{"id":2892,"date":"2016-09-26T13:07:40","date_gmt":"2016-09-26T19:07:40","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2892"},"modified":"2016-09-26T13:07:40","modified_gmt":"2016-09-26T19:07:40","slug":"where-are-the-vulnerabilities-that-sitelocks-vulnerability-scanning-should-have-found","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/09\/26\/where-are-the-vulnerabilities-that-sitelocks-vulnerability-scanning-should-have-found\/","title":{"rendered":"Where Are The Vulnerabilities That SiteLock&#8217;s Vulnerability Scanning Should Have Found?"},"content":{"rendered":"<p>In looking over things for a possible future post about the web security company SiteLock we have noticed that one of the features\u00a0prominently promoted by its hosting <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/09\/sitelock-hosting-partner-gets-majority-of-fees-for-sitelock-services\/\">&#8220;partners&#8221;<\/a>\u00a0when selling\u00a0SiteLock&#8217;s\u00a0services is vulnerability scanning. For example, at HostGator, one of their hosting &#8220;partners&#8221; <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/08\/one-of-sitelocks-owners-is-also-the-ceo-of-many-of-the-companys-web-hosting-partners\/\">that is also run by the owners of SiteLock<\/a>, vulnerabilities scans of varying frequency are included in each package:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2905\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages.png\" alt=\"hostgator-sitelock-packages\" width=\"1200\" height=\"500\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages.png 1200w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages-300x125.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages-768x320.png 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-packages-1024x427.png 1024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>It also promoted on their\u00a0<a href=\"http:\/\/www.hostgator.com\/sitelock\">page for the services<\/a>\u00a0as helping to prevent hacks:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-prevent-hacks.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2906\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-prevent-hacks.png\" alt=\"Make WordPress More Secure Great news for WordPress users! SiteLock's firewall and vulnerability scans help prevent hacks and automated attacks on this ever-more popular publishing platform.\" width=\"560\" height=\"130\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-prevent-hacks.png 560w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/09\/hostgator-sitelock-prevent-hacks-300x70.png 300w\" sizes=\"auto, (max-width: 560px) 85vw, 560px\" \/><\/a><\/p>\n<p>What is missing on the &#8220;partners'&#8221; websites or SiteLock&#8217;s\u00a0as far as we can tell is any evidence on the claimed effectiveness of their vulnerability scanning.\u00a0Vulnerability scanning of the type that it appears\u00a0SiteLock does, doesn&#8217;t have a reputation for being of much value. In a <a href=\"http:\/\/securitee.org\/files\/seals_ccs2014.pdf\">study<\/a>\u00a0(PDF) from 2014 that looked at vulnerability scanners tied to security seals (SiteLock has one of those and its accuracy <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/02\/26\/sitelock-labels-website-as-secure-despite-being-very-dangerous-for-visitors\/\">has been poor<\/a> from what we <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2015\/03\/10\/sitelock-still-failing-to-do-basic-security-check\/\">have seen<\/a>), it was found that two of the 8 vulnerability scanners tested detected none of the vulnerabilities that existed on a website set up with a number of vulnerabilities, which\u00a0was due to those scanners using third party software that &#8220;are not meant to discover vulnerabilities in web applications&#8221;.\u00a0Five of the six remaining scanners only discovered a third or less of the vulnerabilities that existed.<\/p>\n<p>If their vulnerability scanner was in fact detecting vulnerabilities we would expect to have seen evidence of it elsewhere.\u00a0SiteLock <a href=\"https:\/\/wpdistrict.sitelock.com\/behind-the-scenes\/\">claims<\/a> that as of 2015 they were &#8220;serving over 1 million WordPress customers&#8221;. If there vulnerability scanning was actual effective we would expect that would have found quite a few vulnerabilities in plugins based on the number of vulnerabilities we\u00a0see being discovered in WordPress plugins while collecting data for our\u00a0<a href=\"https:\/\/www.pluginvulnerabilities.com\/\">Plugin Vulnerabilities<\/a> service. But we are only aware of <a href=\"https:\/\/wpdistrict.sitelock.com\/blog\/this-week-in-exploits-sitelock-research-teams-first-published-vuln-more-to-come\/\">two<\/a> <a href=\"https:\/\/wpdistrict.sitelock.com\/blog\/malicious-plugin-social-media-tab-removed-from-wordpress-org\/\">vulnerabilities<\/a> that they have discovered in recent times and both of those don&#8217;t appear to have been discovered during the running of their vulnerabilities scanner. By comparison over at the blog for our\u00a0Plugin Vulnerabilities service we have over 90 posts for <a href=\"https:\/\/www.pluginvulnerabilities.com\/category\/vulnerability-report\/\">vulnerabilities we have discovered this year<\/a>\u00a0(some of the post include multiple vulnerabilities, so the total number of vulnerabilities is even higher).\u00a0If their vulnerabilities scanner was discovering other vulnerabilities in plugins on website, even if SiteLock\u00a0were not aware of it, we would expect to see some mentions of that in changelogs of the impacted plugins or discussions of the vulnerabilities and yet what we haven&#8217;t seen any reference to their scanning having identified any\u00a0vulnerabilities and the vast majority of vulnerability disclosures and fixes we have reviewed can be traced back to a source that\u00a0wasn&#8217;t their scanner.<\/p>\n<p>Whether you are looking at SiteLock or another provider of\u00a0security services and products you should look for evidence from the provider that products can perform as claimed, as we\u00a0often see claims made that seem rather unbelievable and from some of the claims we have taken a look into\u00a0they\u00a0often turn out to be at least widely inaccurate.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In looking over things for a possible future post about the web security company SiteLock we have noticed that one of the features\u00a0prominently promoted by its hosting &#8220;partners&#8221;\u00a0when selling\u00a0SiteLock&#8217;s\u00a0services is vulnerability scanning. For example, at HostGator, one of their hosting &#8220;partners&#8221; that is also run by the owners of SiteLock, vulnerabilities scans of varying frequency &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/09\/26\/where-are-the-vulnerabilities-that-sitelocks-vulnerability-scanning-should-have-found\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Where Are The Vulnerabilities That SiteLock&#8217;s Vulnerability Scanning Should Have Found?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[39],"class_list":["post-2892","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2892"}],"version-history":[{"count":6,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2892\/revisions"}],"predecessor-version":[{"id":2908,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2892\/revisions\/2908"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}