WordPress & Drupal Vulnerability? –  Keep calm and update!

drupal-wp-vuln

Yesterday, a serious vulnerability in the PHP XML parser used by WordPress and Drupal was announced. After some great collaboration between the core developers of those applications, new versions that address the issue were released for both WordPress and Drupal. We, at SiteGround, are proactively addressing the issue too:
Continue reading “WordPress & Drupal Vulnerability? –  Keep calm and update!”

Joomla! Kunena Vulnerability Fixed on all SiteGround Servers

blog

Critical vulnerability in the famous Kunena forum component for Joomla! were announced three days ago and a new version of the component that addresses the issue was released. According to the official Kunena blog post all extension that are not updated to the latest version are vulnerable and the attackers may use XSS and SQL injection to gain full access to a Joomla! site.

Continue reading “Joomla! Kunena Vulnerability Fixed on all SiteGround Servers”

Two-factor authentication now available for your SiteGround account!

twofactor

If you have gone through the anguish of having your personal information exposed to theft and abuse, you probably already realize that even the best password is not always enough to protect your data against unauthorized access. There are many ways how you can find yourself exposed: lost/stolen electronic devices, electronic fraud (phishing, scam, etc.), and hacking of popular service providers have all become widespread. Continue reading “Two-factor authentication now available for your SiteGround account!”

TimThumb Critical Vulnerability Fixed on SiteGround Servers

header

Another serious security issue was reported earlier today within one of the popular WordPress plugins for managing thumbnails – TimThumb. This plugin already has a history of causing security issues in the past with which we dealt with. The current vulnerability allows the attacker to gain unauthorised access to your hosting account and even execute shell commands on it. Needless to say, this is not something we can allow to happen.

Our security team has reacted immediatelly after the vulnerability was disclosed. We have applied a patch in our in-house system to protect all our customers from getting hacked through TimThumb. Currently, if you’re hosted on SiteGround, you will be protected against hacking attempts that try to utilise this problem.

However, we strongly recommend that you switch plugins or update TimThumb as soon as new version is released.

[subscribe_cta]

Jetpack Critical Vulnerability Fixed on SiteGround Servers

jetpack

Yesterday, on April 10th, a critical security flaw in the popular Jetpack plugin was made public in an official statement by the Jetpack developers. If the vulnerability was exploited, an attacker could publish new posts in any WordPress installation using Jetpack and possibly get even more access to that site. Although we did not detect any hacked sites through that exploit on our servers, that was a critical security hole and we took several actions to patch it.

Continue reading “Jetpack Critical Vulnerability Fixed on SiteGround Servers”

SSL HeartBleed Vulnerability Patched

heartbleed1

As some of you already know, a major vulnerability in some versions of the OpenSSL software libraries was announced two days ago. It got the fancy name “HeartBleed” and in short, allows anyone on the Internet to read the server memory protected by the vulnerable versions of the OpenSSL software and hijack your SSL’s private key. The interesting information is that not all old versions of the software are affected and there are some older and some newer ones that have it.
Continue reading “SSL HeartBleed Vulnerability Patched”

We now have a Responsible Disclosure Policy!

nenatrapchivo
Ever since I started working for SiteGround I have been really impressed with the effort that goes into protecting the data security of the company and (ultimately) the user. There’s virtually no action taken and no line of code written that are not thought through from the security perspective first. With this level of commitment vulnerabilities in our systems are rare. However, when they appear there is no way to guarantee we’d be the first to spot them.

It is a blessing that we have a community of thousands of happy customers, including some computer security researchers among them. During the years we had several vulnerability cases reported by customers. However, so far there was no structured way to report a security issue to us. To make up for this we are now setting up a formal Responsible Disclosure Policy.

Continue reading “We now have a Responsible Disclosure Policy!”

Joomla! eXtplorer vulnerability – fixed!

hacklogo

Yesterday, my day ended delivering a webinar on Joomla security, only to start today with a new critical vulnerability found in a popular Joomla! extension – eXtplorer File Manager. This vulnerability is a classic example of two of the most popular ways to exploit an application: vulnerable plugin and weak login details. Of course as soon as the issue got discovered we started working on protecting our Joomla customers on a server level. Below I will explain the vulnerability, what we did to fix it on our servers, and what you should do if you are not hosted by SiteGround.

Continue reading “Joomla! eXtplorer vulnerability – fixed!”

WordPress Security Webinar with WebDevStudios – video and slides

WordPress Security Webinar

After a short summer break our educational webinar initiative continues with WordPress! Yesterday we hosted our first WordPress webinar about WordPress security with Brad Williams and Brian Messenlehner from WebDevStudios. We had a really good crowd of attendees and a great discussion at the end.

There are more webinars to come and we would love to hear from you about your preferred topics. Throw your suggestions in the comments below!

As the tradition goes, we’re sharing the video replay and the presentation slides!

Continue reading “WordPress Security Webinar with WebDevStudios – video and slides”