ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Keylogger found on thousands of WordPress-based sites, stealing... | #Blogs #CyberSecurity #Updates #CyberHygiene #Awareness

Keylogger found on thousands of WordPress-based sites, stealing... | #Blogs #CyberSecurity #Updates #CyberHygiene #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it

A new report from researchers at Sucuri reveals that websites are once again being found infected by cryptomining code – stealing the resources of visiting computers to mine for the Monero cryptocurrency.

Many web surfers almost certainly don’t realise that the reason that their laptop’s fan is running at full blast is because the website they are viewing is tied up with the complex number-crunching necessary to earn the digital currency.

But, in a twist, this particular attack isn’t just interested in mining Monero. While the website’s front-end is digging for cryptocurrencies, the back-end is secretly hosting a keylogger designed to steal unsuspecting users’ login credentials.

With the keylogger in place, any information entered on any of the affected websites’ web forms will be surreptitiously sent to the hackers.

And yes, that includes the site’s login form.

 

We’ve said it before, and we’ll no doubt say it again. And again.

If your website is powered by the self-hosted edition of WordPress, it’s essential that you keep both it, and any third-party plugins, updated.

 

Self-hosting your WordPress site is attractive in many ways, but you have to acknowledge that security is now your responsibility (or find yourself a managed wordpress host who is prepared to take it on for you). New vulnerabilities are found in the software and its many thousands of third-party plugins all the time.

 

In short, if you don’t know what you’re doing, there’s a chance that your WordPress-running website has security holes which a malicious hacker could exploit. Such security weaknesses could potentially damage your brand, scam your website visitors, and help online criminals to make their fortune.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

Gust MEES's insight:

A new report from researchers at Sucuri reveals that websites are once again being found infected by cryptomining code – stealing the resources of visiting computers to mine for the Monero cryptocurrency.

Many web surfers almost certainly don’t realise that the reason that their laptop’s fan is running at full blast is because the website they are viewing is tied up with the complex number-crunching necessary to earn the digital currency.

But, in a twist, this particular attack isn’t just interested in mining Monero. While the website’s front-end is digging for cryptocurrencies, the back-end is secretly hosting a keylogger designed to steal unsuspecting users’ login credentials.

With the keylogger in place, any information entered on any of the affected websites’ web forms will be surreptitiously sent to the hackers.

And yes, that includes the site’s login form.

 

We’ve said it before, and we’ll no doubt say it again. And again.

If your website is powered by the self-hosted edition of WordPress, it’s essential that you keep both it, and any third-party plugins, updated.

 

Self-hosting your WordPress site is attractive in many ways, but you have to acknowledge that security is now your responsibility (or find yourself a managed wordpress host who is prepared to take it on for you). New vulnerabilities are found in the software and its many thousands of third-party plugins all the time.

 

In short, if you don’t know what you’re doing, there’s a chance that your WordPress-running website has security holes which a malicious hacker could exploit. Such security weaknesses could potentially damage your brand, scam your website visitors, and help online criminals to make their fortune.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Captcha-Plugin für WordPress installiert Backdoor | #CyberSecurity #Blogs #Awareness

Captcha-Plugin für WordPress installiert Backdoor | #CyberSecurity #Blogs #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it
Ein Captcha-Plugin mit eingebauter Hintertür ist auf 300.000 WordPress-Seiten aktiv. Mittlerweile ist eine bereinigte Version erschienen. Das Vertrauen in den Entwickler bröckelt weiter.

Das WordPress-Plugin Captcha hatte eine Backdoor eingebaut, über die Betrüger auf WordPress-Seiten zugreifen können. Davor warnen Sicherheitsforscher von WordFence. Die Version 4.4.5 von Captcha soll die Hintertür nicht mehr enthalten.

Captcha kommt auf 300.000 WordPress-Seiten aktiv zum Einsatz. Nutzer sollten sicherstellen, dass sie die aktuelle Ausgabe installiert haben – den Sicherheitsforschern zufolge ist die Backdoor seit der Version 4.3.7 mit an Bord. Nun darf der Entwickler das Plugin nur noch mit vom WordPress-Team abgesegneten Updates aktualisieren. Die verseuchte Version wurde automatisch an Nutzer ausgespielt. Betrachtet man den Entwickler Simplywordpress näher, schrumpft das Vertrauen weiter und es liegt nahe, das Plugin dauerhaft zu entfernen.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

Gust MEES's insight:
Ein Captcha-Plugin mit eingebauter Hintertür ist auf 300.000 WordPress-Seiten aktiv. Mittlerweile ist eine bereinigte Version erschienen. Das Vertrauen in den Entwickler bröckelt weiter.

Das WordPress-Plugin Captcha hatte eine Backdoor eingebaut, über die Betrüger auf WordPress-Seiten zugreifen können. Davor warnen Sicherheitsforscher von WordFence. Die Version 4.4.5 von Captcha soll die Hintertür nicht mehr enthalten.

Captcha kommt auf 300.000 WordPress-Seiten aktiv zum Einsatz. Nutzer sollten sicherstellen, dass sie die aktuelle Ausgabe installiert haben – den Sicherheitsforschern zufolge ist die Backdoor seit der Version 4.3.7 mit an Bord. Nun darf der Entwickler das Plugin nur noch mit vom WordPress-Team abgesegneten Updates aktualisieren. Die verseuchte Version wurde automatisch an Nutzer ausgespielt. Betrachtet man den Entwickler Simplywordpress näher, schrumpft das Vertrauen weiter und es liegt nahe, das Plugin dauerhaft zu entfernen.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Heftige Brute-Force-Attacken auf WordPress-Seiten | #CyberSecurity #CryptoMining #Awareness #Blogs

Heftige Brute-Force-Attacken auf WordPress-Seiten | #CyberSecurity #CryptoMining #Awareness #Blogs | ICT Security-Sécurité PC et Internet | Scoop.it

Sicherheitsforscher haben weltweit 14 Millionen Angriffe pro Stunde auf WordPress-Webseiten registriert. Die Angreifer wollen sich Zugang zu den Seiten verschaffen.

Derzeit erschüttert eine Angriffswelle gegen WordPress-Webseiten das Internet. Sicherheitsforscher von Wordfence haben dokumentiert, dass unbekannte Angreifer pro Stunde 190.000 Seiten via Brute Force attackieren. Als Spitzenwert haben sie stündlich 14 Millionen Angriffe beobachtet.

Dabei probieren sie im großen Stil Kombinationen von Nutzernamen und Passwörtern aus, um Admin-Zugriff auf Webseiten zu bekommen. Dabei sollen sie zum Teil organisiert vorgehen und versuchen, die möglichen Zugangsdaten von der URL und dem Inhalt der Webseite abzuleiten.

Malware schürft Kryptowährung


Ziel der Angriffe ist es Wordfence zufolge, auf gekaperten Seiten Software zum Schürfen der Kryptowährung Monero zu installieren oder diese als Ausgangspunkt für weitere Brute-Force-Attacken zu missbrauchen. Mittlerweile sollen die Angreifer dabei Monero im Wert von 100.000 US-Dollar geschürft haben.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=crypto-currency

 

Gust MEES's insight:

Sicherheitsforscher haben weltweit 14 Millionen Angriffe pro Stunde auf WordPress-Webseiten registriert. Die Angreifer wollen sich Zugang zu den Seiten verschaffen.

Derzeit erschüttert eine Angriffswelle gegen WordPress-Webseiten das Internet. Sicherheitsforscher von Wordfence haben dokumentiert, dass unbekannte Angreifer pro Stunde 190.000 Seiten via Brute Force attackieren. Als Spitzenwert haben sie stündlich 14 Millionen Angriffe beobachtet.

Dabei probieren sie im großen Stil Kombinationen von Nutzernamen und Passwörtern aus, um Admin-Zugriff auf Webseiten zu bekommen. Dabei sollen sie zum Teil organisiert vorgehen und versuchen, die möglichen Zugangsdaten von der URL und dem Inhalt der Webseite abzuleiten.

Malware schürft Kryptowährung


Ziel der Angriffe ist es Wordfence zufolge, auf gekaperten Seiten Software zum Schürfen der Kryptowährung Monero zu installieren oder diese als Ausgangspunkt für weitere Brute-Force-Attacken zu missbrauchen. Mittlerweile sollen die Angreifer dabei Monero im Wert von 100.000 US-Dollar geschürft haben.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=crypto-currency

 

No comment yet.
Rescooped by Gust MEES from #CyberSecurity #CyberSécurité #Security #Sécurité #InfoSec #CyberDefence #GDPR #RGPD #DevOps #DevSecOps #SecDevOps
Scoop.it!

Sécurité: WPscan Scan de sécurité du CMS Wordpress

Sécurité: WPscan Scan de sécurité du CMS Wordpress | ICT Security-Sécurité PC et Internet | Scoop.it
Nous allons ici nous intéresser à la sécurité du CMS Wordpress au travers l'outils de scan de sécurité Wordpress WPscan.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=WordPress



Via Frederic GOUTH
Gust MEES's insight:
Nous allons ici nous intéresser à la sécurité du CMS Wordpress au travers l'outils de scan de sécurité Wordpress WPscan.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=WordPress


No comment yet.
Scooped by Gust MEES
Scoop.it!

Security: Mehrere Sicherheitslücken in Drupal entdeckt

Security: Mehrere Sicherheitslücken in Drupal entdeckt | ICT Security-Sécurité PC et Internet | Scoop.it
Zwei Updates schließen mehrere Sicherheitslücken im populären CMS Drupal 6 und 7. Betroffen ist etwa der Pseudozufallszahlengenerator, der unter anderem von OpenID genutzt wird. 


Die Updates sollten unbedingt eingespielt werden.


Gust MEES's insight:

 

               =========> UPDATE asap!!! <========

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Official Google Webmaster Central Blog: Easier recovery for hacked sites

Official Google Webmaster Central Blog: Easier recovery for hacked sites | ICT Security-Sécurité PC et Internet | Scoop.it
Gust MEES's insight:

 

recovery for hacked sites...


Gust MEES's curator insight, October 31, 2013 1:29 PM

 

recovery for hacked sites...

 

Rescooped by Gust MEES from WordPress and Annotum for Education, Science,Journal Publishing
Scoop.it!

How to avoid being one of the "73%" of WordPress sites vulnerable to attack

How to avoid being one of the "73%" of WordPress sites vulnerable to attack | ICT Security-Sécurité PC et Internet | Scoop.it
Researchers have concluded that 73% of the 40,000 most popular websites that use WordPress software are vulnerable to attack. But they admit they might be wrong. Even so, they still highlight an im...
Gust MEES's insight:

 

73.2% of the most popular WordPress installations are vulnerable to vulnerabilities which can be detected using free automated tools.

 

Learn more:

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=WordPress

  
Gust MEES's curator insight, September 27, 2013 9:07 AM

 

73.2% of the most popular WordPress installations are vulnerable to vulnerabilities which can be detected using free automated tools.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=WordPress


Scooped by Gust MEES
Scoop.it!

CMS-Lösungen im Securitycheck

CMS-Lösungen im Securitycheck | ICT Security-Sécurité PC et Internet | Scoop.it
Das deutsche Bundesamt für Sicherheit (BSI) hat die geläufigsten CMS-Lösungen auf ihre Sicherheit überprüft. Getestet wurde unter anderem auch der gebotene Datenschutz.
Gust MEES's insight:

 

A MUST READ!!!

 

Learn more:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Massive Brute-Force Attack Infects WordPress Sites with Monero Miners | #CyberSecurity #CryptoCurrency #CryptoMining #Blogs #Awareness

Massive Brute-Force Attack Infects WordPress Sites with Monero Miners | #CyberSecurity #CryptoCurrency #CryptoMining #Blogs #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it
Over the course of the current week, WordPress sites around the globe have been the targets of a massive brute-force campaign during which hackers attempted to guess admin account logins in order to install a Monero miner on compromised sites.

The brute-force attack started on Monday morning, 03:00 AM UTC and is still going strong at the time of writing.

Brute-force attack targets over 190,000 WordPress sites/hour
To get an idea of the size of the campaign, WordPress security firm Wordfence says this was the biggest brute-force attack the company was forced to mitigate since its birth in 2012.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

 

Gust MEES's insight:
Over the course of the current week, WordPress sites around the globe have been the targets of a massive brute-force campaign during which hackers attempted to guess admin account logins in order to install a Monero miner on compromised sites.

The brute-force attack started on Monday morning, 03:00 AM UTC and is still going strong at the time of writing.

Brute-force attack targets over 190,000 WordPress sites/hour
To get an idea of the size of the campaign, WordPress security firm Wordfence says this was the biggest brute-force attack the company was forced to mitigate since its birth in 2012.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Un plugin WordPress vérolé a ouvert les portes de plus de 300 000 sites | #CyberSecurity #Blogs #Awareness

Un plugin WordPress vérolé a ouvert les portes de plus de 300 000 sites | #CyberSecurity #Blogs #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it

Un plugin WordPress vérolé a ouvert les portes de plus de 300 000 sites !


L'un des intérêts de WordPress est qu'il suffit de télécharger des plugins pour ajouter rapidement des fonctionnalités à son site. Une simplicité apparente qui peut aussi être source de vulnérabilités.

C'est ce qui s'est passé pour les utilisateurs d'un plugin ajoutant un captcha. L'entreprise qui le maintenait a vendu ce produit à une autre société, qui y a discrètement ajouté une porte dérobée. Plus de 300 000 sites utilisent cet outil et sont donc concernés par cette brèche, estime The Hacker News.

Le plugin, ainsi que quelques autres publiés par le même auteur et présentant la même porte dérobée, ont été supprimés de la boutique d'éléments de WordPress.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

Gust MEES's insight:

Un plugin WordPress vérolé a ouvert les portes de plus de 300 000 sites !


L'un des intérêts de WordPress est qu'il suffit de télécharger des plugins pour ajouter rapidement des fonctionnalités à son site. Une simplicité apparente qui peut aussi être source de vulnérabilités.

C'est ce qui s'est passé pour les utilisateurs d'un plugin ajoutant un captcha. L'entreprise qui le maintenait a vendu ce produit à une autre société, qui y a discrètement ajouté une porte dérobée. Plus de 300 000 sites utilisent cet outil et sont donc concernés par cette brèche, estime The Hacker News.

Le plugin, ainsi que quelques autres publiés par le même auteur et présentant la même porte dérobée, ont été supprimés de la boutique d'éléments de WordPress.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Embedding Code | iFrame HTML | CyberSecurity | iFrame Script Injection | eSkills | eLeaderShip

Embedding Code | iFrame HTML | CyberSecurity | iFrame Script Injection |  eSkills | eLeaderShip | ICT Security-Sécurité PC et Internet | Scoop.it
Iframe HTML made easy. Generate an iframe, download a free iframe browser, iFrame HTML made easy, more...


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=iFrame-Injection


Gust MEES's insight:

Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=iFrame-Injection


Gust MEES's curator insight, February 2, 2015 4:58 PM

Iframe HTML made easy. Generate an iframe, download a free iframe browser, iFrame HTML made easy, more...


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=iFrame-Injection



Rescooped by Gust MEES from WordPress and Annotum for Education, Science,Journal Publishing
Scoop.it!

Hackers turn 162,000 WordPress sites into DDoS attack tools

Hackers turn 162,000 WordPress sites into DDoS attack tools | ICT Security-Sécurité PC et Internet | Scoop.it
Legitimate sites forced to aid criminals' illicit botnet operations


Hackers have hijacked more than 162,000 legitimate WordPress sites, connecting them to a criminal botnet and forcing them to mount distributed denial-of-service (DDoS) attacks, according to security firm Sucuri.


Sucuri CTO Daniel Cid said the company uncovered the botnet when analysing an attack targeting one of its customers. Cid said Sucuri managed to trace the source of the attack to legitimate WordPress sites.

"The most interesting part is that all the requests were coming from valid and legitimate WordPress sites. Yes, other WordPress sites were sending random requests at a very large scale and bringing the site down," read the blog.



Via Gust MEES
Gust MEES's insight:


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?tag=Botnet


http://www.scoop.it/t/securite-pc-et-internet/?tag=Botnets


http://gustmees.wordpress.com/2012/05/21/visual-it-securitypart2-your-computer-as-a-possible-cyber-weapon/


http://gustmees.wordpress.com/2013/05/13/visual-cyber-security-see-attacks-on-real-time/

Rescooped by Gust MEES from WordPress and Annotum for Education, Science,Journal Publishing
Scoop.it!

WordPress › AntiVirus « WordPress Plugins

WordPress › AntiVirus « WordPress Plugins | ICT Security-Sécurité PC et Internet | Scoop.it

Via Gust MEES
Gust MEES's insight:

 

WordPress › AntiVirus « WordPress Plugins

 

Learn more:

 

http://gustmees.wordpress.com/2013/06/23/ict-awareness-what-you-should-know/

 

Gust MEES's curator insight, November 2, 2013 7:59 PM

 

WordPress › AntiVirus « WordPress Plugins

 

Learn more:

 

http://gustmees.wordpress.com/2013/06/23/ict-awareness-what-you-should-know/

 

Training in Business's curator insight, November 7, 2013 1:37 PM

WordPress › AntiVirus « WordPress Plugins

 

Techstore's curator insight, November 7, 2013 1:50 PM

WordPress › AntiVirus « WordPress Plugins

Scooped by Gust MEES
Scoop.it!

Cyber-Security Blogs To Follow

Cyber-Security Blogs To Follow | ICT Security-Sécurité PC et Internet | Scoop.it
. . WHY Should I Follow Security Blogs? . WHY SHOULD WE follow Security and Cyber-Security blogs as well, when using Twitter, following some great Cyber-Security experts!? Well, I will give YOU a q...
Gust MEES's insight:

 

WHEN working with any technical device, especially with devices who are connecting to the internet, it is crucial to have some basic knowledge of Cyber-Security! Whether theses devices are mobile (smartphones, iPhone, iPad, Android, tablets…) or desktop units, YOU need to know How To get protected on a maximum and ALSO about WHEN there are NEW threads around, new scams, new updates, new privacy dangers, new security risks, new valuable tips and tricks to stay secure!

 

Thankfully, there are many experts in the field of Cyber-Security and Education who do this for us and share their knowledge online.

 

Learn more:

 

http://gustmees.wordpress.com/

 

http://gustmeesen.wordpress.com/

 

 

Gust MEES's curator insight, October 26, 2013 6:17 PM

 

WHEN working with any technical device, especially with devices who are connecting to the internet, it is crucial to have some basic knowledge of Cyber-Security! Whether theses devices are mobile (smartphones, iPhone, iPad, Android, tablets…) or desktop units, YOU need to know How To get protected on a maximum and ALSO about WHEN there are NEW threads around, new scams, new updates, new privacy dangers, new security risks, new valuable tips and tricks to stay secure!

 

Thankfully, there are many experts in the field of Cyber-Security and Education who do this for us and share their knowledge online.

 

Learn more:

 

http://gustmees.wordpress.com/

 

http://gustmeesen.wordpress.com/

 

Second Star Technologies's curator insight, February 3, 2014 2:42 PM

You are vulnerable.  More so everyday.  These guys know why, how, and what you need to look out for.

Zhao KQiang's curator insight, March 27, 2014 7:24 AM

some useful information from this article that why we need to learn to the security of IT

Rescooped by Gust MEES from WordPress and Annotum for Education, Science,Journal Publishing
Scoop.it!

Safety and Security of WordPress Blog (Infographic)

Safety and Security of WordPress Blog (Infographic) | ICT Security-Sécurité PC et Internet | Scoop.it
WordPress is one of the most popular content management system (CMS) in use and around 17% of the websites that are present on the internet these days are powered by this CMS.

Via Gust MEES
Gust MEES's insight:

 

Learn more:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

http://www.scoop.it/t/securite-pc-et-internet/?tag=WordPress