Corporate bloggers urged to tighten security

Powered by SC Magazine

Network security vendor Network Box has launched a Secure Blogging Guide giving corporate bloggers best practice advice on how to avoid being hacked.

The main threats to blogs are spam left in the comments section, which could contain malicious URLs, and SQL injection attacks that could exploit vulnerabilities in Blogger and Wordpress software, according to Network Box internet security analyst Simon Heron.

"As email becomes more difficult to get exploits through, the hackers are looking for other techniques," he said.

"If you see a link in a blog you're more likely to click on it than in the email environment because there is a greater sense of trust between the blogger [and the reader]."

The guide advises bloggers to restrict user access rights, keep blogging software up to date and check blogs regularly at weekends when attacks are most likely to occur.

Network Box also urges the use of Captcha or other authentication methods in order to reduce the likelihood of spam.

Corporate blogs are increasingly used to deliver marketing messages to customers, and Heron warned that firms must secure their blogs as they would a web site in order to avoid the brand damage that could ensue from a hacking incident.

"It will negate the benefits of a blog if you push out subliminal advertising and also give your customer a virus," he added. "None of the tips in this guide is rocket science and most only have to be done once."

Copyright ©

Top Stories
Toll Group to go Google
Poaches Woolworths project manager.
How News Corp's CIO tackled skills in his race to the cloud
What to do when your team’s talents are no longer needed.
Photos: How Thodey transformed Telstra
From turbulent Trujillo to Australia's leading telco.
Sign up to receive iTnews email bulletins
Latest Comments
Who do you trust most to protect your private data?

   |   View results
Your bank
Your insurance company
A technology company (Google, Facebook et al)
Your telco, ISP or utility
A retailer (Coles, Woolworths et al)
A Federal Government agency (ATO, Centrelink etc)
An Australian law enforcement agency (AFP, ASIO et al)
A State Government agency (Health dept, etc)

Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
I DON'T support shutting the OAIC.