HomeinetWordPress, Joomla or Drupal? CMS Security

WordPress, Joomla or Drupal? CMS Security

Over a third of all websites on the Internet are powered by one of these four major open source platforms: WordPress, Joomla, Drupal, and Magento.

This makes hackers' lives much easier, since they can simply focus on exploiting vulnerabilities in one of their platforms, or one of the most popular plugins and extensions they use.WordPress CMS

Sucuri, a security company focused on detecting online attacks and restoring compromised websites, recently released fresh statistics on hacked websites.

According to reports from the company's Incident Response Team and Malware Research Team, in the first quarter of this year, 78% of successful compromises were on WordPress websites. Websites using Joomla reached 14%, Magento 5%, and Drupal 2%.

E-commerce sites using Magento were hit with exploits that allowed remote code execution in February 2015, and an XSS hole that could lead to a breach of the online store in January 2016. Apparently, not all admins update their installations regularly.

In fact, Magento website administrators are the worst: 97% of Magento installations according to Sucuri experts during their cleanup were old versions. WordPress admins, on the other hand, were better, since “only” 56 percent of installations were on an older version:WordPress sucuri-cleanup-stats

“The top three software vulnerabilities affecting the most websites in the first quarter were through the RevSlider, GravityForms, and TimThumb plugins,” the researchers report.

“For all three of these plugins, there was a snapshot available for at least a year, while for TimThumb it existed many years ago (since 2011).

The problem with RevSlider, in particular, is that it's built into WP themes, and many of the platform's users don't even know they're using it.

Magento websites are commonly compromised by information leaks during customer visits.

For the remaining platforms, SEO Spam (31%, and this percentage continues to grow), drive-by-download infections (60%), hacking tools (exploits or DDoS tools), and phishing are commonly used. Defacements by hacktivists were rarely observed.

In two-thirds of cases, Sucuri's cleanup team discovered backdoors on websites, as attackers wanted to be sure they could still gain access after cleaning the hacked website.

“On average, we clean 132 files per hacked website,” the researchers report.

“This shows how deeply malware can be embedded within a website. This also explains why Google reports a 30% reinfection rate, a rate measured through webmaster tools.”

Here we should mention that WordPress sites, although they come first in terms of infection rate for us, can be considered the most reliable. As long as you are always on the latest updated version, of course.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS