Jetpack Critical Security Vulnerability

jetpack

Today a critical vulnerability was found in one of the most popular and widely used WordPress plugins – Jetpack. Fortunately, according to the plugin authors there is no evidence that this issue has been used to hack real sites. However, an update of the plugin was released – Jetpack 4.0.3.

As usual, our security team was pro-active and updated our WAF (web application firewall), adding rules to prevent the hack from being used. This means that even if your plugin is not updated to the latest version, your site will still be protected. However, we urge all Jetpack users to update the plugin to its latest version in which the vulnerability is patched.

[subscribe_cta]

Supporting Indie Publishing Through Offscreen Magazine

Offscreen cover image

Four years ago we stumbled on the following somewhere on the web: “Offscreen – a print-only magazine about the people behind the internet and technology.” Naturally, our first thought was “Why make a print magazine for people who spend most of their time online?” It certainly piqued our curiosity, and that’s how we came to order our first issue of Offscreen. It was also issue No1 – a brand new magazine. Today, we happily received Issue No14 at the SiteGround office.

Continue reading “Supporting Indie Publishing Through Offscreen Magazine”

Critical glibc Vulnerability Patched on all SiteGround Servers

gnu

Hours ago a critical vulnerability in  the GNU C Library (glibc) was announced alongside a proof of concept for the attack. This library is one of the main components in the majority of Linux distributions (if not all) including those, used for server OS’es. Without getting into too much technicalities, the exploit allows an attacker to remotely execute code by following a simple link. That’s one of the most severe vulnerabilities discovered in the recent years and potentially affects pretty much any Linux server out there.

Given that all SiteGround servers run on CentOS – a Linux distribution, we took immediate measures to secure our machines. I am happy to announce that a patch has been applied on all our servers and our customers are well protected against this security threat!

[subscribe_cta]

2015: The Affiliates’ Assessment

_happy-new-affiliates
We said goodbye to a very successful 2015 and the collaboration with our affiliates had a key role in achieving our great resultsWe have 100% increase in the number of sales generated by our affiliate partners and have paid out commissions worth 4 million dollars! What’s more, the results from our annual affiliate survey results proved that our affiliates are extremely happy with both our service and program features! Read on for the rest of the survey findings.

Continue reading “2015: The Affiliates’ Assessment”

Let’s Encrypt is Here – Open Source Security Certificates Available at SiteGround

Let’s Encrypt

In December 2015 the new certificate authority Let’s Encrypt entered Public Beta and caused a wave of excitement. The groundbreaking news meant that website owners can obtain security certificates for their websites for free instead of paying for traditional SSL certificates and install them much easier. Naturally since then many of you have asked us when we would introduce the certificates on our hosting platform. For all of you who have been eagerly awaiting this moment, we are happy to say that Let’s Encrypt certificates are now available at SiteGround!

Continue reading “Let’s Encrypt is Here – Open Source Security Certificates Available at SiteGround”

Critical Vulnerability in Joomla Fixed on Zero-day

joomla-vulnerability

Yesterday, a serious vulnerability that affects all major Joomla versions was disclosed. Using this security breach a hacker could do a full remote command execution on the targeted site. We have worked together with the Joomla Security teams and came up with a rule in our WAF (web application firewall) that would block hacking attempts using this vulnerability and we don’t have reports for hacked accounts through this exploit.

Continue reading “Critical Vulnerability in Joomla Fixed on Zero-day”

Core Joomla! Vulnerability Patched in Version 3.4.5 Security Release

joomla-vulnerability

A few days ago, a critical vulnerability in the Joomla! core was found. It comes from an unsanitized input in the Joomla! core, which makes an SQL injection possible. The result of such an attack can lead to totally compromised websites – stolen login details, hijacking website access, malicious file uploads, etc. It’s a serious threat, without a doubt, and one that applies to all Joomla! 3.2 versions and above.
Continue reading “Core Joomla! Vulnerability Patched in Version 3.4.5 Security Release”

Affiliate Success Tips Part #4: An interview with Malte Helmhold

Malte-Helmhold

We’ve come to the end of yet another interesting and empowering project that we have undertaken for our affiliates. Today we feature the fourth and final interview from the Affiliate Success Tips series. One of our aims was to introduce affiliates with different profiles in order to show the variety of ways to promote and/or integrate hosting to a service. We chose Malte Helmhold because he has successfully mastered the video tutorials niche and we wanted him to share the benefits and opportunity he saw in it.
Continue reading “Affiliate Success Tips Part #4: An interview with Malte Helmhold”

JetPack XSS Security Issue – What We Did to Protect You

jetpack


On October 1st, a security issue in JetPack, one of the most commonly used WordPress plugins, was disclosed by our partners from Sucuri. The vulnerability was severe because an attacker could exploit the contact form feature of the plugin to insert and execute JavaScript code as an admin of your site. Needless to say, that could lead to all sort of problems – injecting black SEO links, adding backdoors for full access to your account, accessing private information, etc. In this recap post, we would like to summarise what we did to protect SiteGround users with this plugin installed.

Continue reading “JetPack XSS Security Issue – What We Did to Protect You”

Killing SSL SHA-1 Certificates And Making The Web A Safer Place

sha1

Recently PayPal has sent emails to many of its users informing them that SSL upgrades will be performed on their servers and SHA-1 certificates will be upgraded to SHA-256. Some people got confused what they should do when receiving these emails, as the mail that PayPal sent and the blog post they shared, giving more details to the users contain very technical information. Hence, we would like to explain to our customers how end users will be affected from the changes that PayPal makes and what they have to do. Continue reading “Killing SSL SHA-1 Certificates And Making The Web A Safer Place”