December 2016 - We Watch Your Website

December 2016

Investigating some interesting entries in log files from our customers, we see that hackers apparently are still looking for infected WordPress websites. First we see this: (IP address blanked to protect the infected) - - [28/Dec/2016:20:44:14 -0500] "GET / HTTP/1.1" 200 [qodef_highlight background_color="yellow" color="red"]72904[/qodef_highlight] "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.63 Safari/537.31" The big tipoff here is the size of the GET request: 72904. And then this: (IP address...

Read More
wordpress security

  I know I've ranted about this before, but I recently read this in an article about WordPress security:   Preventing Cross-Site Contamination Shared hosting services are popular among businesses to host their WordPress blogs. Unfortunately, such shared services open the possibility of cross-site contamination. This is essentially a strategy that hackers use to attack a website by gaining access to another website in your shared server. One way...

Read More
Our methods for finding and removing website malware

You might imagine that find and removing website malware is relatively straightforward, right? Find malicious code and remove it.   Easy right?   Most website malware removal services work on signatures. These signatures positively identify a string of text in your website files. This method is very fast.   The average WordPress website has about 1,900 files. This is regardless of how many posts you have (posts are stored in the database)....

Read More