Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/plugins/related-posts-thumbnails/related-posts-thumbnails.php on line 846
 

Website Hacking - A real risk for SMB's - InstaHost Solutions

25th January 2016by Insta Team
InstaHost – Secure UK Based Hosting

In 2015 website hacking attacks were far too common and you never had to look too far to find a headline on a cyber-attack and they even in 2016 they keep getting more serious and deadlier by the GB of data. There were several high profile hacks and cyber-attacks last year ranging from telcos to governments to consumer goods. However SME’s are also suffering – howver SME / SMB’s are failing to learn the lessons until their own site is hacked and it’s too late for their brand!  So let’s look at why SME’s are prime targets.

Automation is Key

Understand that the attacks affecting a large number of website owners in the prosumer category (a term I’m using to describe website owners in micro, small, and medium-sized businesses leveraging platforms like WordPress, Joomla and others) are predominantly automated.

The benefits of these automated attacks have not changed, they still provide the attackers the following benefits:

  • Mass Exposure
  • Reduces overhead
  • Tools for everyone regardless of skill
  • Dramatically increases the odds of success

It is not to say that these attacks are never manual, but for the mass majority, automated attacks are what we see during the initial phases of the attack sequence.

A very simple illustration of the sequence would look something like:

  1. Reconnaissance
  2. Identification
  3. Exploitation
  4. Sustainment

The attack sequence can have varying levels of complexity depending on the group of attackers. When working with everyday websites, the most effective way to affect the largest number of websites at any given time would be with the deployment of scripts and bots during steps one and two. Although not always a manual process, steps three and four often have a tendency to have more manual elements to them, although many can be automated as well. While thinking of how these attacks occur, it is important to note the two forms of attack categories; attack of opportunity and targeted attack.

Attack of Opportunity

Almost all prosumers fall within the realm of opportunistic attacks. Meaning that it is not any one individual that is intentionally trying to hack your website, but rather a coincidence. Something about your site was caught by the trailing net as they randomly crawl the web. It could have been something simple like having a plugin installed, or maybe displaying the version of a platform.

In our analyses, we have found that it takes about 30 – 45 days for a new website, with no content or audience, to be identified and added to a bot crawler. Once added, the attacks commence immediately without any real rhyme or reason. It can be any type of website, the only commonality is that it is connected to the web.

These crawlers then begin looking for identifying markers. Is the website running one of the popular CMS applications (i.e. WordPress, Joomla)? If so, is the website also running any exploitable software (i.e. software vulnerabilities or bugs in code)? If the answer is yes, then the site will be marked for the next phase of the attack, exploitation.

The sequence of events can happen in a matter of minutes, days or months. It is not a singular event, instead it occurs continuously, always scanning for changes or updates. It is automated, therefore, once your website is on the list it will just continue trying.

Targeted Attack

This is often reserved for the larger businesses, but not always.  The level of effort it takes to gain entry into these environments is exponentially more difficult but the gains can be astronomical. That being said, a very common form of targeted attack can be seen in something known as a Denial of Service attack in which the attacker works to bring down the availability of your site – common between competing businesses.

With that in mind, targeted attacks are not always reserved for the big boys. They can be deployed against smaller sites, and can be driven by competition or pure boredom and the need for a challenge. These attacks can range from very simple to very complex.

Motivations and Drivers

Now that we have a better appreciation for the how, let’s turn our attention to the why – why websites get hacked. That is why you are reading this.

Economic Gains

The most obvious of the reasons is economic gain. This often manifests in attacks known as Drive-by-Downloads or Blackhat SEO campaigns. As you might imagine, these are attempts to make money from your audience.

A Drive-by-download is the act of deploying what is known as a payload (i.e. injecting your website with malware) and hoping to infect as many of your website visitors. Think of your mom or dad visiting your website and the next thing you know, they are calling you because they installed a fake piece of software like you recommended on your website, but this time their bank accounts were drained. Scary, but very real and very devastating.

Blackhat SEO spam campaigns are not as devastating, however, in many instances they can be more lucrative. This is the game of abusing your audience by directing them to pages that generate affiliate revenue. This is rampant in the pharmaceutical space, but has also extended to other industries like gambling, fashion and many others. What they do is inject links through your website, sometimes you see them, sometimes you won’t. On the contrary, when it comes to search engines like Google or Bing, they see everything and once those links make it onto the Search Engine Results Pages (SERPs) the attackers begin generating revenue from your audience.

System Resources

There is one motivator, the use of your resources, that many don’t talk about. When referring to resources, I am talking about things like bandwidth and physical server resources. I break this out as its own motivator, but it’s also a group under economic gain. The business of farming system resources is big business and a huge motivator for many cyber groups; they’re able to not only use it as part of their own networks, but build a leasing environment off your stack.

You will have likely heard of large botnets and I have also referenced them above. Botnets are nothing more than interconnected systems across the net; they can be desktops, notebooks and even servers – similar to your webserver. They can be employed to perform tasks simultaneously. These can include Denial of Service Attacks, Brute Force Attacks, or even some of the automated attacks mentioned above.

These attacks that target your system resources are dangerous mainly because of their ability to attack without you, the website owner, even realizing it. You go about your day with no worries with your website appearing to be in good standing and with no complaints. Then one day out of the blue, your host shuts you down, your usage bill is through the roof or you receive a notice from the authorities about your hacking attempts.

Hacktivism

This motivator is perhaps the one that’s the hardest to contend with when it comes to getting your head around it. Similar to others, the drivers for these attacks are monetary or abusive. However, they are more finding a way to protest around a religious or political agenda or to show off to peers within the hacking community.

A very common form of this can be identified with Defacements. The point of these attacks often comes down to some form of awareness. This form of attack can be combined with others, but in our experience often are somewhat benign and create more embarrassment to the site owner rather than affecting their users.

Good Security Begins with Good Posture

It’s easy to feel overwhelmed by some of this information, but it is our belief that the best tool you have at your disposal as a website owner is knowledge. Driving your head into the proverbial sand does not make these things disappear; it simply amplifies the impact if and when any of these attacks affect you directly. I assure you they happen more often than note, and Google agrees they blacklist close to 10,000 sites a day for malware and flag over 20,000 sites for phishing every month.

As a species, we are risk averse when it comes to gains, but risk seeking when it comes to loss.

As the CEO of InstaHost one of the most frustrating things that my team would report back is the  “I have had a website for 10 years, never been hacked, I don’t need to worry about it.” especially in response to our courtesy emails to tell them that their CMS (WordPress or Joomla) was out of date and therefore a security issue.  These wre the clients whom we had the most painful conversations with when a hacking incident subsequently occurred.  At InstaHost we had (and still have) a number of premium security systems in place to protect your website and data, yet we found that SME’s/SMB’s were reluctant to pay for these.  At the start of 2015 we decided that we needed to be pro-active both to protect our team from ongoing issues which were taking time and money from our core business  and, of course, increase the security for our clients websites.  So we introduced a number of free items designed to increase security.

1:  We introduced a shared SSL for our clients to use whenever they want

2:  We introduced the award winning “Stop The Hacker” system across all of our Cloud Hosting  Packages for FREE!  This has reduced our CMS hosting security incidents by 77% (in 2015 February to December)
This seal is issued to mcgurk.me by StopTheHacker Inc.

3:  In an effort to protect CMS admin areas from malware attacks, we automated the “Are you Human” check which automatically deploys with each installation.

Now, despite all our efforts, we know that security is not about risk elimination, but rather risk reduction. You have heard this time and time again, risk will never be zero. You can, however, employ tools and steps to reduce it where you can so as not to become part of the statistic – which is exactly what we have tried to do for our InstaHost clients.  We also provide access to backup software in all control panels (this includes being able to backup any sql databases you may be using!  But we know that SMB’s are notorious for failing to backup, so we also take daily snapshot backups for each cloud account – so if your account is hacked – we will have 30 days of copies to enable restoration.

Let’s review the biggest hacks in 2015

OPM (US)

The prize for the biggest hack of 2015 goes to OPM—the federal Office of Personnel Management. The hackers, reportedly from China, maintained their stealth presence in OPM’s networks for more than a year before being discovered. When the breach was finally uncovered, initial estimates placed the number of victims at 4 million. But that number soon ballooned to more than 21 million, including some 19 million people who had applied for government security clearances and undergone background investigations, as well as an additional 1.8 million spouses and live-in partners of these applicants. The hackers got their hands on a trove of sensitive data, including the SF-86 forms of people who applied for clearances. The forms can contain a wealth of sensitive data not only about the workers seeking a security clearance, but also about their friends, spouses, and other family members.

If this wasn’t bad enough, the agency eventually admitted that the hackers also gained access to the fingerprint files of some 5.6 million federal employees, many of whom hold classified clearances and use their fingerprints to gain access to secured facilities and computers.

Juniper NetScreen Firewalls

System administrators who planned to attend the Star Wars: The Force Awakens premier probably had their plans wrecked when Juniper Networks announced on December 17 that it had found two backdoors installed in certain versions of its ScreenOS software. This is the operating system that runs on the company’s NetScreen VPN/firewalls, which are used by government agencies and corporations around the world. As administrators scrambled to apply patches Juniper released, they learned that one of the unauthorized backdoors consisted of a hardcoded master password the attackers had surreptitiously embedded in the software’s source code. The password would essentially allow attackers to take complete control of any vulnerable NetScreen device connected to the internet.

The second backdoor was just as bad, but in a different way. This one appears to undermine the encryption algorithm known as Dual_EC that Juniper uses to encrypt traffic passing through the NetScreen VPN. The backdoor is the kind that a nation-state intelligence agency would love to have to give it the ability to intercept and decrypt large amounts of VPN traffic. But what makes the backdoor even more interesting and notable is the fact that it appears to be based on another backdoor the NSA allegedly created years ago in the Dual_EC algorithm for its own secret use, all of which underscored the risks of letting the government install backdoors in tech products.

Ashley Madison

Unlike the stealth OPM hack, the breach of AshleyMadison.com, a site that touted itself as the premier platform for married individuals seeking partners for affairs, was loud and flashy and deserves the award for brazenness. Exactly one month after their hack of the cheating site went public, the hacker or hackers behind the breach made good on a threat to release sensitive company data, dropping more than 30 gigabytes of internal company emails and documents, as well as details and log-in credentials for some 32 million accounts with the social networking site. The data included names, passwords, addresses, and phone numbers submitted by users of the site. Although many of the personal account details were fabricated by users to remain anonymous, the hackers also released seven years worth of credit card and other payment transaction details, which exposed the real names and address of many customers. Reality TV star Josh Duggar was among those exposed by the breach. The company has been hit with several lawsuits from irate customers who accused the cheating site of being negligent in protecting their data.

LastPass

If you want to steal money, you rob banks. If you want to steal passwords, you hack a password manager. That’s exactly what intruders did this year when they breached the network of LastPass, a service that offers users a one-stop shop to store their passwords. LastPass said the hackers accessed email addresses, encrypted master passwords, and the reminder words and phrases that users designated they wanted the site to ask them if they forgot their master passwords. LastPass said it used strong “hashing” and “salting” functions to secure the master passwords customers choose to lock the vaults where their plain-text passwords are stored, but the company admitted that if customers used simple master passwords, the attackers might be able to crack them. Let’s hope that LastPass customers weren’t using 12345 for their master keys and that other password services are using strong methods similar to LastPass to secure customer data.

Talk-Talk

TalkTalk came under a Distributed Denial of Service (DDOS) attack, where hackers flood a company’s site with internet traffic in an effort to overload digital systems and take them offline.  However customer information was taken it would appear that a second attack occurred  at the same time, with intruders going after TalkTalk’s customer database. This is a common tactic, with a DDOS attack used as a distraction to enact a more specific data breach. “It’s like setting a fire in the front yard, while coming in at the back door,” said Rik Ferguson, global vice-president of security research at Trend Micro, the web security company.  TalkTalk had suffered two similar cyber attacks in 2014 / 15.

Many companies encrypt sensitive information to ensure that even if their defences are breached it would be difficult for outsiders make sense of the data they had got hold of. TalkTalk’s database had not been encrypted (this was made worse by the CEO being unable to answer whether the data was actually encrypted live in a TV interview!

MoonPig

The greetings cards retailer suspended purchases through mobile apps at the start of 2015 after claims that personal data of customers could have been exposed owing to a flaw in its cyber security. A developer alerted the company to the backdoor, and there was no evidence of any loss of personal details.

InstaHost – Secure UK Based Hosting

Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/themes/applauz/views/prev_next.php on line 10
previous
Millennials leading the way in using social media to shape their shopping habits

Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/themes/applauz/views/prev_next.php on line 36
next
The Importance of Accountability and how to develop more of it!

Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/plugins/related-posts-thumbnails/related-posts-thumbnails.php on line 846
https://www.instahost.solutions/wp-content/uploads/2018/10/logo1.png
https://www.instahost.solutions/wp-content/uploads/2017/03/logo_white.png
Insta Security
Website Secured by InstaHost.co.uk
InstaHost Solutions

Our Mission is to deliver an industry leading, comprehensive service to all of our clients regardless of client size or complexity of services required, we are committed to continually striving to develop new, innovative services and technologies in order to continue deliver cutting edge service solutions to all of our clients. We give our clients full control of their digital business without a ridiculous price tag, and our friendly team offers their expertise at all times!

Subscribe

If you wish to receive our latest news in your email box, just subscribe to our newsletter. We won’t spam you, we promise!

    Applauz

    As the pioneer of the lean startup movement, APPLAUZ has dedicated it’s time to sharing effective business strategies that help new businesses and enterpreneurs put their money to work in the right way.

    2021 Copyright by InstaHost Solutions, Powered by InstaHost.co.uk. All rights reserved.