Big Data. Big Decisions
InformationWeek
Special Coverage Series


Tumblr Hack: 4 Security Reminders For SMBs

Following GNAA's defacing of several thousand Tumblr blogs, take these security reminders to heart -- especially if you use popular publishing platforms.

 9 Ways Skype Professional Network Helps SMBs
9 Ways Skype Professional Network Helps SMBs
(click image for larger view and for slideshow)
The ease and speed with which anyone with anyone can create a website these days can be a great thing, especially for smaller businesses short on resources or technical know-how. Unfortunately, those same benefits double as security risks.

That was on display Monday when the online troll group GNAA compromised the popular blogging platform Tumblr. Several thousand affected sites were taken over by a page that, to put it mildly, was not safe for work. Tumblr acknowledged the breach on Twitter. It announced later in the day that the problem, which Tumblr said affected "a few thousand" accounts, had been resolved.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"We quickly identified the source, removed the posts, and restored service to normal," the company said on its own Tumblr blog. "No accounts have been compromised, and you don't need to take any further action."

[ Cybercrooks don't necessarily just follow the money. Read more at How Cybercriminals Choose Their Targets. ]

The security firm Sophos attributed the breach to a fast-spreading worm. Any Tumblr users who visited an infected site while logged in immediately and unknowingly re-blogged the worm. In essence, the worm made use of one of the features that has made Tumblr a hit: the ease with which users can share and re-share content.

That's among the reasons Tumblr makes an attractive target for hackers, trolls, and the like: Plenty of people -- to the tune of 170 million -- love it. That also means plenty of SMBs use it for marketing, customer service, microsites, or even as a full-blown Web presence. The same can be said of other low-cost, easy-to-use publishing platforms such as WordPress, Blogger, and others.

Whether you use Tumblr or not, here are four timely website security reminders.

1. Check your code.

Most website security problems start with the underlying source code. That appears to be the case in Monday's breach, according to Sophos' technical breakdown of the Tumblr worm. Code vulnerabilities can lead to malware, SQL injections, and other security exploits. Whether you write your own code, use someone else's, or manage a combination of both, don't simply trust that it's all safe and secure.

Give your code a regular checkup. Start with your Internet service provider or website host; ask what vulnerability testing and monitoring services they provide. It's possible such services are included as part of your existing agreement. If not, there are loads of security vendors out there who would be glad to take care of this for you, often in automated behind-the scenes fashion -- so long as you can pay their asking price.

For SMBs on a small budget -- or a nonexistent one -- there are free tools out there that can help. Netsparker offers a free community edition of its Web application security software, for example, that scans for SQL injections. (It also offers a free trial of its more robust paid edition.) Google's Webmaster Tools also offers site checkups for malware and other potential problems, as well as help with remediating known problems. The latter is a must to ensure your site stays off Google and browser blacklists in the wake of an incident.

2. Stay current on software.

Just as you stay on top of Windows updates, Adobe patches, Web browser versions, and other important downloads, you should stay current with any website publishing platforms you use. WordPress is a good example -- the wildly popular content management system regularly releases new versions, in part to fix security issues and other bugs. Yet 55% of WordPress sites are running an older version of the software. One reason that can cause problems: The release notes for new versions typically announce the security flaws in the previous versions -- something hackers can use to exploit sites that don't stay up to date.

3. Kill old sites.

Did you start that corporate blog with the best of intentions, only to let it languish in the great Internet desert of forgotten sites? Consider deleting it altogether unless you've got a good business reason to keep it up. "Dead" blogs and other mothballed websites make nice targets for hackers, since they're often running on outdated code or publishing platforms. (If you've stopped updating your blog, you've probably stopped updating its publishing tool, too.)

Even if the forgotten site doesn't necessarily provide a back door into more valuable targets, it can pose the risk of embarrassment and reputation harm -- such as attacks that plaster racist or obscene language across the page. You likewise don't want sites or pages associated with your business unwittingly hosting porn, malware, spambots, or other potentially damaging stuff.

Any Web application is inherently a threat vector, to use security industry lingo. There's no sense in maintaining threat vectors that no longer provide any business value. Eliminate unnecessary risks.

4. Use minor incidents to better defend against major ones.

Monday's security breach was somewhat embarrassing for Tumblr. It was certainly a disruption -- albeit a brief one -- for the several thousand affected sites. But the bottom-line impact was more akin to online vandalism than the types of security issues that lead to bank account losses and other lasting consequences. It wasn't the first incident of its kind; it won't be the last.

That's not to say you should take such cases lightly. Rather, use them as reminders to safeguard your valuable business assets. Assess and prioritize your security risks and act accordingly. Use common sense and good basic security practices, such as strong passwords. Don't be an easy mark for criminals, hacktivists, or people who wreak online havoc just because they can.

Small and midsize businesses are falling prey to cyberattacks that cost them sensitive data, productivity and corporate accounts cleaned out by sophisticated banking Trojans. SMBs are typically on the hook for these losses and lack effective means to prevent them. Our Small Businesses, Big Losses report explains what makes these threats so menacing and shares best practices to defend against them. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.