{"id":5359,"date":"2022-06-17T09:53:33","date_gmt":"2022-06-17T04:23:33","guid":{"rendered":"https:\/\/www.wpoven.com\/blog\/?p=5359"},"modified":"2022-06-17T09:53:33","modified_gmt":"2022-06-17T04:23:33","slug":"godaddy-confirms-data-compromise-save-your-website-now","status":"publish","type":"post","link":"https:\/\/www.wpoven.com\/blog\/godaddy-confirms-data-compromise-save-your-website-now\/","title":{"rendered":"GoDaddy Confirms Data Compromise! Save Your Website Now!"},"content":{"rendered":"<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">On 23<\/span><span style=\"font-weight: 400;\">rd<\/span><span style=\"font-weight: 400;\"> April 2020, GoDaddy, an American based internet domain registrar and web hosting company that is based out of Scottsdale, Arizona confirmed a data breach via email, which was signed by Demetrious Comes, CISO and vice-president of the company.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">With over 19 million customers worldwide, the hacking affected approximately 28,000 were actually affected as their SSH credentials were compromised by an unauthorized hacker, confirmed the spokesperson of the company in a public statement.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The company, in the public announcement also said that, in order to control the damage, they immediately reset the usernames as well as passwords. Furthermore, they additionally removed SSH files from the platform. Furthermore, they assured that the hacker did not have any access to the <\/span><span style=\"font-weight: 400;\">main accounts of any of the users.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Reports by the intelligence team of the company suggested that the data breach resulted in \u201cactive exploitation of vulnerabilities in two related plugins\u201d namely; Elementor Pro and Ultimate Addons for Elementor.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Wpoven Offers Off-Site Backups, Daily malware Scanning and Cleanup, Expert support, SSL, SSD storage with plans starting just $16.61. Check Out <a href=\"https:\/\/www.wpoven.com\/plans-and-features\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>our features to get your mind blown!<\/strong><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_8306\" aria-describedby=\"caption-attachment-8306\" style=\"width: 719px\" class=\"wp-caption alignnone\"><img decoding=\"async\" class=\" wp-image-8306\" src=\"https:\/\/www.wpoven.com\/wp-content\/uploads\/2018\/03\/c7ae95d0-ee76-11e9-babd-e14c314de15b-1509-WPOven-FB-Cover-Photo-2-01-1024x390.jpg\" alt=\"wpoven\" width=\"719\" height=\"274\" title=\"\"><figcaption id=\"caption-attachment-8306\" class=\"wp-caption-text\">wpoven<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">During the public announcement, the company also claimed that it first occurred in October 2019. Now this means that it is recurring, making it an on-going attack, which is why the company is continuing to take adequate precautions to protect the websites of all its consumers. Additionally, GoDaddy has also chosen to give out very limited amount of information so as to not attract unnecessary attention. Furthermore, they have also released a set of firewall regulations in order to assist consumers in protecting their website. This is also the very reason why the firewall has been made free until 5<\/span><span style=\"font-weight: 400;\">th<\/span><span style=\"font-weight: 400;\"> June 2020.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">It is imperative to try and understand what exactly these plugins are and how they have been affected. The first one is Elementor Pro, which was created by Elementor. It has been clarified that this plugin does not affect the free Elementor plugin.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">One of the major vulnerabilities of this plugin is, \u2018zero-day vulnerability\u2019. This means that it allows users to upload files without being checked for any malware, leading to Remote Code Execution, which basically provides hackers access to all sorts of changes to the system on another person\u2019s computer, irrespective of the geographical location. As this error was not fixed timely, the necessary authority is continuing to work in order to control as damage as possible. While in a newer version of the second one, i.e., Ultimate Addons for Elementor version 1.24.2, the issue was that it allowed these hackers to be able to create \u2018subscriber level users\u2019 even when these registrations were turned off. <\/span> <span style=\"font-weight: 400;\">This issue has not been successfully fixed, reported to the authorities.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Now the next step is to understand how users\u2019 websites can be protected for such attack and most importantly what necessary precautions are to be taken at the consumer level.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Although GoDaddy has made necessary changes to the passwords and has also remover the \u2018attacker\u2019s public key\u2019, it has been strongly recommended that users change the password of their website\u2019s database.<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Other precautions also include making necessary changes in plugins until the vulnerabilities are properly fixed. Furthermore, it is advised that websites are periodically checked for unknown or unusual files, subscriber-level users, and most importantly also be on the lookout for arbitrary files with unusual names such as \u201cwp-xmlrpc.php.\u201d<\/span><\/p>\n<p style=\"text-align: justify;\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Following such precautions prescribed by the company will help in preventing any possible attack on the websites of the users.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On 23rd April 2020, GoDaddy, an American based internet domain registrar and web hosting company that is based out of Scottsdale, Arizona confirmed a data breach via email, which was signed by Demetrious Comes, CISO and vice-president of the company.<\/p>\n<p>&nbsp;<br \/>\nWith over 19 million customers worldwide, the hacking affected approximately 28,000 were actually affected as their SSH credentials were compromised by an unauthorized hacker, confirmed the spokesperson of the company in a public statement.<\/p>\n<p>&nbsp; &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.wpoven.com\/blog\/godaddy-confirms-data-compromise-save-your-website-now\/\" class=\"more-link\">Read More <i class=\"fa fa-angle-double-right\" aria-hidden=\"true\"><\/i><span class=\"screen-reader-text\"> &#8220;GoDaddy Confirms Data Compromise! Save Your Website Now!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":25,"featured_media":5360,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ub_ctt_via":"","footnotes":""},"categories":[1],"acf":[],"featured_image_src":"https:\/\/www.wpoven.com\/blog\/wp-content\/uploads\/2020\/05\/Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Copy-of-Yellow-and-Pink-Design-Solutions-Presentation.png","author_info":{"display_name":"snehil","author_link":"https:\/\/www.wpoven.com\/blog\/author\/snehilprakash\/"},"_links":{"self":[{"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/posts\/5359"}],"collection":[{"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/comments?post=5359"}],"version-history":[{"count":3,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/posts\/5359\/revisions"}],"predecessor-version":[{"id":5363,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/posts\/5359\/revisions\/5363"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/media\/5360"}],"wp:attachment":[{"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/media?parent=5359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wpoven.com\/blog\/wp-json\/wp\/v2\/categories?post=5359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}