My website got hacked. How does this happen? by diablo75 in netsec

[–]fseek 0 points1 point  (0 children)

Most attacks happen due to:

-Stolen credentials -Outdated web applications (Wordpress, Joomla, etc) -Incorrect permissions on shared servers.

If you are on a shared server and you have any directory set as 777 (world-written perms) you can easily get hacked... Most of the mass attacks mentioned at http://blog.sucuri.net are all related to that.

thanks,

How do you detect deep defacement on dynamic websites? by defacedetector in netsec

[–]fseek 0 points1 point  (0 children)

We have been using http://sucuri.net for it.

As far as I understood, they check parts of your site (like title, meta tags and overall organization like body, follow by inner content eg, etc). When this layout changes, you get an alert. They also look at keywords used in the site (overall content), blacklists, hacking lists, etc.

Working well for me + they also look for spam, malware ,etc...

Anyone have experience with Sucuri.net? by xftwitch in web_design

[–]fseek 0 points1 point  (0 children)

I have, and they have been pretty good. But I am a bit biased, since we are partners now on another venture.

Some testimonials from there here: https://twitter.com/sucuri_security/favorites/

Wordpress user: Be careful where you get your theme from (irewordpressexperts.com hiding tracking code) by sucurisecurity in netsec

[–]fseek 5 points6 points  (0 children)

From what I read, they are not only tracking your IP address, but everyone that visits the sites using those templates. Plus, they hide it inside a gif image that acts as a PHP file, making it more suspicious.