Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 9th, 2011, 18:41 GMT · By Eduard Kovacs

Hacker Talks About Online Security and How to Protect a Website (Exclusive)

SHARE:

Adjust text size:


Black Hat hacker
Enlarge picture
After recent events, one of the members of black hat collective contacted me and we had a chat about online security and the issues that make a website weak for hackers. Recently, hackers showed that many banks, credit unions and even sites belonging to the United Nations are highly vulnerable so I asked him what could be done to properly secure a site.

First of all, he revealed that it’s very important to make sure components such as Apache or SQL are updated to the latest version.

“Honeypots on certain ports such as SSH and telnet (which is like accessing a machine from your own) are an efficient way of catching most hacking attempts because they are fake ports, and it seems real when most hackers scan for ports on a web server,” he said.

“And they'll be going ‘oh yay, vulnerable port!’ and they don't think twice to hide themselves, their IP address and user agent gets logged with the attempt.”

It’s his belief that when it comes to online security, the use of free content management systems that host many websites is not a very good idea.

“A website running Microsoft’s .ASP is like asking to be attacked,” he added.

Since some of the online payment methods proved themselves to be vulnerable, I asked him to tell me what the safest way of making online transactions is.

“I've taught many old folks that are above the age of 40 on how to remove viruses/any type of nasty infection from their machines, along with taking minimal precautions on keeping their websites/businesses secure online.”

“What I recommend for those who are looking for true card security: PayPal is a good payment gateway as they go through servers that are not on the same server as PayPal.”

Many of the hacking operations that take place these days, especially those made by gray hats, are purposed to show website administrators the weaknesses that can be taken advantage of.

“Defacing websites won't really show a purpose, seeing they can easily repair it. However, if you are actually able to obtain files/data from the server, that will make them take security more seriously.”

He continues, “there will always be private exploits, or a hole that you NEVER would’ve thought to miss. Only way to learn from those types of attacks is to get better and make sure the same thing won't happen again.”

TELL US WHAT YOU THINK:

4,373 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Operation Robin Hood: Not All Credit Unions Should Be Trusted (Exclusive)

Operation Robin Hood Proves BCD Credit Union Vulnerable

Operation Robin Hood: Chargebacks Won’t Stop Us

First National Bank of Long Island, Operation Robin Hood Victim

Team Poison and Anonymous Unite to Fight Banks in Operation Robin Hood

READER COMMENTS:


Comment #1 by: Anon on 09 Dec 2011, 21:13 UTC reply to this comment

Why are they making the enemy stronger with knowledge?

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM