IXDownload.Com combats Wordpress-based malware attacks with security resource launch
IXDownload.Com combats Wordpress-based malware attacks with security resource launch
With over 22 million installs, Wordpress is the defacto standard for standalone blogging on the Internet. However, according to a 2009 New York Times estimate, a whopping 95 percent of blogs are abandoned shortly after they are created. Applying this figure to Wordpress' self-reported installed base, this reveals a huge dormant base of Wordpress installs that no longer get updated. “It appears Wordpress' success is also the cause of many of web visitors' security headaches”, noted Oliver Thompson of IXDownload.
Malware authors and distributors regularly scan the the Net through targeted searches for older installs to exploit security vulnerabilities in these abandoned, and therefore unpatched, installs. These hackers install malware/trojans which allow them to victimize the visitors of these abandoned blogs. These visitors' computers are turned into “zombie computers” which constitute a “botnet” used for spamming, denial of service attacks, spreading malware, and other illegal activities.
Just this past April, hackers used an SQL injection or database vulnerability found on Wordpress blogs hosted by one of the Internet's biggest web hosting companies and domain registrars, Network Solutions. Hackers caused the blogs to redirect to a website which then loads a variant of the BUZUS trojan. Shortly after, bloggers that use the shared hosting services of another giant domain registrar and host, GoDaddy, also report similar attacks on their older Wordpress installs.
These recent attacks are just the latest examples of the never ending security challenge created by a huge installed base of unsecure and abandoned websites and a decentralized band of profit-driven hackers looking to create a self-perpetuating and self-propagating network to spread malware. “While Wordpress is extremely secure when it is upgraded to the latest version, it poses a major network security risk when it is abandoned since the latest patches only apply to the latest version of the script. Older, unpatched versions are ticking time bombs scattered all throughout the Internet”, said Thompson.
IXDownload.Com's new Blog Malware Protection and Prevention Resource Page combats these threats by listing practical tips and free blog security plugins and other tools. The Resource Page is divided into two sections: resources for owners of wordpress blogs and internet users who read blogs. “These two groups of individuals are indispensable to addressing the problem of malware-spreading abandoned Wordpress blogs,” explained Thompson. “The security threat post by abandoned Wordpress blogs can't be fixed unless both sides do their part in addressing the problem.”
Solutions and resources for blog owners focus on best practices to increase their blog's security such as latest version updates, finding secure plugins, preventing version scanning, comment security, login hacking prevention, and diagnostic scanning. “However, the biggest and most crucial part of the solution to abandoned WP blog-based malware distribution threats are the precautions a responsible blogger should take in the event that the blog owner no longer has the time or motivation to update his or her blog,” said Thompson. The Resource Page outlines best practice steps that bloggers should follow, in coordination with their web hosting services' technicians, to prevent their blogs becoming malware distribution sites. “Followed properly, the protocol we are suggesting helps protect bloggers against possible future attacks or liability arising from their abandonment of their blogs,” noted Thompson.
IXDownload.Com's Wordpress Blog Malware Protection and Prevention Resource Page also lists best browsing practices Internet users can put into use, so they can anticipate, prevent, and fix Wordpress blog-related malware attacks. Among the tips and resources discussed are how to use search engines to skip suspected attack sites, configuring browsers to block attack sites from loading, setting up alternative and backup scanning processes, among other tips. The Resource Page also lists tried and tested malware detection and cleaning applications.
“Information truly is the best anti-botnet weapon available on the Internet,” says Thompson. Armed with the right resources, tools, and policies, responsible bloggers and informed blog visitors can ensure that the threat posed by abandoned Wordpress blogs is minimized.
About IXDownload.Com:
IXDownload.Com is the Internet's leading software information and resource site focusing on a wide range of security, productivity, and multimedia applications.
Company:
IXDownload.Com
Related press releases
-
IXDownload.Com combats Wordpress-based malware attacks with security resource la...
[2010-05-28 12:02:09]
(Berlin) IXDownload.Com, the Internet's leading network and computer security resource and news source, launches a new resource page that lists tips and resources that help web users avoid malware/bot... -
Comodo Launches Memory Firewall - One of the Only Ways To Protect Against Buffer...
[2008-01-16 16:57:57]
Free solution prevents over 90% of buffer overflow attacks - one of the most prevalent threats on the Internet today. Jersey City, NJ (January 16, 2008) -- In its continuing commitment to keep PCs ... -
Comodo Users React to Conficker Virus with Confidence, Not Fear
[2009-04-03 03:35:16]
Jersey City, NJ, April 03, 2009 - While users of other firewall and web security products scrambled to prepare for the possibly devastating effects of the Conficker virus, Comodo Internet Security use... -
Agnitum releases Outpost Network Security 3.0 Upgrade focuses on user security,...
[2009-09-24 09:26:18]
ST. PETERSBURG, RUSSIA, February 20, 2009: The security experts at Agnitum, developers of the Outpost Pro product line, are pleased to announce the latest implementation of the company's core business... -
"Testmypcsecurity.com" Provides First Independent, User Driven Testing Resource ...
[2008-03-19 11:15:14]
Testing Resource is Part of Comodo's Trusted Internet initiative to secure PCs for free for all online users Jersey City, NJ (March 19, 2008) - Today, Comodo, a leading security company, announced ... -
Summer Security Bonus
[2005-07-11 00:00:00]
StarForce announces the launch of the summer security bonus program: within the period of June 20 - August 20 all users of licensed security software are invited to advance into the new level of compu... -
K7 Computing CEO Wins Best Member Award in AVAR 2008
[2008-12-16 09:09:12]
Kesavardhanan Jayaraman, Founder and CEO of K7 Computing was granted the Best Member Award in recognition of his significant contributions to AVAR for the year 2008 Chennai, TN, 16th December 2008... -
Attacks during Thanksgiving holidays Leaves Windows Users Vulnerable; Days befor...
[2008-12-04 11:36:57]
New York, NY, Dec 4, 2008- Windows users were preparing for one the worst times of year for malware, and virus attacks. According to an analysis of 500,000 computers by PCTools.com, the time around... -
WordPress Helpdesk Becomes The #1 Plugin For WordPress Site Owners
[2009-10-02 02:32:41]
NY, October 2009 - As the professionals have said, there is literally a flood of WordPress websites today. Both commercial and personal websites are being developed with WordPress. Though the personal... -
Downadup returns – K7 Computing rescues
[2009-03-31 10:22:36]
Antivirus experts K7 Computing release a free tool for ALL PCs to neutralize Downadup worm, also known as Conficker (or) Kido which is threatening again with a latest updated version to be released on...
English
German
French
Spanish
Russian
Romanian



