logo.png
Guided Website Threat Review

Foregenix Blog

Benjamin Hosack

Benj Hosack is a Director and co-Founder of Foregenix Limited. Foregenix is a specialist information security business delivering services in Forensics, PCI DSS, PCI P2PE, PA-DSS and information security solutions within the Payment Card Industry. Our technologies are designed to simplify security and PCI Compliance. Specialties: Cardholder Data Discovery - defining and reducing PCI DSS Scope / PA-DSS / PCI DSS / P2PE / Account Data Compromise Investigations. We are specialists in the Payment Card Industry and work with all types of companies in the payment chain (Acquiring banks, Processors, hosting providers, web designers, merchants, systems integrators etc).
Find me on:

Recent Posts

Benjamin Hosack

Magento Websites: How is the security health of your website?

web security, Magento, Cybersecurity

,10/07/17 16:40
Cyber security is a hot topic, with articles appearing most days within the mainstream media.   As consumers, we’re all becoming more cyber-aware as we see the latest well-known brand in the headlines for having lost their client data.

Most of us will have been affected by a credit card breach within the last few years - I can’t imagine there could be many people in first world countries who have not had their credit / debit card details stolen and received a replacement card from their bank. It's a major hassle - stressful and a huge waste of time.

Read More
Benjamin Hosack

Alert: New PHP Webshell Identified

web security, Magento

,03/03/17 11:50

A new piece of malware has been identified by the Foregenix DFIR team.  The malware is a PHP webshell - a script, which when installed on a compromised system, presents a sophisticated administration platform allowing the attacker to browse the filesystem of the compromised server, upload, create, edit, download or delete files or stop running processes.

Read More
Benjamin Hosack

Vulnerabilities on ManageEngine EventLog 10.7 through 11.2 (Service Pack 11023)

penetration testing

,23/12/16 11:29

We have come across Manage Engine EventLog installations a few times in our penetration tests at Foregenix, and have identified different vulnerabilities in our attempts to compromise it. In most situations a default guest account was left open and becomes a focus point as we attempt to use it to elevate privileges or otherwise influence the profiles behaviour to our advantage. These attempts resulted in the following vulnerabilities being discovered and reported to the vendor. While the installations encountered during the engagements may not be running an up-to-date version of the ManageEngine EventLog software we validated whether the vulnerabilities still exist on the latest version as of the time of reporting them to the Vendor.

Read More
Benjamin Hosack

Magento Malicious JavaScript in Action

web security, Magento, malware, JavaScript

,08/11/16 14:48

Magento websites have been under attack from a new malicious JavaScript family of malware - our forensic team has been working with many hacked websites to help them regain control of their online businesses and to limit losses.

Read More
Benjamin Hosack

Magento Websites - Have You Patched SUPEE-8788 Yet?

web security, Magento

,04/11/16 14:28

Last month Magento released SUPEE-8788 to fix a number of security issues – you can read about SUPEE-8788 in detail here.  A LOT of websites have not yet patched and are at risk of being hacked.

Read More

Benjamin Hosack

Benj Hosack is a Director and co-Founder of Foregenix Limited. Foregenix is a specialist information security business delivering services in Forensics, PCI DSS, PCI P2PE, PA-DSS and information security solutions within the Payment Card Industry. Our technologies are designed to simplify security and PCI Compliance. Specialties: Cardholder Data Discovery - defining and reducing PCI DSS Scope / PA-DSS / PCI DSS / P2PE / Account Data Compromise Investigations. We are specialists in the Payment Card Industry and work with all types of companies in the payment chain (Acquiring banks, Processors, hosting providers, web designers, merchants, systems integrators etc).
Find me on:

Recent Posts

Benjamin Hosack

Magento Websites: How is the security health of your website?

web security, Magento, Cybersecurity

,10/07/17 16:40
Cyber security is a hot topic, with articles appearing most days within the mainstream media.   As consumers, we’re all becoming more cyber-aware as we see the latest well-known brand in the headlines for having lost their client data.

Most of us will have been affected by a credit card breach within the last few years - I can’t imagine there could be many people in first world countries who have not had their credit / debit card details stolen and received a replacement card from their bank. It's a major hassle - stressful and a huge waste of time.

Read More
Benjamin Hosack

Alert: New PHP Webshell Identified

web security, Magento

,03/03/17 11:50

A new piece of malware has been identified by the Foregenix DFIR team.  The malware is a PHP webshell - a script, which when installed on a compromised system, presents a sophisticated administration platform allowing the attacker to browse the filesystem of the compromised server, upload, create, edit, download or delete files or stop running processes.

Read More
Benjamin Hosack

Vulnerabilities on ManageEngine EventLog 10.7 through 11.2 (Service Pack 11023)

penetration testing

,23/12/16 11:29

We have come across Manage Engine EventLog installations a few times in our penetration tests at Foregenix, and have identified different vulnerabilities in our attempts to compromise it. In most situations a default guest account was left open and becomes a focus point as we attempt to use it to elevate privileges or otherwise influence the profiles behaviour to our advantage. These attempts resulted in the following vulnerabilities being discovered and reported to the vendor. While the installations encountered during the engagements may not be running an up-to-date version of the ManageEngine EventLog software we validated whether the vulnerabilities still exist on the latest version as of the time of reporting them to the Vendor.

Read More
Benjamin Hosack

Magento Malicious JavaScript in Action

web security, Magento, malware, JavaScript

,08/11/16 14:48

Magento websites have been under attack from a new malicious JavaScript family of malware - our forensic team has been working with many hacked websites to help them regain control of their online businesses and to limit losses.

Read More
Benjamin Hosack

Magento Websites - Have You Patched SUPEE-8788 Yet?

web security, Magento

,04/11/16 14:28

Last month Magento released SUPEE-8788 to fix a number of security issues – you can read about SUPEE-8788 in detail here.  A LOT of websites have not yet patched and are at risk of being hacked.

Read More

Cyber Security Insights

Jake Dennys
17/10/17 10:33

Foregenix Highly Commended at Fraud Awards 2017

Earlier this year we were shortlisted for a prestige award at Fraud Awards 2017, presented by Retail Risk. Judges had selected Foregenix as a ...

Read More

Jake Dennys
09/10/17 14:24

Why an SSL certificate won’t protect your website, but FGX-Web will.

Having an SSL (Secure Sockets Layer) certificate on your website is important and it's also a good thing to have. The little green padlock in the ...

Read More

Mike Hinton
04/10/17 10:55

Is My Hosting Provider Protecting My Website?

Recently, it was discovered that over 14 million Verizon customers data, including PIN’s, had been exposed on an unprotected web server.  Three ...

Read More

Jake Dennys
28/09/17 10:21

We're Showcasing Cybersecurity at Ecommerce Expo 2017!

Flyers printed, banners set up, scanners prepped, we are officially at Ecommerce Expo 2017! It’s our first year at the show and we’ve hit the road to ...

Read More

Paul Taylor
25/09/17 12:09

Responsible Disclosure of Zero-Day Vulnerabilities Discovered in NfSen and AlienVault OSSIM

Part 1 of 2 – Introduction and Background NfSen is an open source netflow data capture and analysis module which can be used as a standalone product, ...

Read More