{"id":3001,"date":"2016-11-01T10:48:09","date_gmt":"2016-11-01T16:48:09","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=3001"},"modified":"2016-11-01T10:48:09","modified_gmt":"2016-11-01T16:48:09","slug":"high-profile-cyber-security-company-crowdstrike-fails-to-do-basic-security-step-with-their-own-website","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/01\/high-profile-cyber-security-company-crowdstrike-fails-to-do-basic-security-step-with-their-own-website\/","title":{"rendered":"High Profile Cyber Security Company CrowdStrike Fails To Do Basic Security Step With Their Own Website"},"content":{"rendered":"<p>When it comes to security companies we often say that they many of them don&#8217;t know and or care about security, which we think explains a lot of why security is in such bad shape these days. One example that we often find of this is that these companies are failing do the <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">basics when it comes to the security of their own websites<\/a>. We recently looked at one cyber security company that claims to have \u201cclients in the intelligence community,\u00a0DoD\u00a0and nearly every cabinet agency\u201d and <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/10\/10\/cyber-security-companys-poor-website-security-reminder-of-industrys-lack-of-focus-on-actually-improving-security\/\">isn\u2019t bothering to keep the software running the various parts of their website up to date while telling the public they need to take advanced measure to protect their websites<\/a>. They are not the only cyber security that has failed to that.<\/p>\n<p>CrowdStrike was recently in the news due to their investigating the security breach at the Democratic National Committee (DNC) and placing the blame for it on the Russia government. They offer a variety of products and services intended prevent security breaches and respond after them. They also happen to be running an outdated and insecure version of WordPress on the main portion of their website:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3003 size-full\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-website-outdated-wordpress-version.png\" alt=\"The CrowdStrike Website is Running WordPress Version 4.5.2\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-website-outdated-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-website-outdated-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>The <a href=\"https:\/\/www.crowdstrike.com\/blog\/\">blog section of their website<\/a> is running an even older version:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3004\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-blog-outdated-wordpress-version.png\" alt=\"The CrowdStrike Blog is Running WordPress Version 4.5\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-blog-outdated-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/crowdstrike-blog-outdated-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>Like the previous case what makes is particularly troubling is that they are not just running an outdated major version of WordPress, v<a href=\"https:\/\/wordpress.org\/news\/2016\/08\/pepper\/\">ersion 4.6 was released in August<\/a>, but they are not running the latest version of 4.5, 4.5.4. That isn&#8217;t normal, as back in WordPress 3.7 <a href=\"https:\/\/codex.wordpress.org\/Configuring_Automatic_Background_Updates\">a new update system<\/a> was introduced so that minor updates normally happen automatically. So either CrowdStrike disabled those automatic updates (which isn&#8217;t a good idea) and then failed to apply the updates manually or their is some incompatibility between their hosting environment and the update system and they also failed to apply the updates manually. If it was the later, then they could actually help improve security by working with the WordPress developers fix whatever is causing those automatic updates to no happen.<\/p>\n<p>Whichever is the case, the end result is that they have multiple known vulnerabilities on their website, as WordPress <a href=\"https:\/\/codex.wordpress.org\/Version_4.5.2\">4.5.2<\/a>, <a href=\"https:\/\/codex.wordpress.org\/Version_4.5.3\">4.5.3<\/a>, and <a href=\"https:\/\/codex.wordpress.org\/Version_4.5.4\">4.5.4<\/a> all included security updates.<\/p>\n<p>The next question is whether this an aberration or if this is indicative of larger problems with handling and understanding of security at the company, which is something that companies looking to use\u00a0their products and services or journalist looking to cite them should probably find out.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to security companies we often say that they many of them don&#8217;t know and or care about security, which we think explains a lot of why security is in such bad shape these days. One example that we often find of this is that these companies are failing do the basics when &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/01\/high-profile-cyber-security-company-crowdstrike-fails-to-do-basic-security-step-with-their-own-website\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;High Profile Cyber Security Company CrowdStrike Fails To Do Basic Security Step With Their Own Website&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[96],"class_list":["post-3001","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-crowdstrike"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3001","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3001"}],"version-history":[{"count":2,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3001\/revisions"}],"predecessor-version":[{"id":3005,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3001\/revisions\/3005"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3001"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3001"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3001"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}