{"id":3016,"date":"2016-11-07T14:12:40","date_gmt":"2016-11-07T21:12:40","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=3016"},"modified":"2016-11-07T14:12:40","modified_gmt":"2016-11-07T21:12:40","slug":"looking-at-how-sitelock-sells-their-services-versus-the-reality-behind-them","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/07\/looking-at-how-sitelock-sells-their-services-versus-the-reality-behind-them\/","title":{"rendered":"Looking At How SiteLock Sells Their Services Versus the Reality Behind Them"},"content":{"rendered":"<p>We recently have been taking a close look at the\u00a0practices of the web security SiteLock after finding that not only were they providing poor quality services (as is par for the course for web security companies), but a lot of what they look to be doing<a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/05\/03\/it-looks-like-sitelock-is-scamming-people\/\"> falls more closely to outright scamming<\/a>. We thought it would be useful to show how some of what we have found comes in to play to their interactions with a customer. To do that lets look at a <a href=\"http:\/\/www.naminnesota.org\/index.php\/regional-service-mnrsc\/na-minnesota-services\/malware-protection\">recent complaint from one of SiteLock&#8217;s customers<\/a> that hits on a number of issues with what SiteLock is doing.<\/p>\n<p>After their website had been hacked in February of last year SiteLock sold them on one of their services:<\/p>\n<blockquote><p>[L]ast February we purchased \u201cSiteLock Premium\u201d for $500\/year. I was told this was the best security product available. With it, I would have a firewall that would prevent any further attacks.\u00a0 And since it runs \u201cin the cloud\u201d it would actually make our site faster. We were assured that SiteLock has never been hacked and even if we are hacked, our site would be cleaned.<\/p><\/blockquote>\n<p>There are a number of issues we see with that.<\/p>\n<p>We are not sure how SiteLock&#8217;s website never being hacked (if that were even true) would mean that their customer&#8217;s website wouldn&#8217;t be hacked, but that would seem to require the same practices being done on both, but that isn&#8217;t the case as we will get to in a later in the post.<\/p>\n<p>Then there is the issue that as best we can tell <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/11\/02\/is-sitelock-lying-about-patent-pending-technology-and-the-true-source-of-some-of-their-services\/\">SiteLock&#8217;s web application firewall (WAF) isn&#8217;t actually their own, instead there are reselling\u00a0Incapsula&#8217;s WAF service<\/a>. That raises several issues. One is that SiteLock promotes the service as if they are providing it, if they would lie about that, you can reasonably wonder what else they are not being honest about. Since the service involves sending the website&#8217;s traffic through the CDN, that means all the traffic is flowing through a company the SiteLock&#8217;s customers are not even aware of, much less have a relationship with. Finally you have to wonder if SiteLock is even aware of how good or bad the WAF is at protecting against attacks, since it isn&#8217;t actually something they run.<\/p>\n<p>Another serious issue is that SiteLock failed to do a basic part of a proper hack cleanup, making sure that they software is brought up to date. In this case the website is still using Joomla 2.5:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3026\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-secured-website-outdated-joomla.png\" alt=\"A Website That Is Supposed to be Secured by SiteLock is Still Running Joomla 2.5.28\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-secured-website-outdated-joomla.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-secured-website-outdated-joomla-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>That version of Joomla <a href=\"https:\/\/docs.joomla.org\/Joomla!_CMS_versions\">reached end of life on December 31, 2014<\/a>\u00a0and therefore was not receiving further security updates. So any cleanup in 2015 should have included upgrading to a supported version of Joomla. (It is important to note that SiteLock is certainly not alone in doing this important part of hack cleanup, many providers cut corners like this.)<\/p>\n<p>By comparison SiteLock does keep their website up to date. Both their blog and their WordPress focused sub-domain, wpdistrict.sitelock.com, are using the latest version of WordPress:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3028\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-blog-wordpress-version.png\" alt=\"The SiteLock Blog is Running WordPress Version 4.6.1\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-blog-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-blog-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3029\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-the-district-wordpress-version.png\" alt=\"SiteLock's The District Website is Running WordPress Version 4.6.1\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-the-district-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/11\/sitelock-the-district-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>Keeping the software running your website up to date is going to provide real protection, whereas other security services may not (we haven&#8217;t seen SiteLock present any evidence that their services provide better protection then <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">doing the security basics<\/a>). Its telling that SiteLock does that for their own website, but doesn&#8217;t for\u00a0their customers.<\/p>\n<h2>More Money<\/h2>\n<p>One of the things we frequently see brought up with SiteLock is after purchasing one security services that was supposed to protect the website and then doesn&#8217;t, they want to sell your more expensive services (that was even <a href=\"https:\/\/web.archive.org\/web\/20161025054837\/http:\/\/diymarketers.com\/website-hacked-attacked\/\">mentioned by someone who praising their service<\/a>\u00a0(and then deleted their post for some reason)). Remember that this person was sold a $500 a year plan that they say SiteLock claimed was the &#8220;best security product available&#8221;, then the website got hacked again and they are pushing a $720 a year plan:<\/p>\n<blockquote><p>We were recently informed by SiteLock that our site had sustained a Pharma attack that had inserted links directly into our code. This attack could not be automatically cleaned their software could not remove the malware systematically without risking bringing down our site. The SiteLock technician suggested that we purchase their \u201cInfinity Scan\u201d product for $60 \/month.\u00a0 That product includes manual cleaning of our site.<\/p><\/blockquote>\n<p>Again there are multiple issues raised here.<\/p>\n<p>You can start with the fact that SiteLock makes a big deal about their automated malware removal in their marketing material, but\u00a0never mention that it can have the serious problem of taking down a website. It also seems to us that in an instance where it isn&#8217;t up to task they shouldn&#8217;t be charging extra to deal with the situation,\u00a0as it is unable to do what it is promoted to do (and considering their track record you would also have to wonder if they sometimes claim it couldn&#8217;t to get more money from people).<\/p>\n<p>The other troubling aspect of this is that they have a service that provides manual hack cleaning\u00a0on a repeated basis. If a website is properly cleaned then it shouldn&#8217;t get re-hacked, so unless you are not taking basic security measures or get unlucky and have get hacked thorough multiple zero-day vulnerabilities in a year you shouldn&#8217;t need multiple cleanups in one year. The fact that they provide this would be a red-flag on it own that they don&#8217;t do proper hack cleanups, but we already <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/14\/godaddy-and-sitelock-make-a-mess-of-a-hack-cleanup-and-drop-the-ball-on-security-as-well\/\">knew that SiteLock doesn&#8217;t proper clean up hacked websites<\/a>, so you don&#8217;t have to wonder about that.<\/p>\n<p>What would seems to have happened here seems to be another example of that. So how did SiteLock explain how the\u00a0website was hacked again after they were brought in:<\/p>\n<blockquote><p>Now, after we\u2019ve been hacked yet again, I find out that is not true. SiteLock assures me that everything is set up correctly, and that the hacker must have a back door access point.\u00a0 They don\u2019t cover that. Bluehost doesn\u2019t cover that. I\u2019m screwed.<\/p><\/blockquote>\n<p>The backdoor access must have either existed when SiteLock was first brought in to deal with the website and should have been handle during the cleanup or was\u00a0gained after the were supposed to protecting the website. In either case we don&#8217;t understand how that wouldn&#8217;t be on them. The explanation seems to be that since things were set up correctly it couldn&#8217;t be their fault, which doesn&#8217;t make any sense to us.<\/p>\n<p>Also worth noting here is that their web host, Bluehost, who\u00a0pushes\u00a0SiteLock services as one of their &#8220;partners&#8221;, is <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/08\/one-of-sitelocks-owners-is-also-the-ceo-of-many-of-the-companys-web-hosting-partners\/\">ultimately run by the owners of SiteLock<\/a>\u00a0and looks to be getting a <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/09\/sitelock-hosting-partner-gets-majority-of-fees-for-sitelock-services\/\">majority of the money from services sold through their partnership<\/a> (which explains the high price of SiteLock&#8217;s services and the low quality for the amount paid). That isn&#8217;t something they publicly disclose and something that one of the other web hosting owned by the same company, Hostgator, <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/10\/11\/hostgator-is-actively-hiding-the-true-nature-of-their-partnership-with-sitelock\/\">wouldn&#8217;t even acknowledge<\/a> is after it was pointed out those facts were coming from their parent company.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently have been taking a close look at the\u00a0practices of the web security SiteLock after finding that not only were they providing poor quality services (as is par for the course for web security companies), but a lot of what they look to be doing falls more closely to outright scamming. We thought it &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/07\/looking-at-how-sitelock-sells-their-services-versus-the-reality-behind-them\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Looking At How SiteLock Sells Their Services Versus the Reality Behind Them&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[77,39],"class_list":["post-3016","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-bluehost","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3016"}],"version-history":[{"count":6,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3016\/revisions"}],"predecessor-version":[{"id":3030,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3016\/revisions\/3030"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}