Get All Access for $5/mo

How to Fend Off a New Kind of Cyber Attack Hackers can use malware that redirects customers to malicious websites when they visit yours. Here's how to defend your site in an attack.

By Mikal E. Belicove

Opinions expressed by Entrepreneur contributors are their own.

How to Fend off a Cyber AttackWelcome to your worst nightmare online. That business website you so painstakingly created, nurtured and made successful has just been poisoned in a nasty cyber attack. Known as Mass Meshing Injection, this type of attack attempts to overpower security measures aimed at detecting a previous type of cyber attack called Mass SQL Injection. Since the beginning of June, it's affected thousands of business websites worldwide.

"In Mass SQL Injections, scripts or iframes are injected into innocent victim sites that cause the browser to load malicious content from the 'redirectors,' which are domains registered by the attacker," Wayne Huang, chief technology officer at Armorize, wrote last week on the Web security firm's Malware Blog.


"To defeat this," Huang continues, "Mass Injection does the following: Every infected website contains a redirector script in the root directory; in this case it is example.js. This is an obfuscated script that will dynamically generate an iframe to the exploit server. It runs the BlackHole exploit and serves drive-by downloads."

As a result, Huang writes, "Every infected website is injected, in their pages, with a script src tag pointing to another random infected website's example.js."

If all of that sounds like mumbo-jumbo, here's a translation: In a mass-meshing attack, hackers implant scripts in websites that redirect a visitor's computer to Web servers that, in turn, inject them with infected programs. Worse yet, an infected site has the very real potential of being blacklisted by Google and security vendors.

So how do you know if your site has been hacked, and if it has, how do you restore it and your reputation when Google or their antivirus software tells customers your site poses a risk? Regina Smola is founder and CEO of WP Security Lock, a Davis Junction, Ill.,-based firm that provides malware prevention and removal services for small and medium-size business. Smola says the best indication that your website has been hacked is when you are redirected to another site when you open your webpage.

"If you attempt to go directly to your website -- or to get to your site from a search engine link -- and you're referred elsewhere, this is a strong indication that your site may have been infected with malware," says Smola. "If this happens, close the web page immediately and run a full malware scan on your website." Smola recommends using a service like Sucuri Web Integrity Monitoring, which lets you know if malware is found on your website.

Even if you suspect your business website has fallen victim to a Mass SQL or Mass Meshing Injection, the best outcome is derived by immediately contacting everyone on your Web and IT teams, including your Web-hosting provider. Then outline a plan of attack of your own. And since infected websites ultimately infect your local computers, be sure to scan -- and if necessary, repair -- your computers before changing any of your administrative passwords. The reason is if your PC is infected, the bad guys could easily gain access to your new passwords, also.

Has your business' site been attacked by malware? Let us know how you handled it in the comments section.

Mikal E. Belicove is a market positioning, social media, and management consultant specializing in website usability and business blogging. His latest book, The Complete Idiot’s Guide to Facebook, is now available at bookstores. 

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Side Hustle

'Hustling Every Day': These Friends Started a Side Hustle With $2,500 Each — It 'Snowballed' to Over $500,000 and Became a Multimillion-Dollar Brand

Paris Emily Nicholson and Saskia Teje Jenkins had a 2020 brainstorm session that led to a lucrative business.

Business News

'I'm Not Trying to Land on Mars': Mark Cuban Takes Dig at Elon Musk to Explain Why His Online Pharmacy Isn't Trying to Make More Money

Mark Cuban Cost Plus Drug Co. is an online pharmacy co-founded by Cuban and radiologist Alex Oshmyansky.

Business Ideas

63 Small Business Ideas to Start in 2024

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2024.

Business News

'It's Not About You': How to Fire Someone Effectively, According to Kevin O'Leary

O'Leary says that if you can't fire someone, you aren't the right leader for the organization.

Leadership

Should I Stay or Should I Go? 8 Key Points to Navigate the Founder's Dilemma

Here are eight key signs that help founders determine whether to persevere or let go.

Marketing

Your Most Powerful Marketing Weapon Is Hiding in the Finance Department — Here's Why

Transform your marketing leadership by turning finance from a barrier into a strategic ally. Learn how aligning with your finance team can drive unprecedented growth and innovation.