{"id":2122,"date":"2014-09-03T14:34:51","date_gmt":"2014-09-03T20:34:51","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2122"},"modified":"2017-01-03T15:19:55","modified_gmt":"2017-01-03T22:19:55","slug":"sitelock-fails-to-do-basic-security-check","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/09\/03\/sitelock-fails-to-do-basic-security-check\/","title":{"rendered":"SiteLock Fails To Do Basic Security Check"},"content":{"rendered":"<p>When it comes to the security of websites what we see is a situation where basic security measures, like keeping software up to date, are not being taken and security companies, most of whom appear to have little interested in actually improving security, are selling security services that are really not needed. A good example of this is SiteLock, which sells a security service that doesn&#8217;t provide any of the\u00a0<a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">security measures that need to be taken to protect your website from hackers<\/a>. Worse than that, we recently found that it is really poor at doing one of things that it is supposed to do, leading the people running websites and their customers to have a false sense of security.<\/p>\n<p>We recently were hired to do an u<a href=\"http:\/\/www.whitefirdesign.com\/services\/magento-upgrade.html\">pgrade of website running Magento 1.4.1.1<\/a>, a rather out of date version (the next version, 1.4.2.0, was released in December of 2010). When we took a look at the website we were rather surprised to see a security seal from SiteLock claiming the website was secure (we have blacked out the domain name in the image):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2124\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/sitelock-secure-seal.png\" alt=\"SiteLock Secure Seal\" width=\"150\" height=\"100\" \/><\/p>\n<p>Version 1.4.1.1 of Magento is old enough that security patches for major issues are no longer released for it and anyone concerned about security would be running at least the most recent major release, 1.9.0.0, as it <a href=\"http:\/\/www.magentocommerce.com\/knowledge-base\/entry\/ce19-later-release-notes#ce19-1900\">includes a number of security enhancements<\/a>:<\/p>\n<ul class=\"level1 circle\" style=\"color: #555555;\">\n<li>Addressed a potential cross-site scripting (XSS) vulnerability while creating configurable product variants.<\/li>\n<li>Addressed a potential security issue that could result in displaying information about a different order to a customer.<\/li>\n<li>Users can no longer change the currency if the payment method PayPal Website Payments Standard is used.<\/li>\n<li>Removed an\u00a0<tt>.swf<\/tt>\u00a0file from the Magento distribution because of security issues.<\/li>\n<li>Improved file system security.<\/li>\n<li>Enhanced the security of action URLs, such as billing agreements.<\/li>\n<li>Addressed a potential session fixation vulnerability during checkout.<\/li>\n<li>Improved the security of the Magento randomness function.<\/li>\n<\/ul>\n<p>We don&#8217;t really think that a website should labeled as secure in that instance, but we assumed that SiteLock had at least\u00a0provided a private warning that the website was in need of an update. But according to our client they never heard anything from SiteLock about the issue. This is surprising considering it is something that service is supposed to be providing. On the homepage of their website they start the description of their services as\u00a0&#8220;We scan your website to find and fix existing malware and vulnerabilities &#8220;. On the page about the service they\u00a0<a href=\"https:\/\/www.sitelock.com\/how-it-works.php\">further\u00a0expand on that<\/a>:<\/p>\n<blockquote><p>Our scanners identify applications you have installed and which version you have. We compare that to industry and proprietary lists to determine the security of your installation. SiteLock&#8217;s comprehensive scanning eliminates reports of &#8220;false positives&#8221; that are not truly dangerous to your business. If we discover a vulnerability in our testing, we report it to you immediately and can help you upgrade your application version and secure your site.<\/p><\/blockquote>\n<p>How did SiteLock miss that the website is running such outdated software? It is not because it is difficult to detect. If you have access to the website&#8217;s underlying files, which it appears SiteLock would have, then you can easily get the Magento version number from the file \/app\/Mage.php in Magento. Without access the underlying files you can still get the version number of Magento in use. One way to do that is with our <a href=\"https:\/\/chrome.google.com\/webstore\/detail\/magento-version-check\/aekpbnbbbgocohlbdpdfgghamedmplal\">Magento Version Check extension for Chrome<\/a>, which had no problem detecting the version in use on the website:<\/p>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/magento-version-check\/aekpbnbbbgocohlbdpdfgghamedmplal\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2126 size-full\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/magento-version-check.png\" alt=\"Magento Version Check\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/magento-version-check.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/magento-version-check-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>For anyone looking for a tool that will actually alert you when your websites are using outdated software our\u00a0<a href=\"https:\/\/chrome.google.com\/webstore\/detail\/up-to-date\/gfdibfaafmpljichhkbgbegfoinihnab\">Up to Date? app for Chrome<\/a> provides just that:<\/p>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/up-to-date\/gfdibfaafmpljichhkbgbegfoinihnab\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2129\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/up-to-date-magento-versions.png\" alt=\"Up to Date? app showing Magento verisons\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/up-to-date-magento-versions.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/up-to-date-magento-versions-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>As for the SiteLock service, you would better off using the money you would spend on their service on the <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">things that will actually keep your website secure<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to the security of websites what we see is a situation where basic security measures, like keeping software up to date, are not being taken and security companies, most of whom appear to have little interested in actually improving security, are selling security services that are really not needed. A good example &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/09\/03\/sitelock-fails-to-do-basic-security-check\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SiteLock Fails To Do Basic Security Check&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,34],"tags":[39],"class_list":["post-2122","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-magento","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2122"}],"version-history":[{"count":8,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2122\/revisions"}],"predecessor-version":[{"id":2135,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2122\/revisions\/2135"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}