3 questions: WordPress security
CSO - Adam J. Kujawa is Malware Intelligence Lead at Malwarebytes. He authored the report "Cyberthreats in 2012," highlighting (among other things) security issues with the popular blogging/website platform WordPress.
CSO: What's the big deal with WordPress security--why is this a significant issue now?
Adam Kujawa: You've got fish in a barrel and an upgraded harpoon, in that a lot of people are creating their own blogs and the mass existence of exploit kits like Blackhole.
WordPress is a great exploit platform, because users have lots of control over how their WordPress site is viewed, and using plugins and things like that. But the problem is that users aren't properly securing them. They aren't keeping their passwords difficult enough or resetting them from the default, they're using outdated plugins and a lot of other bad security practices. It makes it very easy to set up drive-by exploits.
What was the worst WordPress exploit you saw?
We saw immense amounts of ransomware. The nightmare scenario would be malware-tisements--malicious ads where you're surfing a legit website, minding your own business, and a legitimate ad has been modified by cyber criminals and allowed to execute code or redirects. Next thing you know this ad shows up and you're redirected to a WordPress site with a drive-by on it and you get infected with ransomware and you're locked out of your computer and you have to pay $300 to get it back. My father got ransomware by this method.
Is it hard to set up WordPress securely?
Adam Kujawa: It's not super hard. If you're not inherently technical, I wouldn't try to set up WordPress. I'd get somebody else to do it. But the biggest targets are the ones that are quickly set up, and don't have a massive amount of traffic. The best advice I have is to find a professional or a hosting company. They might cost a little more but will be worth it if they can securely establish a web presence.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Cyberwarfare White Papers | Webcasts