Serious Joomla Vulnerability found but we’ve got you Covered!

security

It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting, to say the least. On Thursday, 25 July the Joomla! Project announced the availability of Joomla 3.1.4/2.5.13 and many users upgraded their websites because the new releases provide tons of useful new features and bug fixes. One will think: job well done, it is time to hit the beach! But… On Thursday, 01 August, the Joomla! Project surprisingly  announced the immediate availability of Joomla! 3.1.5/2.5.14. Apparently not much time to sip exotic summer cocktails was allowed. The reason for this extremely short period between the two versions was that a critical level security issue was discovered just after the previous release and it had the potential to affect all Joomla! CMS versions. Yes, that’s correct  – we are talking about all the Joomla! sites out there. All versions are affected – 1.5, 1.6, 1.7, 2.5 and 3. Sounds scary, right? Not if you’re hosted on SiteGround servers!

Continue reading “Serious Joomla Vulnerability found but we’ve got you Covered!”

JCE/Image Manager vulnerability? NOT on SiteGround servers anymore!

You should always update!

Few days ago our security team has come across a JCE related vulnerability that has the potential to affect many Joomla 1.5.x based websites. The problem is that an old version of one of the JCE addons called ImageManager has turned out to be vulnerable to attacks. The number of the affected websites is big, because many templates  providers include the JCE editor together with ImageManager as part of their template bundle installations. So many Joomla users have these extensions without having installed them themselves.

Continue reading “JCE/Image Manager vulnerability? NOT on SiteGround servers anymore!”

Keeping The SiteGround Herd Safe

SiteGround Security Infographic

In 2012 we started the SiteGround How Cool Is That challenge to help our clients learn about the cool technologies that only we provide. Every week of the challenge we posted a new infographic explaining one of our unique features. In the final stage of the competition, our clients were invited to vote for the coolest technology by sharing their feedback in a comment. Our unique security technology gathered most of the votes and was chosen as the coolest Siteground feature among all others. Read the comments to see the feedback from the clients who voted for it or check a short infographic on how it works.

[subscribe_cta]

WordPress with W3 Total Cache plugin? Should you worry?

W3 Total Cache Christmas Vulnerability

On this year’s Christmas day, many WordPress users were quite unpleasantly surprised by a vulnerability in the popular W3 Total Cache plugin. The issue was a serious one, allowing the attacker to get access to sensible information from the WordPress database including password hashtags, usernames and much more. This meant that an experienced hacker could get full access to your site, download your personal information from it, change its looks, include malicious code, add backdoors for future access and much more bad things, you wouldn’t want to experience. Sounds scary? Not if you host with SiteGround!
Continue reading “WordPress with W3 Total Cache plugin? Should you worry?”

Has your WordPress site been hacked recently?

If you’re using WordPress as your favorite open source blogging platform, chances are pretty high you’ve already heard about the recent security flaw found in the TimThumb plugin fow WP. If you haven’t – you should, cause it’s pretty severe. Here is more info on that:

http://www.websitedefender.com/wordpress-security/timthumb-vulnerability-wordpress-plugins-themes/

The security flaw isn’t a core WordPress vulnerability, so you won’t be vulnerable for just using WordPress. However, the bad news is that a pretty big number of themes out there use the TimThumb plugin in order to operate correctly and therefore TimThumb is included in a lot of WordPress plugins and themes, both free and paid. The result is that there is a good chance you might have the vulnerable TimThumb installed and running on your WordPress even if you don’t really know about it or you don’t care.

Continue reading “Has your WordPress site been hacked recently?”

SiteGround Security Ins and Outs

SiteGround SecurityI’ve always wanted to express how I feel about security in the shared web space, where dozens of users divide the same resources and at the same time require dramatically different technologies to be enabled on a single host server (such as different PHP engines with different options enabled, Perl, Python, an FTP service, an email service, a Database service, etc;). In case you’re an admin, you’ll know how difficult it is to provide all of that on a shared hosting server while allowing access to practically everybody on the Internet and at the same time maintaining a very good level of security. Believe me, it’s a tough job. I know it as I’ve been dealing with that for more than 8 years in a row now, on a daily basis.

Continue reading “SiteGround Security Ins and Outs”

osCommerce Vulnerability Fixed on All SiteGround Servers

As probably most of you know, osCommerce is a shopping cart application for creating and managing online stores. It is very widely used and has many implementations and variations. Many popular shopping cart applications like OscMax, ZenCart, CreLoaded, etc. are actually based on osCommerce and use its code.

Unfortunately, for quite a while now, there has been a known vulnerability in the osCommerce code and the code of the applications based on it through which a hacker can exploit the admin area and take malicious actions. Although on the osCommerce official website there is some information how the problem can be avoided (http://svn.oscommerce.com/jira/browse/OSC-1069), the vulnerability has not been fixed yet in the latest osCommerce release and with each new download and installation of a related shopping cart software, new people and online stores become potential targets.

When there is a vulnerability in such a popular application and many sites are at risk, we at SiteGround do not believe in the approach: “let each user find and apply the bug fix him/herself”. First, most of the users understand about the issue only after they are already affected. Second, many of them are unable to apply the fix themselves. To protect our customers from hacker attacks, some of our best technical experts investigated the problem in details and applied a global solution to all potentially vulnerable customers’ applications.

The results from our osCommerce patch operation are:

  • the osCommerce package available for installation through Fantastico has been patched so that the new installations are not vulnerable to the exploit;
  • all future transfer clients with osCommerce-based websites will get the vulnerability fix as part of the website transfer service we provide;

We are proud that once again SiteGround has provided a security service high above the standard level for a shared hosting company. Our knowledge and reaction in situations like these make us believe that we do provide the best osCommerce hosting.

Hristo
Product Development – Technical

[subscribe_cta]