). She brings many years of experience in forensic work and site remediation to the team and has worked for several notable companies and organizations prior to Wordfence including NASA.

    The Wordfence Forensic Team produce much of the data that we use to improve our detection capability in Wordfence and our firewall rules. We rely on them to not only get our customer websites back up and running as fast as possible after an incident, but to produce research on an ongoing basis that informs our products and helps improve security for the whole WordPress community via the Wordfence Threat Defense Feed.

    resizeccTell us about your background, how did you become a WordPress security expert?

    I started off developing nTier client/server applications and websites in the mid 90s and security was always more of a hobby for me.  It wasn’t until after the early 2000s that people started getting concerned with the concept of computer and cyber security. This shift gave me a chance to turn something that I loved doing into a career. I’m the type of person though that doesn’t like the label “expert” – I feel there is always something more to learn and know. No one can ever truly be an expert in WordPress security. I know enough to know that I don’t know everything, and probably never will. There are always new ways to attack and defend and you have to continually be in learning mode.

    Describe the emotional state of a typical site owner who has been hacked.

    As you would expect, most site owners are frightened, scared and sometimes a bit panicky when they find out their site has been compromised and infected. They don’t think that attackers target their business or site because it’s so small.  What they don’t know is that attackers don’t just go after the big guys like Target, Home Depot and big banks – they often use the little guys as an intermediary to carry out a large scale attack. No one is safe, everyone is a target.

    What makes cleaning up a hacked website difficult? Why do people turn to experts for help?

    In order to be able to identify what’s bad in a site, you have to understand the technology it’s built with and what attackers commonly use to hide their malicious activity. This often involves reading code, reverse engineering obfuscated payloads, reviewing log files and sometimes even reenacting the attack using the same vector as the attacker. This is far beyond the capabilities of most website owners. They usually hire a developer and designer to create their site and once that is done, they no longer have a relationship them and no one on staff with the technical expertise required.

    What makes your job rewarding?

    Knowing that my knowledge can help someone get out of a tough spot and keep their business going.

    With all of the advances in website security, why are hacks still happening?

    I think the biggest misconception that people have about security is that once something is “secure” it’s no longer hackable. Nothing could be further from the truth. There is no guarantee in security. Security is about mitigating your risk and improving your security posture. It’s not a matter of “if” I will be hacked, it’s a matter of “when”.

    To determine what to protect, you have to decide if the cost to recover is more than the cost to secure it in the first place.  I think that’s why Wordfence makes so much sense for business owners. The cost of a compromised site far exceeds the cost of Wordfence Premium.

    Attacks still happen because new methods are uncovered almost every day. Once you stop one type of attack, another surfaces. The only way to completely secure your site is to take it offline – but then what good does that do you?

    What trends are you seeing with infected websites lately?

    The biggest trend lately has been ransomware. Attackers inject code into unsuspecting sites that redirect users to malicious sites with payloads that are then downloaded based on what they have running on their system that is outdated. Then their system gets encrypted and requires them to pay a ransom to the attackers to get their data back. This really underlines the importance of good backups.

    What advice would you give to site owners who want to improve security?

    I think it’s been said many times but bears repeating: Make sure you have a good host, put preventative measures in place, like Wordfence and make sure you keep your site, plugins, themes, etc. up to date. Also, don’t forget the back-end that you rarely see and forget about entirely – your hosting account and your FTP/SSH credentials. All of these passwords should be changed on a regular basis, just like your underwear. Another “biggest issue” I see with most site owners is log retention & review. Many never look at their logs; they rely on things like Google Analytics because they are only concerned about their traffic, but they should also be reviewing their logs regularly for signs of potential issues, malicious activity and threats.

    Conclusion

    We’d like to thank Colette for taking the time out of her busy schedule to participate in this interview. If you would like apply to join the Wordfence team, visit our careers page –  we’d love to hear from you. If you would like to learn more about WordPress or web security and how to spot vulnerabilities or perform your own forensic investigations into website intrusions, visit our Learning Center where you can find knowledge that we’ve shared about website security and secure application development.

    If you have been hacked, visit this page to learn about how our team can help clean your site and get you back up and running.

    The post An Interview with a Wordfence Senior Security Analyst appeared first on Wordfence.

  • A Big Week for Security: Upgrade Jetpack to 4.0.4, Upgrade WordPress Core to 4.5.3.

    It’s been a busy week for WordPress security. Jetpack has released a major security update with version 4.0.4 this week that fixes three vulnerabilities:

    • a vulnerability that allowed an attacker to perform unauthorized changes to the “post by email” settings
    • a cross site scripting (XSS) vulnerability in the Jetpack ‘Likes’ module
    • a vulnerability that made submitted feedback publicly available via the REST API

    These are all reasonably serious vulnerabilities. If you have not already upgraded to Jetpack version 4.0.4, we recommend you do so now.

    In addition, WordPress core version 4.5.3 was released this week and is a security update that fixes the following:

    • a vulnerability that we discovered that allows any attacker to bypass password protected posts and read those posts
    • a redirect bypass vulnerability in the customizer
    • two different XSS vulnerabilities via attachment names
    • an oEmbed denial of service attack vulnerability
    • a vulnerability that allows unauthorized category removal from a post
    • a vulnerability that allows an attacker to change passwords via a stolen cookie
    • a security improvement to the sanitize_file_name() function

    WordPress 4.5.3 also includes 17 bug fixes. We recommend you upgrade as soon as possible because this release contains a large number of security improvements.

    The post A Big Week for Security: Upgrade Jetpack to 4.0.4, Upgrade WordPress Core to 4.5.3. appeared first on Wordfence.

  • 8 Reasons Why You Should Choose Wordfence to Clean Your Hacked Site

    At Wordfence we know you have a choice between site cleaning vendors. We feel strongly that you should choose ours because it has very tangible benefits over any other site cleaning service available. So to save you some time, I’d like to describe a few compelling reasons why you should choose Wordfence to clean your hacked site.

    1. We don’t set you up for recurring billing.

    At Wordfence we understand that our business model should not affect how much you pay for site cleaning. Your site is hacked and you need it fixed. You don’t want to be signed up for a monthly or yearly recurring subscription of some sort.

    Our pricing works the way you’d expect an incident response and forensic service to work: A single site cleaning costs $179 and that’s it. Your card will not be repeat billed. It’s intuitive, straightforward and completely transparent. We even include a Premium Wordfence license with every site cleaning that is completely free. This gives WordPress site owners the best firewall and malware detection in the business and it’s included at absolutely no cost to you.

    2. Our prices are the most competitive in the industry.

    At $179 for a site cleaning, our site cleaning service is extremely cost effective. We’re able to maintain the excellent hands-on service and quality we provide because we get tremendous value from the forensic intrusion data we gather during each site cleaning.  When we clean your hacked site, we discover how an attacker gained access and we share that information with you. We also analyze the footprints they left behind and we provide that information to you too. Then we feed that data into our software products like the Wordfence plugin and it improves our protection and detection capability. This helps improve our product and it helps make the larger online community safer.

    Because our larger customer base benefits from the data we get from each site cleaning, we’re able to keep our pricing super competitive while giving you the best incident response and customer service experience in the business.

    3. Our team is highly trained and certified

    Our two senior analysts are Colette Chamberland and Brad Haas. They both hold multiple forensic and security certifications including CEH, CHFI, CISSP, GCFA, and GCIH  certifications. Colette has previously worked for NASA at their Langley Research Center. Brad joins us from US STRATCOM (Strategic Command) and he brings a wealth of security and incident response experience both from his military and intelligence background and his experience in incident response.

    Our team is guided and mentored by Brad and Colette. We provide excellent training and mentorship and the best tools for them in the business.

    4. We have turned site cleaning into a software problem

    At our core, Wordfence is a software engineering organization. Rather than treat each hacked site as a new and isolated problem, we have spent a lot of time thinking about how new customers can benefit from what we already know about hacked websites. We know that each hacked site does present some new challenges and requires the intelligence of an analyst to bring it back into production. But we also know that many hacked sites have a lot in common and that we can use this common data to more efficiently and effectively clean and repair a hacked site.

    We have developed an internal tool we call ‘Omega’ which our analysts use to very quickly analyze and repair a hacked site. Omega uses data from our Threat Defense Feed and from the wealth of knowledge and experience our site cleaning team has gained through cleaning thousands of hacked sites. It also provides a standardized way to approach a hacked site, analyze the intrusion and remediate the hack.

    We treat Omega as an internal software product and it is constantly evolving, improving and getting smarter as the attacks we see evolve and as our engineers come up with new ways to make Omega more effective at assisting our analysts in their forensic work.

    5. Our Process is safe, secure, thorough and very effective

    Our senior analysts and technical leads have created a site cleaning process that ensures that:

    • Your data remains secure. Our clients’ sites frequently include their own customer personally identifiable information (PII). We understand the importance of that data remaining secure and our process ensures that your site data and customer PII remains secure at all times.
    • Our process is safe. We start by ensuring that a full backup is taken of your site and this backup is stored securely and used to perform the site remediation on a separate secure virtual machine that is created just for you. At no time is a site cleaning done on a customer’s live production website. This drastically reduces risk and allows our analysts to be more effective at finding and repairing the infection.
    • We are very effective. Using Omega, our internal forensic tool, along with the extensive training that our team receives and the best tools and techniques in the business, we are extremely effective at finding and completely removing an infection.

    6. Our team and systems get smarter with every site cleaning

    The Threat Defense Feed is a major part of all Wordfence products and services and this feed is the result of our forensic investigation efforts. Internally we have a process that takes all of the attack data we receive from compromised websites and we translate that data into patterns we can use to improve our detection capability. We also turn some of the data into firewall rules that we can use to improve Wordfence’s protection capability.

    Our Threat Defense Feed data also powers our forensic investigation tools. That means that with every site we clean, our detection, protection and repair capability continues to improve. The result is that you benefit from a site cleaning service that has the intelligence gained from thousands of forensic investigations built into it.

    7. We offer a complete service.

    A site cleaning and forensic investigation is far more than simply bringing a hacked site back to life. At Wordfence site cleaning we offer a complete service:

    • We start by capturing a backup of your site to ensure that your data stays secure, we have a snapshot in time to aid our forensic analysis and in case the damage to your site is ongoing.
    • Your site is throughly cleaned by our team.
    • Our team investigates how an attacker gained entry and how the site was compromised.
    • We remove any malware, malicious links or content in your posts, pages, database or source code.
    • We include a detailed report and this report includes the above information – how the site was compromised and what malicious code or content we found.
    • We provide a detailed checklist to help prevent your site from being compromised in future.
    • We include a Wordfence Premium license key to help protect your site in future at no additional cost to you.

    8. Excellent customer service

    We understand that repairing a hacked site is very high priority. You need your site back in production fast to minimize the damage it does to your search engine ranking and your brand. We also understand that clear communication is very important when dealing with a crisis.

    Once you contact our team and we start the site cleaning process, we carefully monitor how your site cleaning is progressing and ensure that it moves forward as quickly as possible and you continue to receive clear communication and updates from us.

    Our entire site cleaning team is based in the United States. Hiring forensic analysts locally means we have a close relationship with each analyst and they are able to effectively communicate with our customers in the major English speaking markets that we serve.

    Quotes from our customers:

    “To the Wordfence team. Thanks for all of your help on my sites.  I have been really impressed with your business model and execution of services.  It feels like I have my own security team.”

    ~Ben

    “One of my websites got hacked… Thanks for cleaning it up Wordfence Cleaning Team. Great job!”

    ~Alexander

    “It’s taken some time to get a handle on it, but thanks to the team over at Wordfence Security, things are now looking in the clear and Google has once again given Business Cat the clean bill of health.”

    ~Tom

    Thank you Kathy. I am happy that this work was done so fast.”

    ~Tomas

    Many thanks for not only sorting the issues on my website but for your comprehensive reply.”

    ~Stuart

    “Thanks so much for your work on this. It means I could focus on getting my actual paid work out the door instead of messing about with this.”

    ~Chris

    Get your site cleaning started

    If you have a site that has been hacked, visit this page to start the site cleaning process now and our team will get right on it. Our checkout process gives you the ability to securely send us your site credentials and once checkout is complete, our team will respond quickly and will get your site back into production and provide you with the tools to prevent a future compromise. We’re looking forward to hearing from you.

    Community Site Cleaning Resources

    We understand that some members of our community may not be able to engage the services of a paid site cleaning service. We have provided our community with tools to help empower them to clean sites themselves. If you would like to clean your own site, you will find the links below very helpful. We also encourage you to read the additional content in our Learning Center which will help you gain a more complete understanding of website security. Here are a few resources for website owners who want to clean their own hacked site:

    The post 8 Reasons Why You Should Choose Wordfence to Clean Your Hacked Site appeared first on Wordfence.

  • Vulnerability in WordPress Core: Bypass any password protected post. CVSS Score: 7.5 (High)

    The WordPress Core team have just released WordPress version 4.5.3 which is a maintenance and security release. The release went out less than 2 hours ago.

    WordPress allows you to create posts that are protected by a password and only users with that password can then gain access to the post.

    On May 3rd we disclosed a vulnerability in WordPress Core to the Core team that allowed any user with an unprivileged account to bypass the password protection WordPress provides. Anonymous attackers are able to exploit this vulnerability and gain access to password protected posts on websites where registration is open.

    The CVSS score of this vulnerability is 7.5 (High) for websites with open registration, because no privileges are required in that case to exploit the vulnerability. On websites with closed registration the CVSS score is 6.5 (Medium) because low privileges are required to exploit the vulnerability.

    The WordPress team responded on May 6th and acknowledged the vulnerability.

    On May 31st they asked for an extension.

    Today, June 21st they released a fix for this vulnerability which is included in WordPress core version 4.5.3 which is a maintenance and security release.

    Note that if you run Wordfence Premium, you have been protected against this attack since May 3rd which is when we disclosed this to the WordPress core team. We included a rule in the Wordfence Firewall that was obfuscated which prevented it from being reverse engineered the moment we disclosed it to the vendor.

    At the time of this writing the official announcement credits “Dan Moen” who is our chief marketing officer and who sent the email to the WP Core team. It is in fact the Wordfence Research Team who found this vulnerability. Credit specifically goes to Pan Vagenas who discovered the attack and to Ryan Britton, Matt Barry and Matt Rusnak for validating the vulnerability and developing and testing the firewall rule that we have been using to protect our customers from this attack. Nice work guys! We’ve reached out to the WordPress Core team to correct the omission.

    We will not be releasing a proof of concept at this time, but we may release one in future to help other firewall vendors add protection to their products which will help the broader community stay safe.

    Full timeline:

    • May 3rd: We released a firewall rule to our Premium customers that protected against this vulnerability being exploited.
    • May 3rd: On the same day we disclosed the vulnerability to the WordPress core team.
    • May 6th: The WP core team acknowledged the vulnerability.
    • May 31st: The WP core team asked for an extension which we granted.
    • June 3rd: The free community edition of Wordfence received protection against the exploit.
    • June 21st: WordPress 4.5.3 was released which includes a fix for this vulnerability.

    The post Vulnerability in WordPress Core: Bypass any password protected post. CVSS Score: 7.5 (High) appeared first on Wordfence.