Login close
 

XSS redirect attack – root compromized via simple tricky redirect

April 16, 2010 - 3:54 pm | No Comment

As the attacks on infrastructure become more complicated, the true nature of deep penetration attacks prove food for thought for all developers and operators.  Consider this case – where the Apache open source infrastructure itself became significantly exposed by a simple XSS attack that utilized some social engineering techniques (i.e. getting folks to click on [...]

Who can access my WebsiteDefender Agent and the data it creates?

April 8, 2010 - 2:50 pm | One Comment

To trigger the Agent, the request sent to it must be encrypted using the Agent’s unique private encryption keys, which are only known by the WebsiteDefender Scanning Servers. If a normal user tries to access the agent directly, the agent will not return any data. All files stored on the Scanning Servers are encrypted with [...]

What is the WebsiteDefender Agent?

April 8, 2010 - 2:40 pm | One Comment

The WebsiteDefender Agent is a small piece of PHP code that sits either on the root of your website or within a sub-directory, and it is also used to verify that you own the scanned website. Unlike other security products the Agent is non-intrusive and is in no way harmful to your website or its performance, [...]

What WebsiteDefender IP addresses should I allow to scan my website?

April 8, 2010 - 1:17 pm | 5 Comments

If you would like to restrict access to the WebsiteDefender Agent you will have to add the WebsiteDefender Scanning Servers as exceptions, otherwise they will not be able to communicate with each other. Therefore you should grant access to the host name ‘scanners.websitedefender.com’. Restricting access to the WebsiteDefender Agent will help tighten up the web [...]

How many times does WebsiteDefender scan my website?

April 8, 2010 - 1:04 pm | No Comment

WebsiteDefender runs two security checks at different times based on the severity of the check. For instance, one of the scans, which reviews website uptime, DNS and other “uptime” monitoring checks are run hourly. A full website security scan, wherein WebsiteDefender checks all files and links to malware etc. is run once a week. Please note that this [...]

Page 24 of 28« First...10...2223242526...Last »