Popular Posts
-
ASPHostPortal.com - The leader of ASP.NET hosting provider launches ASP.NET 4.6 hosting with fast network and fast support. New York, ...
-
I would like to bring another one of my skills to the table, WordPress baby! Starting with this post I will be covering the basics, doma...
-
Whenever a website is made you have to pay for the host and domain. There are different payment plans, sometimes every month and sometim...
-
danroo 6 hours ago Template 59 Views HostWHMCS is a Responsive Web Hosting and WHMCS Template designed for All kinds of Domain an...
-
I want to share something from the first chapter of my upcoming book Front-end Development with ASP.NET Core, Angular, and Bootstrap. Wh...
-
Web.com is set to purchase all the available shares of Yodle, closing at the end of the first quarter of 2016 Yodle, based in New York C...
-
Introduction I am writing this article as a result of my learning for deploying ASP.NET Core web applications on Linux boxes. There is a ...
-
Savvy E Hosting, a prolific web development solutions provider based in Singapore, is offering quality VPS hosting services to busi...
-
Doug Schneider of 2nd Watch 2nd Watch, which helps large organizations such as Crate & Barrel, Condé Nast, Coca-Cola North America a...
-
San Marino, CA — (SBWIRE) — 06/08/2016 — WP Engine was recently rated the top managed WordPress hosting provider in an extensive co...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Krebs on Security
In what's being billed as an unprecedented global law enforcement response to cybercrime, federal investigators in the United States, United Kingdom and Europe today say they've dismantled a sprawling cybercrime machine known as "Avalanche" — a distributed, cloud-hosting network that for the past seven years has been rented out to fraudsters for use in launching countless malware and phishing attacks.
The global distribution of servers used in the Avalanche crime machine. Source: Shadowserver.org
According to Europol, the action was the result of a four-year joint investigation between Europol, Eurojust the FBI and authorities in the U.K. and Germany that culminated on Nov. 30, 2016 with the arrest of five individuals, the seizure of 39 Web servers, and the sidelining of more than 830,000 web domains used in the scheme.
Built as a criminal cloud-hosting environment that was rented out to scammers, spammers other ne'er-do-wells, Avalanche has been a major source of cybercrime for years. In 2009, when investigators say the fraud network first opened for business, Avalanche was responsible for funneling roughly two-thirds of all phishing attacks aimed at stealing usernames and passwords for bank and e-commerce sites. By 2011, Avalanche was being heavily used by crooks to deploy banking Trojans.
The U.K.'s National Crime Agency (NCA), says the more recent Avalanche fraud network comprised up to 600 servers worldwide and was used to host as many as 800,000 web domains at a time.
"Cyber criminals rented the servers and through them launched and managed digital fraud campaigns, sending emails in bulk to infect computers with malware, ransomware and other malicious software that would steal users' bank details and other personal data," the NCA said in a statement released today on the takedown. The criminals used the stolen information for fraud or extortion. At its peak 17 different types of malware were hosted by the network, including major strains with names such as goznym, urlzone, pandabanker and loosemailsniffer.At least 500,000 computers around the world were infected and controlled by the Avalanche system on any given day."
The Avalanche network was especially resilient because it relied on a hosting method known as fast-flux, a kind of round-robin technique that lets botnets hide phishing and malware delivery sites behind an ever-changing network of compromised systems acting as proxies.
"The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action," Europol said in its statement.
It's worth noting here that Avalanche has for many years been heavily favored by crime gangs to deploy Zeus and SpyEye malware variants involved in cleaning out bank accounts for a large number of small to mid-sized businesses. These attacks relied heavily on so-called "money mules," people willingly or unwittingly recruited into helping fraudsters launder stolen funds.
At the time of the takedown, the Avalanche cybercrime infrastructure spanned more than 180 countries, according to The Shadowserver Foundation, a nonprofit group that helped authorities gain control over the Avalanche domains. Read more on Shadowserver's role in this effort here.

The Avalanche crime infrastructure. Image: Europol
Tags: Avalanche, double fast-flux, Eurojust, Europol, fbi, NCA, Shadowserver Foundation, U.K. National Crime Agency
This entry was posted on Thursday, December 1st, 2016 at 1:50 pm and is filed under Other. You can follow any comments to this entry through the RSS 2.0 feed. You can skip to the end and leave a comment. Pinging is currently not allowed.
Source: Krebs on Security
Website down!!!!
wedmfm.com is a wordpress.ORG software install on paid hosting, hosted by Bluehost, not by wordpress.COM. Contact your web host.
You are posting to the wrong support forum. That site is not on wordpress.COM servers and we cannot help with it.
This is wordpress.com support. We provide support only for wordpress.COM hosted sites. Our support docs do not apply to(1) local installs of wordpress.ORG software on your own server or(2) wordpress.ORG software installs on paid hosting, and we do not provide support for them at wordpress.COM.
Also, note that we do not provide Jetpack support https://jetpack.com/support/ for sites linked to wordpress.COM accounts with the Jetpack plugin so they display on the My Sites wordpress.com account page.
Some Jetpack solutions are here http://jetpack.com/support/
Others are in the Jetpack support forum at WordPress.orghttp://wordpress.org/support/plugin/jetpack
However, if help cannot be found at either one then they can file a Jetpack support ticket here > http://en.support.wordpress.com/contact/?jetpack=needs-service
WordPress.COM and WordPress.ORG are completely separate and have different username accounts, logins, features, run different versions of some themes with the same names, and have separate support documentation and separate support forums. Read the differences here http://en.support.wordpress.com/com-vs-org/
As you are referring to a site that is not hosted here, if you don't have a username account at WordPress.ORG account, then click http://wordpress.org/support/ and register one on the top right-hand corner of the page that opens, https://wordpress.org/support/register.php so you can post to the support forums there.Resetting your WordPress.ORG password http://codex.wordpress.org/Resetting_Your_PasswordWordPress.org support docs are at https://codex.wordpress.org/Main_PageSee also https://apps.wordpress.org/support/
Source: Website down!!!!
WordPress Will Only Recommend Hosting Companies Offering SSL by Default in 2017
In October, Let's Encrypt was managing more than 10 million active SSL certificates. That number doubled to 20 million in November as large providers continue to partner with the organization to manage their customers' certificates.
In 2014, Google announced that HTTPS is a ranking factor. Earlier this year, the Google Chrome security team announced that Chrome 56 will mark HTTP sites that transmit passwords or credit cards as insecure.

In 2017, managed WordPress hosting companies will have one more reason to enable SSL by default for new accounts. In a post on the WordPress.org blog, Matt Mullenweg, co-founder of the open source WordPress project, explains what the project is going to do to encourage HTTPS by default across the web.
"Early in 2017, we will only promote hosting partners that provide a SSL certificate by default in their accounts," Mullenweg said.
"Later we will begin to assess which features, such as API authentication, would benefit the most from SSL and make them only enabled when SSL is there."
Unrelated to SSL, Mullenweg also commented on the significant performance improvements in PHP7 and will consider whether hosting partners use PHP7 by default for new accounts in 2017.
These moves are a continued effort by Mullenweg to secure and encrypt as much of the web as possible. Earlier this year, WordPress.com encrypted all of its sites using Let's Encrypt.
Let's Encrypt is an initiative which aims to encrypt 100% of the web by making trusted certificates available to everyone at no cost. It's a 501(c)(3) nonprofit and recently launched a crowdfunding campaign to cover the cost of one month of operations totaling $200K.
Josh Aas, ISRG Executive Director, explains the reasons behind the crowdfunding campaign, "First, there is a gap between the funds we've raised and what we need for next year," Aas said.
"Second, we believe individual supporters from our community can come to represent a significant diversification of our annual revenue sources, in addition to corporate sponsorship and grants."
To learn more about the campaign and to contribute, visit Let's Encrypt's Indiegogo page.
Like this:Like Loading...
Related
Source: WordPress Will Only Recommend Hosting Companies Offering SSL by Default in 2017
How to Make a Great Writer Portfolio Website With WordPress
Looking for something to help kick start your next project?
Envato Market has a range of items for sale to help get you started.
PowerPoint Templates
From $4
Keynote Templates
From $4
Website Templates
From $4
Business Card Templates
From $2
Source: How to Make a Great Writer Portfolio Website With WordPress
Web Hosting Company Shuts Down Conservative Site Boycotting Target Stores
The conservative group 2ndVote has called for a boycott on Christmas shopping at the retail giant Target over its bathroom policies. But on Nov. 23, Leadpages, the company hosting the #AnywhereButTARGET boycott campaign's website, sent 2ndVote an email requesting the page be taken down.
In his email to 2ndVote, Leadpages' director of operations, Doug Storbeck, stated that the campaign website violated the company's terms of service, specifically, the portion prohibiting any content that is "hateful or discriminatory based on race, color, sex, religion, nationality, ethnic or national origin, marital status, disability, sexual orientation or age or is otherwise objectionable."
In his email to 2ndVote, Storbeck also wrote:
At Leadpages, we strive to create an inclusive workplace that upholds the dignity of all people. We value, respect, and celebrate everyone's individualities and honor their unique strengths from all different walks of life.
"Leadpages must have sensed our campaign was gaining momentum so they resorted to the typical liberal bully tactics of shutting down and censoring ideas they don't agree with and calling them 'hateful' or 'discriminatory,'" Robert Kuykendall, 2ndVote's director of communications, said in a statement. "Apparently, Leadpages wanted to use the cover of Thanksgiving Day thinking they could quietly make #AnywhereButTARGET disappear."
"Liberals who constantly tout tolerance and inclusion go out of their way to shut down ideas they disagree with" Lance Wray, executive director at 2ndVote, said in a statement. "To say our campaign is about inequality, intolerance, hate, discrimination, or devaluing anyone is flat wrong, it's about common sense and safety. But, some of the truest hate and intolerance we've seen has come from the liberal responses to our campaign."
After being shut down on Thanksgiving Day, the #AnywhereButTarget website is now back up. Target did not respond to a request for comment from The Daily Signal.
2ndVote has released a Christmas shopping guide for conservative buyers.
Source: Web Hosting Company Shuts Down Conservative Site Boycotting Target Stores