boonbox

Web Threats Weekly

 Week of December 17, 2008

Web Threats Weekly helps alert organizations and individuals to known online vulnerabilities. 

If you have questions about how to make your organization secure against web threats, please  contact Boonbox for more information.


News & Ideas

Read articles, commentary and tips about IT security, ID management and more.

PCIS invites you to Managers' Toolbox Session: Protecting Your Business Online

Implications of Outsourcing Web Application Security (White Paper)

Calculating Return on Investment (ROI) of Devfense for Web Application Security (White Paper)

Myth of PCI DSS: PCI DSS: Security Compliance Is Hard (Pacific Coast Informer Blog)

Internet Explorer Critical Vulnerability Warning (PCIS)

In this issue:

* News & Ideas

* Hacker Bait 

* Mythbusters Tip #6

* Spam-Alot


Web Threats Weekly is distributed by:

* Pacific Coast Information Systems Ltd.

* Boonbox


* Boonbox IT security resources page


* Subscribe/Unsubscribe Instructions below

Hacker Bait

The latest Hacker Bait list contains social networking and business websites around the world that have been found to have vulnerabilities that hackers and cyber criminals could exploit. 

Keep in mind that this is not a complete list of all vulnerable sites on the Internet, but only represents websites where vulnerabilities were found within the past 90 days.

These are only the latest additions to an ever-growing club of sites found to be insecure according to various public sources and online tools used in the web security industry.

If you would like more information on our data and why these sites are listed here, please contact Boonbox

Hacker Bait Sites With Vulnerabilities Discovered in Past 90 Days

www.new.facebook.com

my.barackobama.com

www.theopenpress.com

www.tagomatic.com

wikimapia.org

community.mccainspace.com

www.tripadvisor.fr

login.facebook.com

www.googlesyndication.com

ca.music.yahoo.com

www.firstbusiness.ca

www.entrepreneur.com

www.financialexpress.com

www.bondsonline.com

shopping.web.de

shop.rcn.com

www.pizzahut.lk

www.megabuy.vn

easports.com

www.realtor.com


Mythbusters Tip #6

“My IT people already take care of our security. I'm positive. That's what we pay them for.”

Naturally, you want to have faith in your IT people. 

But your IT people are already working overtime re-setting passwords, finding lost files for hapless staff and patching all of your applications. You think they have time to do regular security compliance code reviews of your website and apps that were never built with security in mind in the first place?  

Most likely, your time-starved IT people simply can't keep on top of EVERYTHING. But as the hacker threat rises, it's more important than ever to stay on top of your vulnerabilities. Need help? Contact us


Spam-Alot

Spammers are linking to blogs, profiles and other pages on these trusted sites to give victims a false sense of security that the links can be followed safely. These sites may not have been hacked, but following the spam links to these sites and clicking on links shown there can result in harm to your computer.

If you would like more information on our data and why these sites are listed here, please contact Boonbox

Spam-Alot Websites Exploited Since Dec. 10

freebusinessthinking.com

whynotdesign.com

barak.net

aol.com

technomax.com

justkarma.com

Boonbox and Pacific Coast Information Systems Ltd.

Boonbox is a division of Pacific Coast Information Systems Ltd., specializing in products for web security, network security, password management and data backup.

PCIS is a Vancouver-based company which provides strategic consulting, application development, technology solutions and managed services to companies and government organizations throughout North America.

HOW TO SUBSCRIBE/UNSUBSCRIBE

SUBSCRIBE: To subscribe to Web Threats Weekly, send a blank email message with subject line "SUBSCRIBE" to informer@pcis.com

UNSUBSCRIBE: If you do not wish to receive future issues of Web Threats Weekly, send a blank email with subject line "UNSUBSCRIBE" to:informer@pcis.com and we will promptly remove you from our distribution list.

WE WANT YOUR FEEDBACK

Our purpose for providing this free service is to keep our clients and business contacts informed of technology developments. This information can help them resolve common problems and achieve their full potential by strengthening their business processes and infrastructure. Your input is important to us and we welcome your ideas for new features and how we can continue to improve our service to you. Send your comments and suggestions to informer@pcis.com or contact us directly at 604.844.7558

 

Copyright © 2008 Pacific Coast Information Systems