Major Retailers Experience 161% Increase in Attemp
web hosting directory web hosting dedicated server colocation hosting web hosting services servers web hosting company web hosting article web host news web host news

web hosting
Cheap web hosting
Windows web hosting
Linux web hosting
Unrestricted hosting
Ecommerce web hosting
Virtual server VPS
Reseller hosting
by US State
by US City
Web Hosting coupons
VPS coupons
Articles

Cheap dedicated servers
Best dedicated servers
Windows dedicated servers
Linux dedicated servers
Unrestricted server
dedicated managed server
dedicated server unmetered
by US State
by US City
Dedicated server coupons
Articles

Cheap colocation hosting
Unrestricted Colocation
by US State
by US City
Coupons Promotion
Articles

Domain Registration
SSL Certificate
Website Statistics
Merchant account
Control panel
WebSite monitor

Intel Servers
AMD servers
SCSI Servers
Cheap Servers

Web hosting company
Dedicated Hosting
Colocation hosting
Web Hosting Services
Server manufacturer
Reviews

So you want to know how you decide what web host is best!

What is 1Mbps 95th percentile ?

Top 10 Dedicated servers May 2010

Westmere Dedicated server the best deal

Using CMS to create Websites

Top 10 Dedicated Servers March 2010

Control Panel Benefits

Top 10 Dedicated servers January 2010

More Articles


Ring the Christmas Bells with Infrenion Networks 50% Discount!

WebHost.UK.Net: offering web hosting great deals this Christmas.

Action Web Group Introduces The All New RubberBand Plan To Take The Place Of Unlimited Web Hosting!

Vision Helpdesk Christmas Madness is back! HO-HO-HO Huge Discounts!

Codero Names Jonathan Ewert as President and CEO

Lunarpages Boosts Reseller Plan

More News




Major Retailers Experience 161% Increase in Attempted Hacker Attacks According to SecureWorks

Major Retailers Experience 161% Increase in Attempted Hacker Attacks According to SecureWorks
Thursday December 4, 2008 15:10:01

Major Retailers Experience 161% Increase in Attempted Hacker Attacks, According to SecureWorks

Online Shoppers and Retailers Advised to Take Protective Steps this Holiday Season and Beyond

ATLANTA, Dec. 4 -- SecureWorks(R), a leading Security as a Service provider, reports they have seen a 161% increase in the number of attempted hacker attacks they are blocking for their retail clients. Attempted attacks increased from an average of 56,000 per client per month in the first six months of the year to 133,000 per client per month for the last five months. The attack statistics represent the attack activity for 36 major retail corporations located across the country.

SecureWorks' security researchers attribute the overall increase to a rise in attempted authentication attacks, SQL Injection attacks and network scans.

"We saw a large increase in hackers looking for open ports, as well as those trying to identify the applications and other services our retail clients were running," said Wayne Haber, director of architecture for SecureWorks. "An increase in network scans is often a red flag because many times it is followed by attacks specifically targeted at the organization's services," said Haber." "Attempted network scans against our retail clients increased 61% in 2008 going from an average of 56,000 per client per month in the first six months of the year to 90,000 per client per month in the last five months of the year," continued Haber.

The number of attempted authentication attacks -- attacks used to compromise user names and passwords -- increased steadily throughout the year, jumping from an average of 6,000 per client per month in the first six months of the year to an average of 34,000 per client per month in the last five months. The numbers continued to increase through the most recent month, November, where authentication attacks spiked to 137,000 per client per month. "It is not surprising that the attempts to steal customer credentials greatly increased just before the holiday shopping season. The November authentication attacks also followed a significant increase in network scanning in October where we blocked 202,000 network scans per client," said Haber.

"One of the methods used to bypass authentication are brute force attacks -- where hackers systematically try large numbers of username and/password combinations in order to gain access to the retail organizations," said Don Jackson, director of Threat Intelligence for SecureWorks. "Hackers know that if they can successfully steal customer usernames and passwords, they can get access to retail accounts to make fraudulent online purchases and redirect those purchases to mailing addresses of their choice," continued Jackson.

Attempted SQL injection attacks, a technique that exploits security vulnerabilities in Web applications by inserting malicious SQL code in Web requests, increased significantly in May for our retailers, going from an average of 20 per client per month to 237 per client per month. It then hit a peak in July with 17,000 attempted SQL Injection attacks per retail client and since November has dropped off to normal levels, averaging 18 per client per month.

"The abnormally high attack levels in July, August and September are a result of the rash of SQL Injection attacks we saw this year from a Chinese SQL injection tool and the Asprox trojan," said Jackson. http://www.secureworks.com/research/threats/danmecasprox/

"In July, August and September, hackers used the Chinese SQL Injection tool and the Asprox trojan to launch thousands of SQL Injection attacks so as to build up their botnets," said Jackson. "With these attacks, they sought out websites that utilized active server pages linked to a Microsoft SQL Server backend and unfortunately a lot of retailers use this platform, thus they became a big target. Of course, this boded well for the hackers because if they could infect high trafficked sites then their chances of infecting large numbers of computers and turning them into bots would be much greater. The bots were then used to send phishing e-mails and launch additional SQL Injection attacks. For retailers, the danger of a SQL Injection attack is that if it is successful then the hacker can potentially gain administrator access to the affected server, thus opening up the entire customer database to the hacker, complete with the customers' account information which could include credit card data, bank account information, name, address, etc. Even worse, under some circumstances, once the hacker has successfully infiltrated the database server they can use it as a jumping off point to access the rest of the company's network," continued Jackson.

"With the holiday season upon us and shoppers flocking to the Internet to make gift purchases from the convenience of their computers, retail organizations and online shoppers should be aware of the threats and should employ protective measures," said Haber.

Security Tips for Online Retailers

Retail organizations should make sure their Web presence is secured against cyber attacks by employing a defense in depth strategy including:

-- Keeping all servers and workstations fully patched to protect against attacks targeted at the latest security vulnerabilities, especially Web application attacks such as SQL injection and cross site scripting.

-- Employing a default deny policy on firewalls at their network perimeters. This policy involves blocking all network traffic except traffic that is explicitly allowed.

-- Employing effective security practices on services requiring authentication, including password aging, password complexity, authentication delay and automatic lockout on repeated failed login attempts.

-- Employing intrusion prevention at the network perimeter to block attacks on key services accessible from the Internet including Web servers and mail servers, while allowing legitimate traffic to pass.

-- Monitoring servers and security devices 24x7x365 for security issues and requiring preventative actions to be taken on security threats in real time.

-- Regularly testing the organization's security posture via vulnerability scans and penetration tests.

Online consumers also need to take precautions, not only during the holiday season but whenever they are making online purchases. "E-commerce always increases around this time of the year, and with an increase in e-commerce comes an increase in criminal activity," said Jackson.

  Security Tips for Online Consumers
  Jackson recommends the following shopping tips for online consumers:


1. Be wary of holiday gift cards and holiday coupon offers sent via e-mail -- these often have malicious links within the offer which lead to downloads of info-stealing trojans or the hackers try to scam you out of your bank account information.

2. When visiting your favorite online retailer to purchase gifts, be sure to type the actual Web site address of the retailer into your browser. Do not follow links provided by e-mail offers or pop up ads. Many times these are fraudulent sites made to look like the legitimate retail sites.

3. When making online purchases, always use a credit card that limits your fraud liability. Avoid using debit cards to do online purchases when possible so as to limit your personal exposure to any possible fraudulent transactions.

4. When making online purchases, always look at your Web browser for the https (as opposed to http) protocol that proceeds a Web address. The "s" let's you know that the Web site is providing a layer of security for transmitting your personal information over the Internet.

5. Be wary of unsolicited e-mails, even from senders that you know, that include links or attachments. Before clicking on links or attachments, ALWAYS verify that the correspondent sent you the e-mail and enclosed link or attachment.

6. Be wary of e-mails notifying you that your banking certificate or token is out of date and to download a new certificate or token. Before taking any action, verify with your financial institution by calling them on a number that is not provided in the email.

7. Online computer users should avoid using weak or default passwords for any online site.

"We traditionally think of financial institutions as being the primary target of hacker attacks, but the fact is cyber-criminals are targeting other industries, like the billion-dollar retail industry, in order to get their hands on valuable personal data so they can reap the rewards from selling or using the data to commit fraud," Haber said.

About SecureWorks:

With over 2,000 clients, SecureWorks is one of the market's leading Security as a Service providers. Organizations are protected from external and internal cyber-threats through SecureWorks' On-Demand Security Information and Event Management (SIEM) platform, the SecureWorks Counter Threat Unit(SM) and three fully synchronous Security Operations Centers (SOCs) staffed with SANS GIAC certified analysts working 24x7 to safeguard client systems. SecureWorks has won SC Magazine's "Best Managed Security Service" award for 2006, 2007 & 2008 and has been named to the Inc. 500, Inc. 5000 and Deloitte lists of fastest-growing companies. www.secureworks.com .





Related Articles

SecureWorks Inc Wins SC Magazines Reader Trust Award for Best Managed Security Service for Four Years Running
SecureWorks, Inc. Wins SC Magazine's Reader Trust Award for Best Managed Security Service for Four Years Running ATLANTA, April 23 -- SecureWorks(R), one of the market's leading Security as a...
Thursday April 23, 2009 15:10:01
Security
Major Retailers Experience 161% Increase in Attempted Hacker Attacks According to SecureWorks
Major Retailers Experience 161% Increase in Attempted Hacker Attacks, According to SecureWorks Online Shoppers and Retailers Advised to Take Protective Steps this Holiday Season and Beyond ATLANTA,...
Thursday December 4, 2008 15:10:01
Security
SecureWorks and Microsoft Collaborate to Deliver Enhanced Protections for Security Vulnerabilities
SecureWorks and Microsoft Collaborate to Deliver Enhanced Protections for Security Vulnerabilities The Microsoft Active Protections Program (MAPP) Clears the Way for a More Rapid Response to...
Tuesday October 14, 2008 13:10:01
Windows
SecureWorks Provides Solutions to Help with Payment Card Industry PCI Data Security Standard DSS Version 12
SecureWorks Provides Solutions to Help with Payment Card Industry (PCI) Data Security Standard (DSS) Version 1.2 ATLANTA, Oct. 2 -- SecureWorks, a leading Security as a Service Provider (SaaS),...
Thursday October 2, 2008 13:10:02
Security
Community Bankers Association of Oklahoma Endorses SecureWorks as their IT Security Services Provider of Choice
Community Bankers Association of Oklahoma Endorses SecureWorks as their IT Security Services Provider of Choice ATLANTA, and OKLAHOMA CITY, June 30 -- Community Bankers Association of Oklahoma...
Monday June 30, 2008 11:10:02
Security
SecureWorks Wins SC Magazines Readers Trust Award for Best Managed Security Service for Three Years Running
SecureWorks Wins SC Magazine's Readers' Trust Award for Best Managed Security Service for Three Years Running ATLANTA, April 11 -- SecureWorks, one of the market's leading Security as a Service...
Friday April 11, 2008 11:10:01
Security
Security Services Provider SecureWorks Partners with Corporate America Credit Union to Deliver Security Services to Credit Unions Nationwide
Security Services Provider SecureWorks Partners with Corporate America Credit Union to Deliver Security Services to Credit Unions Nationwide ATLANTA, Feb. 5 -- SecureWorks(R), one of the market's...
Tuesday February 5, 2008 12:10:01
Security
SecureWorks Designated as a Qualified Security Assessor for PCI Audits
SecureWorks Designated as a Qualified Security Assessor for PCI Audits Now able to certify retailers, utilities, financial institutions, healthcare organizations and others ATLANTA, Dec. 18 --...
Tuesday December 18, 2007 12:10:01
Web Host
Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks Data
Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks' Data Firm Warns of Browser Attacks ATLANTA, Oct. 5 -- SecureWorks, one of the industry's leading managed...
Friday October 5, 2007 08:10:01
Web Host
SecureWorks Positioned in the Leaders Quadrant for Advisory Firms Managed Security Services Provider Magic Quadrant for 1HO7
SecureWorks Positioned in the Leaders Quadrant for Advisory Firm's Managed Security Services Provider Magic Quadrant for 1HO7 Evaluation Based on Completeness of Vision and Ability to Execute...
Friday August 3, 2007 11:10:07
Hardware

Related Categories

Search news  
AskWebHosting Top Categories

Dedicated Hosting DirectoryServer Colocation DirectoryRackmount Server Directory
Webmaster Resources DirectorySpecial offersArticles
Shared Web Hosting Directory




Special offer



TOP 10 Best Dedicated Servers January 2011


AskWebhosting.com recommends 3dstats.com real time web statistics for tracking your visitors.

SingleHop Review
Codero Review
1&1 USA Review
DedicatedNOW Review
TurnKey Review
iWeb Review
ServerPronto Review

iPage Review
JustHost Review
FatCow Review
CoolHandle Review
midPhase Review
HostMonster Review
BlueHost Review
Hostgator Review

Amd X2 8GB Ram 8TB HDD Raid5 1Gbps 10TB NLWS $65 dedicated server

EU S p e c i a l s Powerful Xeon amp QuadCore Servers dedicated server

USDediDirect Dual Quad 2 5Ghz 8GB Ram 500GB HD 10TB BW $75 M dedicated server

ModulaOne Network Fully Managed 24x7 Support 10% OFF dedicated server

Taiwan 4 Cores AMD CPU 8GB DDR3 RAM 500G SATAII dedicated server

affordable dedicated servers atom d525 4g $65 m amp xeon e31230 8g ram $115 m

NL InstantDedicated com Dell R210 II E31260L 8 GB RAM 30 TB for 115 EUR dedicated server

deukus fully managed dedicated server 24x7 support from 39 eur get 1 year free

sandy bridge unmetered dedicated servers 100tb deals starting at $89 95 mo 10gbps unmetered servers

Dual Xeon L5420 250GB HDD 24GB RAM STARTING $160 dedicated server

MicraHosting Peer1 LA X3430 $139 Better Network for USA Asia China Taiwan HK dedicated server

hugeserver los angeles sandy bridge dedicated server one month for free

Dallas Texas Must sell immediately Xeon 3460 4x500GB RE3 RAID 10 Hardware dedicated server

dallas los angeles germany fully managed cpanel dedicated server as low as 149$

Quad 32GB RAM $119 m 2xL5420 16GB 1Gbps 40IPs $134 m i7 $139 m E31230 1Gbps $164 dedicated server

SingleHop coupon

Web Hosting deals

VPS Hosting deals

Colocation deals

More Deals


Free Web Stats
Web Statistics
Web Templates
Free Photos


2010 AskWebHosting.com    Contact-us    Advertise    Register    Web Hosting Questions    Privacy Policy