educational

Watch Your Websites!

Some recent activity on the hacker front prompts me to write this warning. One of the latest trends for malware proliferation is to hack legitimate websites, load their evil wares and leverage the site's popularity to spread infections.

Websense, a web security company, said in a recent report called the State of Internet Security, that 70 percent of the top 100 sites had been hacked to serve malware to unsuspecting users. Some of the most recent examples include the websites of Paris Hilton, Paul McCartney, Anti Virus vendors Kaspersky and F-Secure, Facebook, MSN, Twitter along with many, many others.

Even if your site isn't among the web's top 100, you still need to be very vigilant. IBM recently reported that 450,000 web sites EVERY DAY are being hit by cyber criminals attempting to hack them. How sure are you that your site is clean and not being used by criminal elements to deliver malware? In this column I will show you some basic tools and show you how to use them to perform a quick check.

The first tool that we're going to use is a great program called Sandboxie. After you install the program, go ahead and run an Internet browser inside it. After the program starts, open the program's main window. From there, choose the "View" drop down menu and then "Files and Folders." Running your web browser connected to a safe site should not give you any error messages.

Then I went looking for trouble. In fact, all I did was open my SPAM filter and start clicking links. At least one of the sites installed some very suspicious software on my computer. Be VERY suspicious of any site that downloads files to your computer without your knowledge or if the site says it needs to load a program in order for you to be able to see its content.

Our next tool was written by Microsoft and works with Internet Explorer. It's called Fiddler and can be downloaded for free. This program is a bit more technical than Sandboxie but it also provides more information. Fiddler is a program used to debug web pages by monitoring all traffic between a web page and a browser and its output is more detailed.

Every time the web sends information to a browser it is logged along with the type of communication protocol used (HTTP), exactly who was sending the information (useful to make sure that only those sites that you allow are accessing your customers), and the type of content being transferred. Fiddler is a very powerful tool and you can dive into it as far as your technical skills allow. Simply be careful when using the Auto Responder and Request Builder tools.

The last tool we will explore is an add-on to the Firefox browser. Security Compass is the software company that wrote the add-on and actually has three tools worth trying: XSS Me, Access Me and SQL Inject me. As the names imply, each add-on tests for different vulnerabilities. This set of tools, unlike the previous two, actively sends information to a website looking for vulnerabilities and should be used only against sites that you own or control. The tools produce an easy to read report which summarizes any problems that it finds (make sure to disable any other add-ons that you may have running) and even test input fields for database vulnerabilities such as SQL injection attacks.

Remember though that the tools in this article are free may not be as comprehensive or thorough as tools that cost thousands of dollars.

With these pieces of software you have a basic toolbox for testing your web pages. Check your sites often and make sure that you have a clean restore disk image just in case you should ever need it.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

How Rolling Reserves Affect Cash Flow and Merchant Stability

You log in to your payment processor’s dashboard, discover they are withholding 10% of your sales, and immediately assume something has gone wrong. In reality, everything is working exactly as intended.

Jonathan Corona ·
opinion

What Federal Age Verification Could Mean for Adult Websites

Our industry has grappled with a patchwork of confusing and burdensome state age verification laws for the past couple of years. But that landscape could change quickly after the House passed the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757) by a vote of 267-117, marking a significant federal step into this space.

Lawrence G. Walters ·
opinion

The Website Footer Requirements Every Adult Merchant Should Know

Since I started in this business 25 years ago, I've watched website footers evolve from a simple collection of links designed to help with SEO into important tools for meeting compliance and regulatory requirements, improving the customer experience and reducing chargebacks.

Cathy Beardsley ·
opinion

Why E-Payment Diversification Matters for Merchant Stability

Match payment methods to your customers. Look at where your customers are located, how they prefer to pay and which products they purchase. A business with significant European traffic may benefit from SEPA or Pay by Bank, while a subscription-based business may prioritize ACH or cryptocurrency. Add the payment methods your customers are most likely to use, as not every option is available.

Jonathan Corona ·
trends

AI at Work: The Tools and Practices Powering Creativity, Commerce and Compliance

For years, artificial intelligence felt like the plot of a science-fiction movie. Pop culture gave us Skynet from “The Terminator,” the replicants of “Blade Runner” and countless visions of machines replacing human creativity altogether. AI was cast as either humanity's next great breakthrough or the beginning of a dystopian future.

Jackie Backman ·
opinion

Key Questions Online Merchants Should Know About PCI Compliance

Choosing a payment provider involves more than comparing features and pricing. It's also about trusting that your customers' payment information is being handled securely. Every August, Segpay is recertified as a Level 1 PCI-compliant service provider, a milestone the company has achieved for the past 20 years. Having helped write Segpay's original PCI policy documents more than two decades ago, I've seen firsthand how PCI compliance has evolved.

Cathy Beardsley ·
profile

New Moon Network's Savannah Sly on Turning Lived Experience Into Advocacy

Savannah Sly is the first to admit she didn't always understand sex work. At 18, she was an art student in Boston, working part-time at a box office and, as she puts it, "broke as a joke." While looking for ways to make ends meet, she often found herself browsing Craigslist's adult ads, intrigued by the women advertising their services.

Jackie Backman ·
opinion

How to Safeguard Your Website Against CIPA Claims

There is a new wave of lawsuits targeting online businesses, including adult websites. These suits involve the California Invasion of Privacy Act (CIPA), and they are becoming increasingly prevalent. In fact, three different clients of my law firm were recently served or threatened with CIPA lawsuits — all in the same week.

Nick Zargarpour ·
opinion

How Clear Talent Contracts Can Save Time and Money

The adult industry has always been defined by its ability to evolve. It embraced online distribution before much of mainstream entertainment did, pioneered subscription-based business models, and continues to evolve in areas ranging from streaming to AI.

Corey Silverstein ·
profile

Jerkmate's Lili L. on Dropping Beats to Fuel Creator Success

Long before joining the Jerkmate team as a marketing strategist, Lili L. was the kind of person who always felt like she needed a new challenge.

Women In Adult ·
Show More