Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Top 5 Reasons Your Small Business Website is Under Attack
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
Chris Weltzien
50%
50%
Chris Weltzien,
User Rank: Author
9/2/2014 | 6:37:08 PM
RE: Solutions
Hi Joseph -- at 6Scan we provide a free scanning service availble at www.6scan.com/signup. We will identify vulnerabilities and existing website infections and we provide paid remediation services to fix any problems. We try and keep the process as smooth and affordable as possible. Solutions are also available from SiteLock and Sucuri.
JosephL208
100%
0%
JosephL208,
User Rank: Apprentice
9/1/2014 | 9:28:53 AM
RE: Solutions
So, what are the solution? The real soutions? As a small business owner, I don't really have the time to dedicate to protecting my systems especailly given how fast the hacking evolves. Yet, I also can't afford to have my reputation and data compermised. So, what are the solutions?


Capital LookUp - www.capitallookup.com/
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/31/2014 | 8:37:37 AM
Re: a good read - important for small business owners
Is the reason for why they are typically less vigilant with their bank accounts due to lack of resources? I feel their should be a finance analyst that would track changes to the account on a daily basis.

Also, how come the same fraud measures aren't taken for SMB's?
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
8/29/2014 | 9:25:41 AM
Re: a good read - important for small business owners
A key reason for continued attacks on SMBs is their bank accounts. An SMB can get a significantly larger line of credit than an individual, yet most SMBs don't track their "identities" as closely as individuals do. And oh, by the way, banks don't simply reimburse SMBs for fraudulent charges as they do for individuals.
Biffster
50%
50%
Biffster,
User Rank: Apprentice
8/28/2014 | 3:24:10 PM
Re: How do non-techie small businesses get security advice?
Agreed! Or perhaps Web Hosters should be more proactive in enforcing safe secure website behavior, sorta like the "click it or ticket" campaign for seat belt enforcement. Unsecured sites are the online equivalent of an attractive nuisance that can harm many others.
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
8/28/2014 | 3:15:27 PM
Re: Don't bother without security
A lot of the problems I've found when working with smaller businesses, is there's often a lack of understand not only of security itself, but who to hire to help with it. There are pleenty of freelancers I've worked with who claim to be well versed in Wordpress (or similar CMS) security, only to have them charge for hours of work with little results, or for them to clear out the affected files but not fix the loophole.

Very frustrating for everyone involved. I'd love to see some sort of accreditation that could be earned perhaps that was well known enough that even those unfamiliar with web security at an even basic level could understand and hire the right people. 
Chris Weltzien
50%
50%
Chris Weltzien,
User Rank: Author
8/28/2014 | 3:12:31 PM
Re: Don't bother without security
Great point. With proactive security the cost/benefit analysis focuses on value of the assett being secured. Two examples we see are small companies that service larger customers and small businesses that run transactional models. 

If you serve larger clients (who interact with your site) the cost of being a watering hole -- hacked and infected as a means to attack your larger customers -- can be measured as percentage of the value of your current clients. Also, if the attack became public, competitors would use it to take new business. To stay competitive would then require  marketing to off set the damage. 

On the transactional side the calculation would include lost revenue if your site is blacklisted by browsers or toolbars (Chrome, Firefox, AVG, etc) and the near destruction of all SEO/SEM efforts. Years of optimization can be undone with a single malware detection and it can take months to get it back. 
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
8/28/2014 | 2:49:48 PM
Re: Don't bother without security
Unfortunate indeed! Delivery of secure technology, and not just delivery of technology itself, should be a top priority for a business that includes an internet presence as part of their operational and strategic goals. However, without proper communication of the importance of security, organization heads will not place that kind of priority on security. It is therefore imperative that security professionals learn the art of effective business communication if they are to push the security agenda forward. FUD (fear, uncertainty, doubt) based messages have gone the way of the boy who cried wolf. Tough sell though, for a small business that has limited resources to begin with.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
8/28/2014 | 8:00:11 AM
Re: How do non-techie small businesses get security advice?
Or the web hoster should be more proactive about raising the awareness of the small business about potential website security issues that could cause serious damage.
Chris Weltzien
50%
50%
Chris Weltzien,
User Rank: Author
8/27/2014 | 9:57:16 PM
Re: How do non-techie small businesses get security advice?
This rather common -- a small company has a problem with their site but the developer did it as a one-off project and is no longer actively engaged. You make a great point, when hiring a developer companies should ask for an ongoing plan to maintain the security of the site.
Page 1 / 3   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
9 Tips to Prepare for the Future of Cloud & Network Security
Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
Attacker Dwell Time: Ransomware's Most Important Metric
Ricardo Villadiego, Founder and CEO of Lumu,  9/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25288
PUBLISHED: 2020-09-30
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitra...
CVE-2020-25781
PUBLISHED: 2020-09-30
An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
CVE-2020-25830
PUBLISHED: 2020-09-30
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
CVE-2020-26159
PUBLISHED: 2020-09-30
In Oniguruma 6.9.5_rev1, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concat_opt_exact_str in src/regcomp.c .
CVE-2020-6654
PUBLISHED: 2020-09-30
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.