Website attacked - Who's responsible?

Had one of our websites attacked with what looks like an sql injection attack. The web guys we've used are on to it but I wondered how common this is, whether it's the fault of the web guys we use or if these things are constantly developing so there's no real way to stop them. Can I expect a charge from them for this?
 

fisicx

Moderator
Sep 12, 2006
46,983
9
15,527
Aldershot
www.aerin.co.uk
If the site security was tight then the SQL attack should have been thwarted (unless they really were after your blood).

Nothing is foolproof but I'd check your contact forms, search feature and so on to make sure they validate for scripts and code.

So if it really was a nasty you may have to pay. If it is their sloppy coding then they should be paying you.
 
  • Like
Reactions: matt.chatterley
Upvote 0

fisicx

Moderator
Sep 12, 2006
46,983
9
15,527
Aldershot
www.aerin.co.uk
What a load of cod.

All you need is a decent cleansing system on your forms and anything that looks like code will get deleted. Ask them what validation they hove got set up.

If you have FTP access then you can get the code yourself.

If you haven't got FTP access then ask why, it's your site so you should be in charge of the files.

The people who attacked oyur site aren't hard core hackers. All they are doing is sending out a bot to see if you are vunerable. The bots usually aren't that sophisticated and a halfway decent validation systme will stop them in their tracks.
 
Last edited:
Upvote 0
it depends how it has happened...
no web company is going to give a 100% guarantee against hacking (or if they do it will be expensive!) when you see the CIA / FBI / White House websites hacked you realise that if anyone has the incentive to be proof against hackers it is them, yet they are not...

in reality hackers have far more time / resources / etc. and all they need is a simple exploit...

however there are certain obvious and simple things that should be in place - so if a site is hacked because of the basics then it would be the responsibility of the web company to replace it - unless the reason the more sophisticated code was not in place was the client cutting corners to start with...

a web company should have backups (as should you!) so putting back is not difficult, finding the reason and fixing it takes a bit more time...

if they want to charge you ask them for a break-down of what they have done and why it is chargeable (it may be valid / may not) I am sure that others can then advise you whether that is reasonable...

if they don't charge you - still ask them - all website owners should play a part in taking responsibility for their websites - it is your business...

Alasdair
 
Upvote 0
Suppose it's just the complexity of how it has happened that is confusing me. If I've got to get a third party to look into it for me obviously I'm going to incur extra costs as well as potentially any costs from the web developers looking at it now. What is common practice amongst web design businesses? Do you have a duty of care for any website you build and if so over what period would this last?
 
Upvote 0

stugster

Free Member
Feb 1, 2007
9,060
2,076
Edinburgh, UK
considerit.com
From a web-hosts point of view, they will be liable up to a point. If the hack has originated from your own code (through not updating your CMS system, or vulnerabilities) the web host cannot possibly be held accountable.

However, if it's a result of their negligence in securing the server, then yes, they'd probably be the ones that would fix it (and they shouldn't charge for that).

It's unlikely to be the webhost being negligent though.
 
Upvote 0
Suppose it's just the complexity of how it has happened that is confusing me. If I've got to get a third party to look into it for me obviously I'm going to incur extra costs as well as potentially any costs from the web developers looking at it now. What is common practice amongst web design businesses? Do you have a duty of care for any website you build and if so over what period would this last?

In short no.

They built you a website and that website should be secure when they hand it over to you which presumably it was.

But exploits are discoverd every day so if they made your website on 'application v1' last year and 'application v2' was released this year because a number of bugs were found in version 1 then it is not really their responsibilty to inform you of this. Unless your paying some sort of maintenance contract.

It is impossible to future proof a website in the same way as it is impossible to make it 100% secure. For all you know, your personal computer was compromised, you connected to the website via ftp and put the virus there yourself (unintentionaly).

This happens to pretty much every online business at some point. There are a worrying amount of people and scripts that are dedicated to comprimising websites. Sooner or later one will get through and when they do you'll have to deal with it. As mentioned, the website is your responsibility unless you are paying someone to make it theres.

Hope that helps, and I hope you get it all sorted.
 
Last edited by a moderator:
Upvote 0
I can totally understand that what is secure one day might not be another but at the same time I need to be sure that what I initially got was of a satisfactory standard. Looks like I'll just have to wait and see what the bill is and see where I go from there. Realistically though from what everyone is saying even after I've had the site fixed it could happen again?
 
Upvote 0
Realistically though from what everyone is saying even after I've had the site fixed it could happen again?

Quite possibly. Once they have fixed the issue and removed any problem code, I would do the following:

1) Scan you personal computer using a good virus checker. If it spots anything, remove it and scan again to make sure.

2) Then log into your websites control panels and change all the passwords. Make them something good (e.g. jh38ehrkejfws9) that is not going to be guessable, don't use dictionary words. Maybe download something like Keypass, http://keepass.info/ to keep all your passwords safe so you don't have to remember them. Passwords I would change are: FTP, CMS password and Hosting Control Panel password (if you have one). If you can't do this yourself, ask your develoer to do it for you.

3) Find out what applications your website uses and make sure you are using the latest version of each. If not have them updated (I would take advice from your developer on this to make sure nothing breaks during the update).

4) Contact your hosting company and get them to restrict FTP access and access to your various control panels to your IP. This means that only someone connectoing from your computer will get to the panel, everyone else will see a blank screen.

Essentially if you follow all the above it will make things very difficult for anyone wanting to compromise your website. Very little you can do to make it impossible but that should keep you secure. Hope that all helps (and makes sense :))
 
Last edited by a moderator:
  • Like
Reactions: inphozone
Upvote 0
Suppose it's just the complexity of how it has happened that is confusing me. If I've got to get a third party to look into it for me obviously I'm going to incur extra costs as well as potentially any costs from the web developers looking at it now. What is common practice amongst web design businesses? Do you have a duty of care for any website you build and if so over what period would this last?

If you have their written reasons - then (while you might not wish to post them in public) a quick glance by most web companies will know whether their are ont he straight or talking tosh ;) can't imagine any charge for 30 seconds look!

There is no common practice - some web companies will have you on a maintenance contract which would cover this, others don't and charge for their time; some would consider this their responsibility, others would not...

to be fair and impartial on this you need to consider several things and amongst that would be - what was your original requirement / spec.?

If you initially went for a cheap website based on price, then don't expect the service - if you spent more then you might reasonably expect more service...

I would talk it through with them and make a judgement based on how you feel they are treating you...

as an analogy:

you buy a car from a dealer...
you may or may not have a warranty / AA cover / etc.
a thief breaks in, smashing a window / stealing the radio...

whose fault?

if the car's security system was faulty - then the dealer might be liable - otherwise, bad luck - the fault is the thief's...

Alasdair
 
Upvote 0
Quite possibly. Once they have fixed the issue and removed any problem code, I would do the following:

1) Scan you personal computer using a good virus checker. If it spots anything, remove it and scan again to make sure.

2) Then log into your websites control panels and change all the passwords. Make them something good (e.g. jh38ehrkejfws9) that is not going to be guessable, don't use dictionary words. Maybe download something like Keypass, http://keepass.info/ to keep all your passwords safe so you don't have to remember them. Passwords I would change are: FTP, CMS password and Hosting Control Panel password (if you have one). If you can't do this yourself, ask your develoer to do it for you.

3) Find out what applications your website uses and make sure you are using the latest version of each. If not have them updated (I would take advice from your developer on this to make sure nothing breaks during the update).

4) Contact your hosting company and get them to restrict FTP access and access to your various control panels to your IP. This means that only someone connectoing from your computer will get to the panel, everyone else will see a blank screen.

Essentially if you follow all the above it will make things very difficult for anyone wanting to compromise your website. Very little you can do to make it impossible but that should keep you secure. Hope that all helps (and makes sense :))


I wouldn't disagree with this advice ;) but it is not sufficient - most websites are not compromised through someone knowing an FTP password - why bother when there are many more doors open!

biggest issue is vulnerable forms - when there is a form such as a contact form which is then processed there is code you can put into it which will process and then give access...

insecure code (i.e. responsibility of the web company) is the biggest issue...

but as mentioned above there are options to protect against this...

Alasdair
 
Upvote 0

rachelandrew

Free Member
Jun 15, 2005
10
3
If this is SQL Injection then some code on your website is at fault. Are there any open source or other third party scripts on the site, and if so are they bang up to date (out of date WordPress, PHPbb etc. are often the culprits)? If you have third party code running make sure you know whose responsibility it is to update it.

If this is all custom code from your web development agency then I would be pushing for them to fix it. Anyone selling services as a web developer should know and understand basic security issues such as this. I would be mortified if this had happened to a client of ours and would not think to charge them, I'd just want to get a fix deployed as soon as possible.

I would say the only exception that would be if the attack could be shown to be something very new - that your developers could not be expected to know about.

As a couple of people have mentioned it is also possible that the attack is the fault of the hosting company. I've cleaned up a few instances where the compromise was via insecure control panel software provided by the host. Searching Google with your hosting company name will likely show if anyone else has had the same problem. If there are people on the same host, with the same issue then I would be asking questions of the host as well. Hosting companies will invariably tell you your code is at fault, which is why it is worth seeing if you can find other people with the same problem.
 
Upvote 0

mit74

Free Member
Jun 4, 2010
2,463
447
The web guys we've used are on to it but I wondered how common this is?

Very common. Every website I've had that used logins, forums or mysql has been hacked or attempted hack at some point with open source websites being more vulnerable only because the code is in the public domiain. What I suggest, although may be little use to you if you can't code, is that you always add your own code into open source just to throw attackers off for extra security.

This is a good example of how using open source and functionality that isn't needed can be exploited:
A few years ago I had an ecommerce site hacked after the open source code was found to have an exploit where a user could use the automated 'forgotten password' function to gain admin control over the site. They used it to setup a fake bank website (phising). The E-Commerce site was a very low-functioning, low customer base site with only maybe 1-2 sales per week. Did it need an automated system for forgetting password? No. The site being as it was could have easily used a system where the admin could be emailed first and they ok the password request first.
Probably not relevant to your site but small details like this should be taken into account with regards to security.
 
Upvote 0
M

matt.chatterley

Had one of our websites attacked with what looks like an sql injection attack. The web guys we've used are on to it but I wondered how common this is, whether it's the fault of the web guys we use or if these things are constantly developing so there's no real way to stop them. Can I expect a charge from them for this?

This is a topic which pops up from time to time - in particular SQL injection, but also various other types of attack.

They're far more common than you think - but some types (including SQL injection) are not really that drastic these days - at least, as other posters have commented, if your site copes with them or at least has appropriate low-level safety built in so that at the very worst it shows an error to the attacker - but no harm is done to the site itself.

I blogged about this in March last year on the Mattched IT Blog - nothing revolutionary there but a good chance to wave it around ;)

A lot of attacks seem to originate from China recently and are automated - they literally scroll through lists of websites with a program to see if basic opening gambits work on any of them - and if so they will (presumably) follow up by hand.

Re: Liability, cost, etc - if the developer didn't allow for basic security, I'd say they should be fixing the issues which have been exposed in their site - it might be that the situation is more complex than this but they should at least offer an explanation - I wouldn't expect them to charge you for any investigation as theres a chance they are at fault.

Your host is unlikely to be liable, assuming it's an issue with the site itself.

Sadly these things do happen and we all need to take (at least basic) precautions - that said - advising you on what precautions to take is something your developer should have done from day one!
 
Upvote 0

OpenSure

Free Member
Apr 1, 2010
156
18
Herefordshire
Such attacks often have as many causes or weaknesses as there are opinions from interested parties, but our 2 pennies worth would be:

1) Open source scripts tend to get fixed and updated quickly and have a fast effective distribution model so although they are not exempt from weakness they do tend to be updated by most competent hosting companies. The best OSS is tracked and controlled in an open way with good standards at the core which make code maintenance much better managed.

2) Web design shops small or large that have put together a cheap in house solution for price sensitive customers rarely consider long term support issues and wont notify you of updates. Often scripts are pulled out of a heap and deployed with no forward tracking and no real documentation. Unless you really know what you were sold, you will probably have to pay for specialist support or site redesign.

3) Web hosts provide an environment for your site hosting which may include approved scripts, script languages etc or just a basic OS platform. If any of that is at fault whole tranches of sites will be hit, check the forums or other sites for stories and news of similar attacks.

4) If you have purchased licenses ensure you update them and maintain a subscription to updates and upgrades. Always apply security updates but beware these do sometimes break functionality that was poorly designed. If the updates stop coming then change the software.

5) If you have open source software ensure the project is properly supported and take updates regularly. If a project ends or stops issuing security updates plan a move to something else.

My one plea would be for businesses to stop thinking so much about price and consider cost more. Most businesses forget that the real cost of a website is maintenance and support not hosting or bandwidth.

A website is for life not just for Christmas ;-)
 
Upvote 0
If you have FTP access check the root file permissions. If you notice a file permission being set to "777" then this is a writeable file permission and poses a security as code can be injected by bots.

It would also be worth changing the FTP password in case it was a dictionary attack, this would of course only apply to relatively weak FTP passwords.

Kind Regards,

Craig
 
Upvote 0

Dominic Taylor

Free Member
Jun 19, 2008
1,173
254
Bath
I wouldn't disagree with this advice ;) but it is not sufficient - most websites are not compromised through someone knowing an FTP password - why bother when there are many more doors open!
True though you'd be surprised...one evening we had one server blocking hundreds of bots which were abusing an account for which they'd somehow gained the FTP login.

Distributed FTP login monitoring/blocking took care of it but my notifications went a little beserk!
 
Upvote 0
T

TailorMade

You have had lots of good responses, given the limited info you supplied. I can wholeheartedly recommend Heart Internet if you do look for a new hosting environment. When sites I have developed which use open source solutions have been compromised in the past they have notified me and disabled the site until the problem was resolved. They are proactive in providing tips to prevent future problems and they offer good security on FTP with auto-locking or access only by designated ip address. If you want to cast a wider net - then try http://www.whoishostingthis.com its a site done by a client of mine and includes listings and customer reviews of hundreds of web-hosts.
 
Upvote 0

Latest Articles

Join UK Business Forums for free business advice