Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
daviddede
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
daviddede
12y ago
We have a few samples of the SQL injection attempts here: http://blog.sucuri.net/2014/10/drupal-sql-injection-attempts... In there you can see the type of backdoors being added (generally fake users with admin-lev
2.
▲
by
daviddede
12y ago
And that was at the same time that everyone was worried about POODLE and the media was going crazy over it. Somehow this vulnerability went over the radar. What is interesting is that based on our own data, we started noticing attacks aroun
3.
▲
by
daviddede
12y ago
Virtual patching is the main benefit on WAFs for cases like this. We were able to issue a virtual patching signature for our clients in less than 2 hrs after the disclosure. Plus, our generic SQL injection signatures were already blocking t
4.
▲
by
daviddede
12y ago
That's exactly the issue. Most enterprises didn't even have time to be notified and properly test/push a patch live before the attacks were already in the wild.
5.
▲
by
daviddede
12y ago
You have a good point, but I was looking at these two points: 1- Extent of the damage 2- Number of points vulnerable Heartbleed had (has) a lot more servers vulnerable, but the impact is a lot lower and it is a lot harder to exploit to extr
6.
▲
by
daviddede
12y ago
It depends on the complexity of the attack. This Drupal one took our team less than an hour to have a working proof of concept (just based on the diffs). The exploit is very simple, and doesn't require any interaction with the remote s
7.
▲
by
daviddede
12y ago
That's as big as it can be. We started seeing attacks hours after the initial disclosure and shared some of them here: http://blog.sucuri.net/2014/10/drupal-sql-injection-attempts... This is a lot worse than
8.
▲
HTTPS is one of the least important things you can do to secure your site
(dcid.me)
4 points
by
daviddede
12y ago
|
1 comments
9.
▲
Mass Drupal SQL Injection Attacks – Turning SQLi into Code Execution
(blog.sucuri.net)
1 points
by
daviddede
12y ago
|
0 comments
10.
▲
by
daviddede
12y ago
That's very similar to what we are seeing as well: http://blog.sucuri.net/2014/09/bash-shellshocker-attacks-inc... Also, if anyone need a WAF to protect it in the mean while, we offer one that works very well
11.
▲
by
daviddede
12y ago
That's just the start. Once people start hitting cpanel servers: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...
12.
▲
by
daviddede
12y ago
It absolutely is. Specially now with thousands of cPanel servers known to be vulnerable: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...
13.
▲
by
daviddede
12y ago
cPanel servers vulnerable as well: http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shoc...
14.
▲
Thousands of CPanel Sites at Risk on the Bash / ShellShoker Vulnerability
(blog.sucuri.net)
3 points
by
daviddede
12y ago
|
0 comments
15.
▲
by
daviddede
12y ago
Do you have a screenshot by chance?
16.
▲
Anatomy of 2,000 Compromised Web Servers Used in DDoS Attack
(blog.sucuri.net)
2 points
by
daviddede
12y ago
|
0 comments
17.
▲
by
daviddede
12y ago
We have quite a few openings (all remote): -Senior PHP developer: http://sucuri.net/company/senior-php-developer-ops-022514 -Frontend designer/developer: http://sucuri.net/company/senior-front
18.
▲
by
daviddede
12y ago
Not new: http://dcid.me/texts/attacking-log-analysis-tools.html It had a similar vuln many years ago.
19.
▲
by
daviddede
12y ago
Yep, same here. I hate when products (companies) I use get acquired. It always come with not-welcoming product changes. Hope it doesn't happen to them.
20.
▲
Website Malware – Mobile Redirect to BaDoink Porn App
(blog.sucuri.net)
2 points
by
daviddede
12y ago
|
0 comments
21.
▲
Remote File Upload Vulnerability on WordPress MailPoet Plugin (1.7+m downloads)
(blog.sucuri.net)
6 points
by
daviddede
12y ago
|
0 comments
22.
▲
Disclosure: The Anatomy of a Remote Code Execution bug on Disqus (0day)
(blog.sucuri.net)
5 points
by
daviddede
12y ago
|
1 comments
23.
▲
by
daviddede
12y ago
Top of my list: Linode, Digital Ocean, Sucuri, CloudProxy, Balsamiq and Amazon Ec2.
24.
▲
by
daviddede
13y ago
Sucuri, Inc - Remote Our company is fully remote and we have people working from all sort of places: USA, Canada, Brazil, Spain, Romania, etc. Right now we have 3 positions open: -Senior PHP Developer -Senior FrontEnd Developer -Product UI
25.
▲
Mesh Network of compromised web sites
(blog.sucuri.net)
1 points
by
daviddede
13y ago
|
0 comments
26.
▲
by
daviddede
13y ago
I know one: http://sucuri.net Focused exactly on what you mentioned (web site recovery, monitoring and protection). *I work there :)
27.
▲
by
daviddede
13y ago
Remote, Anywhere Sucuri, INC: http://sucuri.net Senior FrontEnd Developer Sucuri is looking for a Senior Frontend Developer to join our R&D (Research and Development) team. As a senior frontend develper you would be responsi
28.
▲
by
daviddede
13y ago
Remote, Anywhere Sucuri, INC: http://sucuri.net System Administrator Sucuri is looking for a System Administrator with strong Linux and shell scripting experience to join our IT team. As a system administrator with Sucuri, you w
29.
▲
by
daviddede
13y ago
Remote, Anywhere Sucuri, INC: http://sucuri.net Senior PHP Developer: http://sucuri.net/company/senior-php-developer-ops-022514 Sucuri is looking for a Senior PHP Developer with shell scripting and Linux ex
30.
▲
Potential vBulletin Exploit (4.1+ and 5+)
(blog.sucuri.net)
2 points
by
daviddede
13y ago
|
0 comments
More ›