SugarCRM 8 engages Data Protection

23/08/2018

SugarCRM 8 engages Data Protection

In May 2018, SugarCRM deployed its new brand version: Spring ’18 for the Sugar Cloud instances and Sugar 8 for those “on site”.

Since SugarCRM introduced a new pace in scheduling their releases:

this is the major upgrade they did.

Because of European Union GDPR and the rising of request of data privacy enforcement, SugarCRM introduced new functionalities and a new Data Privacy Management Module.

This is a good improvement because it helps DPO to manage all requests of customers and prospect to know about how their personal data are kept. Requests are stored in records, so they can be audited for further searches.
It’s vital for businesses to engage data protection following SugarCRM example.

Why SugarCRM is boosting its sales

13/08/2018

Why SugarCRM is boosting its sales

SugarCRM developed a different business plan compared to others CRM software companies.
Its aim is to compete with top vendors in the CRM market such as SalesForce and Microsoft, so it has a different vision: it points to the customer service and it’s succeeding doing that.

According to PC Mag’s 2018 CRM Report SugarCRM scored 7.7 in overall satisfaction.

While other Open Source companies works mainly on adding new functionalities to their product and to fix highlighted bugs, SugarCRM focused on integration with platforms like Microsoft IIS or IBM DB2 that are closed but well known and already in use in thousands of business instances.

SugarCRM is preparing itself to be the next leader in the CRM world and with the right accent on security there’s no reason why this should happen.

SugarCRM 7 is Now


SugarCRM 7 is Now





NEWS: the SugarCRM7 version of CRM Defender is available now!

For On Demand environment also!

Secure your SugarCRM 7 system:

  • Find a great Protection against brute force attacks.
  • Track users’ logins and protect your data.
  • Detect and Defend your CRM system from threats coming from hostil IPs.

Contact us

Feel free to contact us for commercial or technical questions

Brute Force Attack

17/04/2017

Brute Force Attack


Brute-force Attack





What is actually a Brute-force Attack, and how can i protect my CRM system against it?

A Brute-force attack is the most simple way to try to access in a system without being authorized; but it’s effective. With this technique, an attacker has the mathematical certainty to find a way to go inside.

Definition

A Brute-force attack satisfies the following characteristics:

  • guess every possible password;
  • time to break the system depends on the length and complexity of the password choosen;
  • usually ine system could be considered safe if it forces users to adopt  long and complicated passwords.

How it works

A Brute-force attack consists of an enormous continued repetition of attempts to find the right combination of user names and passwords.
It’s usually conducted by bots, automatic programs that replicates human enterings.

Like in every battle, there are some factors that could help the attacker while others help the defender; let’s focus on the first ones in order to strengthen the protections:

Admin user

If the Crm Administrator uses “admin” as its username, half of the attacker’s job is already done, because it has only to try all the combinations of passwords with any length and any carachter.

CRM URL

If your CRM system location is predictable, like:

  • crm.yourcompanyname.com
  • www.yourcompanyname.com/crm

then the attacker knows where to intervene and how to set its automatic bots.

In case the attacker is an old workmate or a former employee, the CRM URL is obviously known. It’s “overkill” to change URL:  think of the disorder that would be caused to the colleagues that should save the new link in their browsers or Apps.

But don’t worry; there are easier solutions.

Protection in Passwords

One classical way to protect your system is to oblige your employees to use a strong password. You can easily set the password requirements in the Password Management panel in the admin page: https://support.sugarcrm.com/Documentation/Sugar_Versions/6.5/Ent/Administration_Guide/Password_Management/index.html

Please note that some of the settings showed in the previsious link are related to SugarCrm paid versions. You can always achieve that with custom development.

Think different

Instead of wasting precious energy, fighting against potential threats and trusting the procedures to ensure that employees adopt strong passwords and\or renew them often, you can introduce an automatic barrier that bans any potential intruder as soon as you exceed the maximum number of allowed attempts.

With a solution like CRM Defender there will be no way to hijack your system, because the Web Server itself, duly instructed by CRM Defender, will block intruders.

Contact us

Feel free to contact us for commercial or technical questions

CRM Defender available on SugarOutfitters


CRM Defender available on SugarOutfitters



CRM Defender is now available on SugarOutfitters marketplace :

SugarOutfitters

Get in touch there to get a free trial and experiment the package as you wish.

Feel free to open there a Support Case or contact us via the following form. We are here to help you to feel confident and secure about your SugarCRM and SuiteCRM system.

You can also contact us if you want any help testing your system against a brute-force attack, because we can simulate it for you.

Contact us

Feel free to contact us for commercial or technical questions

Data Protection


Data Protection



In an increasingly connected world, where competitiveness is the dominant value, Data protection plays a crucial role. First of all it’s a must to keep a way to have back your data in case of emergency.

One of the key challenge for a Small Medium Business is to keep its own data as much safe as possible. And reducing the amount to invest in defense.

For a startup business the first target to reach is to survive but after reaching this out, it’s important to start thinking about the potential losses caused by a breach in the system.

Contact us

Feel free to contact us for commercial or technical questions

CRM Security

CRM Security

Your CRM Data are vital for your business. To protect them is an obvious priority. No mather if your CRM runs on Premise or on a Cloud service: if someone tries to force your passwords, and you don’t take any countermeasure, soon or later, your CRM Data will at the mercy of the attacker.
But if you act properly there’s nothing to worry about.

The first thing in order to achieve that is to enforce users to use strong passwords or to generate them using autocreation tools.
You can also ask to your IT manager to ban some IP addresses from where suspicious attempts come. This require that you or your workmate keep an eye on potentially fraudulent login attempts tracking such behavior on your Server or on your Local Net proxy.
If you are on a hosted environment, you can use a tool like cPanel > IP Address Deny Manager:

This obviously requires that you are aware of which is the IP of the attacker, or its IP range. So it could take time to prevent further intrusions. Best choice is always to automate this flow; this will let your system protected even if the “IT Manager is on holydays”.

Another difficult task you can experience, if your system is accessed from a large set of IPs, potentially from different country, is to check for failed login attempts.  To do so, one would need to check directly on the CRM log. But there is another problem: SugarCRM itself doesn’t allow you to know from where a suspicious attempt came.

I.e. a failed attempt on “admin” user would add on sugarcrm.log two rows like:

Fri Mar 3 19:00:00 2017 [35403][-none-][FATAL] SECURITY: User authentication for admin failed
Fri Mar 3 19:00:00 2017 [35403][-none-][FATAL] FAILED LOGIN:attempts[1] - admin

that is simply ineffective.

Contact us

Feel free to contact us for commercial or technical questions

Copyright All Rights Reserved 2019 CRM Defender - Lion Solution Srls