Tumblr Hack: 4 Security Reminders For SMBs

  /     /     /  
Publicated : 22/11/2024   Category : security


Tumblr Hack: 4 Security Reminders For SMBs


Following GNAAs defacing of several thousand Tumblr blogs, take these security reminders to heart -- especially if you use popular publishing platforms.



9 Ways Skype Professional Network Helps SMBs (click image for larger view and for slideshow)
The ease and speed with which anyone with anyone can create a website these days can be a great thing, especially for smaller businesses short on resources or technical know-how. Unfortunately, those same benefits double as security risks.
That was on display Monday when the online troll group GNAA compromised the popular blogging platform Tumblr. Several thousand affected sites were taken over by a page that, to put it mildly, was not safe for work. Tumblr acknowledged the breach
on Twitter
. It announced later in the day that the problem, which Tumblr said affected a few thousand accounts, had been resolved.
We quickly identified the source, removed the posts, and restored service to normal, the company said on
its own Tumblr blog
. No accounts have been compromised, and you dont need to take any further action.
[ Cybercrooks dont necessarily just follow the money. Read more at
How Cybercriminals Choose Their Targets
. ]
The security firm Sophos
attributed the breach
to a fast-spreading worm. Any Tumblr users who visited an infected site while logged in immediately and unknowingly re-blogged the worm. In essence, the worm made use of one of the features that has made Tumblr a hit: the ease with which users can share and re-share content.
Thats among the reasons Tumblr makes an attractive target for hackers, trolls, and the like: Plenty of people -- to the tune of 170 million -- love it. That also means plenty of SMBs use it for marketing, customer service, microsites, or even as a full-blown Web presence. The same can be said of other low-cost, easy-to-use publishing platforms such as WordPress, Blogger, and others.
Whether you use Tumblr or not, here are four timely website security reminders.
1. Check your code.
Most website security problems start with the underlying source code. That appears to be the case in Mondays breach, according to Sophos technical breakdown of the Tumblr worm. Code vulnerabilities can lead to malware, SQL injections, and
other security exploits
. Whether you write your own code, use someone elses, or manage a combination of both, dont simply trust that its all safe and secure.
Give your code a regular checkup. Start with your Internet service provider or website host; ask what vulnerability testing and monitoring services they provide. Its possible such services are included as part of your existing agreement. If not, there are loads of security vendors out there who would be glad to take care of this for you, often in automated behind-the scenes fashion -- so long as you can pay their asking price.
For SMBs on a small budget -- or a nonexistent one -- there are free tools out there that can help. Netsparker offers a
free community edition
of its Web application security software, for example, that scans for SQL injections. (It also offers a free trial of its more robust paid edition.) Googles
Webmaster Tools
also offers site checkups for malware and other potential problems, as well as help with remediating known problems. The latter is a must to ensure your site stays off Google and browser blacklists in the wake of an incident.
2. Stay current on software.
Just as you stay on top of Windows updates, Adobe patches, Web browser versions, and other important downloads, you should stay current with any website publishing platforms you use. WordPress is a good example -- the wildly popular content management system regularly releases new versions, in part to fix security issues and other bugs. Yet 55% of WordPress sites are
running an older version
of the software. One reason that can cause problems: The
release notes
for new versions typically announce the security flaws in the previous versions -- something hackers can use to exploit sites that dont stay up to date.
3. Kill old sites.
Did you start that corporate blog with the best of intentions, only to let it languish in the great Internet desert of forgotten sites? Consider deleting it altogether unless youve got a good business reason to keep it up. Dead blogs and other mothballed websites make
nice targets for hackers
, since theyre often running on outdated code or publishing platforms. (If youve stopped updating your blog, youve probably stopped updating its publishing tool, too.)
Even if the forgotten site doesnt necessarily provide a back door into more valuable targets, it can pose the risk of embarrassment and reputation harm -- such as attacks that plaster racist or obscene language across the page. You likewise dont want sites or pages associated with your business unwittingly hosting porn, malware, spambots, or other potentially damaging stuff.
Any Web application is inherently a threat vector, to use security industry lingo. Theres no sense in maintaining threat vectors that no longer provide any business value. Eliminate unnecessary risks.
4. Use minor incidents to better defend against major ones.
Mondays security breach was somewhat embarrassing for Tumblr. It was certainly a disruption -- albeit a brief one -- for the several thousand affected sites. But the bottom-line impact was more akin to online vandalism than the types of security issues that lead to
bank account losses
and other lasting consequences. It wasnt the first incident of its kind; it wont be the last.
Thats not to say you should take such cases lightly. Rather, use them as reminders to safeguard your valuable business assets. Assess and
prioritize your security risks
and act accordingly. Use common sense and good basic security practices, such as
strong passwords
. Dont be an easy mark for criminals, hacktivists, or people who wreak online havoc just because they can.
Small and midsize businesses are falling prey to cyberattacks that cost them sensitive data, productivity and corporate accounts cleaned out by sophisticated banking Trojans. SMBs are typically on the hook for these losses and lack effective means to prevent them. Our
Small Businesses, Big Losses
report explains what makes these threats so menacing and shares best practices to defend against them. (Free registration required.)

Last News

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security

▸ Criminal Possession of Government-Grade Stealth Malware ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Tumblr Hack: 4 Security Reminders For SMBs