Hosting providers seem to be an often overlooked exposure area for many small and mid-size organizations. In the last several weeks, as we have been growing the use of our passive assessment platform for supply chain assessments, we have identified several instances where the web site hosting company (or design/development company) is among the weakest links. Likely, this is due to the idea that these services are commodities and they are among the first areas where organizations look to lower costs.
- “PCI accredited” checkout pages hosted on the same server as other sites that are clearly under the control of an attacker
- Exposed applications and services with default credentials on the same systems used to host web sites belonging to critical infrastructure organizations
- Dangerous service exposures on hosted systems
- Malware infested hosting provider ad pages, linked to hundreds or thousands of their client sites hosted with them
- Poorly managed encryption that impacts hundreds or thousands of their hosted customer sites
- An interesting correlation of blacklisted host density to geographic location and the targeted verticals that some hosting providers sell to
- Pornography being distributed from the same physical and logical servers as traditional businesses and critical infrastructure organizations
- A clear lack of DoS protection or monitoring
- A clear lack of detection, investigation, incident response and recovery maturity on the part of many of the vendors