I just returned from the HostingCon conference in Los Angeles. The keynote speech was an impressive presentation by Kevin Mitnick, the renowned hacker. It was a fascinating presentation, including gems like finding the social security number of a random audience member. It took him 90 seconds to find that, his mother’s maiden name, phone numbers, addresses and more. However, my key take away is that social engineering is the number one Magento exploit. Security experts report 100% success rates in penetrating companies if they use social engineering. And, it’s something you can easily protect your site from.
What is Social Engineering
According to WebRoot, social engineering is “the art of manipulating people so they give up confidential info. The types of info these criminals are seeking can vary, but when individuals are targeted the criminals are usually trying to trick you into giving them your passwords or bank info, or access your computer to secretly install malicious software–that will give them access to your passwords and bank infor as well as giving them control over your computer.”
Our clients rely on Web 2 Market to secure their sites because Web 2 Market Magento hosting and AbleCommerce hosting are PCI compliant. Our coding follows best practices to protect our clients’ sites from hackers. We’ve had tremendous success keeping the bad guys out. Nevertheless, that can all be undone by your warehouse employee or office staff being easily duped by a hacker with bad intentions. The good news is that protecting yourself involves a few simple good practices.
Here are a few examples to look out for:
- Emails that ask for personal info, like names, addresses, passwords and logins. The hacker then uses this info to gain further access to your systems.
- Emails that provide link to a domain name LIKE a legitimate domain name. For example, Ebayrewards.com. Or links using domain shorteners like bit.ly. These links send you to malicious sites where you can be tricked into providing systems info.
- Phone calls from someone posing to be from AT&T, or Web 2 Market, or your bank. The hacker tricks you into providing private data.
- Offers of free software from unverified sources. The software gathers keystrokes, account info or even uses your computer’s camera to spy on you.
- Finally, memory sticks or DVDs found lying on the ground. These can contain malicious code whch hack your system automatically, as a result.
How do I Protect Against this kind of AbleCommerce or Magento Exploit?
The solutions are fairly easy. The trick is to follow them religiously. When you’re busy, it’s easy to skip the right process. But that’s what hackers are counting on. Don’t help them!
- Don’t trust email from people you don’t know. And even if it seems to be from someone you know, don’t send sensitive info via email.
- If an offer seems to be to good to be true, it probably isn’t a good offer.
- Don’t open attachments from untrusted sources, even if it seems OK.
- If in doubt, check the identity of a phone caller, or the person sending you an email.
- Install antivirus software. There are many good, free software packages, like AVG. Virus will consequently not be able to share your system info.
In conclusion, protecting your self against a Magento exploit like hackers, phishing attacks and spammers doesn’t need to be hard. Think before you act. Follow good practices. Use common sense. And if you’re not sure, contact us and we’ll be glad to help.