Online Services

Category: Security

  • Ask Sucuri: How Does Sucuri Clean a Website?

    Ask Sucuri: How Does Sucuri Clean a Website?

    Question: How does Sucuri clean hacked websites? What is the process? We clean a lot of websites, ~ 400 / 500, daily during our normal load. To understand how we do it, you have to understand where it all comes from. The biggest challenge with providing incident response services (remediation) on compromised websites is that a majority…

    The post Ask Sucuri: How Does Sucuri Clean a Website? appeared first on Sucuri Blog.

  • Massive Admedia/Adverting iFrame Infection

    Massive Admedia/Adverting iFrame Infection

    This past weekend we registered a spike in WordPress infections where hackers injected encrypted code at the end of all legitimate .js files. The distinguishing features of this malware are: 32 hex digit comments at the beginning and end of the malicious code. E.g. /*e8def60c62ec31519121bfdb43fa078f*/ This comment is unique on every infected site. Most likely an MD5…

    The post Massive Admedia/Adverting iFrame Infection appeared first on Sucuri Blog.

  • Website Hacked Trend Report – 2016/Q1

    Website Hacked Trend Report – 2016/Q1

    Our Remediation group is comprised of two distinct teams, the Incident Response Team (IRT) and Malware Research Team (MRT). These teams work closely with our customers in an effort to identify and remove website infections to include malware, SEO spam and a number of other malicious actions attackers take once successfully penetrating a websites defenses….

    The post Website Hacked Trend Report – 2016/Q1 appeared first on Sucuri Blog.

  • XSS Vulnerability in Wordfence 6.1.1 to 6.1.6. Severity: 6.1 (Medium)

    An hour ago a security researcher, Kacper Szurek, reported a reflected XSS vulnerability in the current version of Wordfence. Wordfence is now using CVSS as our standard vulnerability scoring mechanism. The severity of this vulnerability is 6.1 (Medium).

    Impact

    This only affects Wordfence users who have the Wordfence firewall disabled. Wordfence has built in protection against XSS vulnerabilities and has had since version 6.1.1, so if your firewall is enabled you are not affected. If you have the firewall in learning mode or disabled, you are not protected against this vulnerability.

    What to do

    We have already released a fix. If you have Wordfence set to auto-update then it will automatically update to Wordfence 6.1.7 within the next 24 hours and you don’t have to take any action. If you have the Wordfence firewall enabled, you are already protected and were never affected by this issue.

    If you have Wordfence auto-update disabled and you have the firewall in learning mode or disabled, we recommend you sign into your website and manually upgrade Wordfence to version 6.1.7 now. We also suggest that you consider enabling your Wordfence firewall if that is feasible for you.

    Vulnerability Info

    CVSS Severity: 6.1

    CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

    Vulnerability Type: Reflected XSS (Cross Site Scripting)

    Kacper has shared a proof of concept for this vulnerability with us which we have verified. We will not be sharing it at this time but may share it at a future date.

    Further notes on vulnerability disclosure by Wordfence

    At Wordfence we practice responsible disclosure both on products belonging to other vendors and on our own product. Even though this is our own product, you will see a style of disclosure here that uses the same standards that we use when we disclose vulnerabilities relating to other vendor’s products.

    Wordfence has now standardized on using the CVSS 3.0 vulnerability scoring system which we have included in this post. Going forward we will include the CVSS score of every vulnerability in the subject of our blog posts and in an email alert we send to our community. This gives our community an immediate indication at a glance of the severity of a vulnerability. It also provides an objective methodology of scoring vulnerabilities that is not subject to opinion or bias.

     

    The post XSS Vulnerability in Wordfence 6.1.1 to 6.1.6. Severity: 6.1 (Medium) appeared first on Wordfence.