{"id":1960,"date":"2014-03-12T13:50:18","date_gmt":"2014-03-12T19:50:18","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=1960"},"modified":"2014-03-12T13:50:18","modified_gmt":"2014-03-12T19:50:18","slug":"kaspersky-lab-and-cambridge-university-websites-highlight-the-poor-state-of-security","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/03\/12\/kaspersky-lab-and-cambridge-university-websites-highlight-the-poor-state-of-security\/","title":{"rendered":"Kaspersky Lab and Cambridge University Websites Highlight The Poor State of Security"},"content":{"rendered":"<p>While keeping the software running a website up to date is a <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">basic security measure,<\/a> as it prevents the website from being exploited due to a known vulnerability in outdated versions of the software, we continue to see that the software isn&#8217;t being kept up to date. Our recent look at the stats of our tools for checking web software versions showed that a <a title=\"Outdated Versions of Joomla 2.5.x and 3.x Widely Used\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/03\/03\/outdated-versions-of-joomla-2-5-x-and-3-x-widely-used\/\">large percentage of websites checked were running outdated versions of Joomla, WordPress, and MediaWiki<\/a>. Even websites that you would expect would be taking security seriously are failing to keep the software up to date. We recently looked at <a title=\"Joomla Hack Cleanup Providers Don\u2019t Care About the Security of Their Own Websites\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/02\/25\/joomla-hack-cleanup-providers-dont-care-about-the-security-of-their-own-websites\/\">companies offering to clean up hacked Joomla websites and found that they were not keeping the software running their websites up to date<\/a>. All of those companies are rather small, so what about higher profile organizations? The examples below show that even they are failing to do this basic task.<\/p>\n<h2>Threatpost<\/h2>\n<p><a href=\"http:\/\/threatpost.com\/\">Threatpost<\/a> is a security news website run by Kaspersky Lab, a major provider of security software. If you visit their website with our <a href=\"http:\/\/www.whitefirdesign.com\/server-details\">Server Details web browser extension<\/a> you will be warned that the website is using outdated software. Clicking on the icon for the extension will let you know that they are using an outdated version of the nginx web server software:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/server-details\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1961\" alt=\"The Threatpost Website is Running on nginx 0.7.5\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/threatpost-nginx-version.png\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/threatpost-nginx-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/threatpost-nginx-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a>The next version in 0.7 series of nginx was <a href=\"http:\/\/nginx.org\/en\/CHANGES-0.7\">released in June of 2010 and the last release in the series was released in July of 2011<\/a>. There have been <a href=\"http:\/\/nginx.org\/en\/security_advisories.html\">two security vulnerabilities discovered<\/a> &#8211; and resolved in newer versions of nginx &#8211; that impact the version being used, the older one being disclosed in November of 2011.<\/p>\n<p>This isn&#8217;t an isolated issue at Kaspersky, in April of last year we posted about the fact that their <a title=\"Kaspersky Lab\u2019s US Website Running Outdated and Insecure Version of Drupal\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2013\/04\/12\/kaspersky-labs-us-website-running-outdated-and-insecure-version-of-drupal\/\">US website was running an outdated version of Drupal<\/a>. They are still are running the same outdated version, which is now over four years out of date.<\/p>\n<h2>University of Cambridge<\/h2>\n<p>The website for the University of Cambridge is running an outdated version of Drupal, with at least<a href=\"https:\/\/drupal.org\/drupal-7.26\"> one security update<\/a> missed:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/drupal-version-check\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1962\" alt=\"The University of Cambridge Website is Running a Drupal Version Below 7.25\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/university-of-cambridge-drupal-version.png\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/university-of-cambridge-drupal-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/university-of-cambridge-drupal-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a>The university&#8217;s computer science department has a\u00a0<a href=\"http:\/\/www.cl.cam.ac.uk\/research\/security\/\">Security Group<\/a>, which you would expect would want to make sure that the university&#8217;s websites is being kept secure, but at this point they are not even doing for their own blog. Their <a href=\"http:\/\/www.lightbluetouchpaper.org\/\">Light Blue Touchpaper<\/a> research blog is running a very out of date version of WordPress:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/meta-generator-version-check\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1963\" alt=\"Light Blue Touchpaper is Running WordPress 2.9.2\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/light-blue-touchpaper-wordpress-version.png\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/light-blue-touchpaper-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/03\/light-blue-touchpaper-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a>That version of WordPress is over three and half years out of date and nine subsequent releases have included security updates.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While keeping the software running a website up to date is a basic security measure, as it prevents the website from being exploited due to a known vulnerability in outdated versions of the software, we continue to see that the software isn&#8217;t being kept up to date. Our recent look at the stats of our &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/03\/12\/kaspersky-lab-and-cambridge-university-websites-highlight-the-poor-state-of-security\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Kaspersky Lab and Cambridge University Websites Highlight The Poor State of Security&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,36,35],"tags":[],"class_list":["post-1960","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-outdated-server-software","category-outdated-web-software"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=1960"}],"version-history":[{"count":1,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1960\/revisions"}],"predecessor-version":[{"id":1964,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/1960\/revisions\/1964"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=1960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=1960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=1960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}