Author Archives: Steve

Creepy!

When you next Tweet, think about the information you’re giving away. A new tool has been developed that will gather geolocation related information from your Tweet and image hosting services, pin pointing where you were and presenting the information via … Continue reading

Posted in Web Security | Leave a comment

How To Best Utilise A Dedicated Server With Cloud Server Management Software – 5 Simple Tips!

Server Images By using the snapshot feature of the cloud manager, you can take a snapshot image of your live server and use that image to create a server for testing your software updated. As a test server you’ll only … Continue reading

Posted in Cloud | Leave a comment

Facebook Targeted by Worm

Security researchers have revealed that a bank account-raiding worm has started spreading on Facebook, stealing login credentials as it creeps across the site. The worm, called Ramnit, originally discovered in April 2010 by the Microsoft Malware Protection Center (MMPC) is … Continue reading

Posted in Managed Hosting | Leave a comment

Would you lay out the welcome mat for hackers?

The idea of willingly inviting hackers to break into your website or server may seem odd, but if the intention of the hacker are good (i.e. they don’t intend to use what they find to exploit your business) it can … Continue reading

Posted in Web Security | Leave a comment

Concrete5 CMS Advisory – Multiple Vulnerabilities

Application : Concrete 5 Versions Affected: < 5.4 Exploit : Multiple SQL Injections and XSS Threat Level: Potentially high Fix: Update not available Credit: Ryan Dewhurst External Website: http://www.concrete5.org What does it mean, do I have to do anything, if … Continue reading

Posted in Web Security | Leave a comment

WordPress Security Advisory – Adrotate – SQL Injection

Application : WordPress Adrotate Plugin Versions Affected: 3.6.5 Exploit : SQL Injection Threat Level: Low Fix: Update Plugin to 3.6.6 Credit: Miroslav Stamper External Website: http://adrotateplugin.com/page/updates.php What does it mean, do I have to do anything, if so what? Adrotate … Continue reading

Posted in Web Security | Leave a comment

Common forms of Hacking

I’ve been asked to write an article for a popular website in relation to hacking and what the most common forms of hacking are. So, I’ve put together a brief blog about it and will link to the full article … Continue reading

Posted in Web Security | Leave a comment

Apache Security Advisory – Remote DoS

Apache Security Advisory – Remote DoS Application : Apache Web Server (mod_deflate module) Versions Affected : 1.3 – 2.2. Exploit : Range header DOS vulnerability Ease of use : Simple Threat Level : High Fix : Multiple, see below. ZeroDay … Continue reading

Posted in Managed Hosting | Leave a comment

Mambo CMS Security Advisory – SQL Injection

Application : Mambo CMS Versions Affected: 4.6.5 and Lower Exploit : SQL Injection Easy of use: Moderate Threat Level : Low Fix: Use another CMS in active development ZeroDay : No Credit: Aung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar … Continue reading

Posted in Web Security | Leave a comment

WordPress Security Advisory – TimThumb Theme Plugin – Remote Execution

Application : WordPress TimThumb (Theme) Plugin Versions Affected: 1.* – 1.32 (Only version 1.19 and 1.32 were tested.) Exploit : Remote Code Execution Easy of use : Moderate Threat Level: High Fix: Update to latest ZeroDay : No Credit: Mark … Continue reading

Posted in Web Security | Leave a comment