Knowledgebase

How Sites Actually Get Compromised Print

  • websitesecurityfundamentals, website, hacked, uploads, security, password, plugins, themes
  • 0

The common routes.

OUT-OF-DATE SOFTWARE

The most common by a wide margin.

A vulnerability is published, attackers scan for the vulnerable version, and exploit it within hours.

OUT-OF-DATE PLUGINS AND THEMES

More common than core software, which usually updates reliably.

WEAK OR REUSED PASSWORDS

Guessed, or taken from a breach elsewhere.

NULLED OR PIRATED SOFTWARE

Frequently contains injected code deliberately.

COMPROMISED CREDENTIALS

Stolen from an infected computer, or from an insecure connection.

ABANDONED INSTALLATIONS

An old application in a subdirectory nobody remembers, never updated.

UPLOAD FORMS

Files uploaded and then executed.

WHAT THESE HAVE IN COMMON

Something out of date, or something exposed that should not be.

Neither is exotic.

WHAT THIS MEANS

Most compromises are preventable with routine maintenance.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot