{"id":1927,"date":"2014-02-27T15:39:56","date_gmt":"2014-02-27T22:39:56","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=1927"},"modified":"2014-02-27T15:39:56","modified_gmt":"2014-02-27T22:39:56","slug":"norton-secured-seal-service-doesnt-do-basic-security-check","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/02\/27\/norton-secured-seal-service-doesnt-do-basic-security-check\/","title":{"rendered":"Norton Secured Seal Service Doesn&#8217;t Do Basic Security Check"},"content":{"rendered":"<p>Three years ago we <a title=\"Why That Trustmark Doesn\u2019t Mean a Website is Actually Secure\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2011\/04\/19\/why-that-trustmark-doesnt-mean-a-website-is-actually-secure\/\">posted<\/a> about the fact that trust marks shown on websites that claim to certify that the websites are secure cannot be trusted to identify if a website is actually secure for a number of reasons, including that in many cases they scan the websites from the outside so there are many things that they would never detect. What we recently noticed is that the Norton Secure Seal service fails to do a really basic security check that can be done from the outside. When it comes to the security of websites one of the\u00a0<a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">basic security measures<\/a> is to keep the software running the website up to date. This prevents the website from being hacked to the exploitation of a known vulnerability in the software that has been fixed in a subsequent release. As we have found the Norton Secure Seal service doesn&#8217;t check to make sure the software running the website they are claiming is secure is up to date.<\/p>\n<p>As an example of this we will take a look at the website of an IT security company that carries the Norton Secure Seal as you can see here:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1928\" alt=\"Norton Secure Seal\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal.png\" width=\"500\" height=\"300\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal-300x180.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>Using our <a href=\"http:\/\/www.whitefirdesign.com\/joomla-version-check\">Joomla Version Check web browser extension<\/a> you can see that the website is running an outdated version of Joomla:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/joomla-version-check\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1929\" alt=\"Joomla Version Used on Website Shown\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal-misses-outdated-joomla-version.png\" width=\"500\" height=\"300\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal-misses-outdated-joomla-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/norton-secure-seal-misses-outdated-joomla-version-300x180.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a>That version of Joomla, 3.1.1, is seven months out of date and more importantly subsequent versions have fixed four security vulnerabilities, including a <a href=\"http:\/\/developer.joomla.org\/security\/news\/563-20130801-core-unauthorised-uploads\">vulnerability rated as having\u00a0critical severity<\/a> and a <a href=\"http:\/\/developer.joomla.org\/security\/news\/570-20131101-core-xss-vulnerability\">vulnerability rated as having high severity<\/a>. A website with that level of security issue should not be labeled as being secure.<\/p>\n<p>The technology our web browser extension uses to detect that Joomla is powering a web page and what version is in use is rather simple and there is no excuse for a major company such as Symantec, the maker of the Norton Secured Seal service, not being able to do the same. Providing more awareness that an outdated version of Joomla is in use is definitely needed as <a title=\"Joomla 1.5 Still Widely Used Despite Support Ending in September of 2012\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/02\/24\/joomla-1-5-still-widely-used-despite-support-ending-in-september-of-2012\/\">outdated versions of Joomla are widely used<\/a>, including among <a title=\"Joomla Hack Cleanup Providers Don\u2019t Care About the Security of Their Own Websites\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/02\/25\/joomla-hack-cleanup-providers-dont-care-about-the-security-of-their-own-websites\/\">companies that provide security services for Joomla websites<\/a>, and <a title=\"Vulnerability in Joomla 1.6, 1.7, and 2.5.0-2.5.2 Being Exploited Now\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/01\/14\/vulnerability-in-joomla-1-6-1-7-and-2-5-0-2-5-2-being-exploited-now\/\">some older versions contain a vulnerability that is being exploited by hackers<\/a>.<\/p>\n<p>It isn&#8217;t just Joomla that Norton Secured Seal service doesn&#8217;t check to make sure is up to date; the same website has a blog running an outdated and <a href=\"http:\/\/wordpress.org\/news\/2013\/09\/wordpress-3-6-1\/\">insecure<\/a> version of WordPress as well:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/wordpress-version-check\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1930\" alt=\"The eGestalt blog is Running WordPress 3.5.2\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/egestalt-blog-wordpress-version.png\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/egestalt-blog-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/02\/egestalt-blog-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three years ago we posted about the fact that trust marks shown on websites that claim to certify that the websites are secure cannot be trusted to identify if a website is actually secure for a number of reasons, including that in many cases they scan the websites from the outside so there are many &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/02\/27\/norton-secured-seal-service-doesnt-do-basic-security-check\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Norton Secured Seal Service Doesn&#8217;t Do Basic Security Check&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,15],"tags":[],"class_list":["post-1927","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-website-security"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=1927"}],"version-history":[{"count":2,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1927\/revisions"}],"predecessor-version":[{"id":1932,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1927\/revisions\/1932"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=1927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=1927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=1927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}