Showing posts with label Drupal. Show all posts
Showing posts with label Drupal. Show all posts

Tuesday, 27 October 2015

Criticism Joomla Leak Within Four Hours After Patch Attacked



A critical vulnerability in their content management system Joomla where last week a patch for appeared four hours after the release of the update has already attacked. The creators of Joomla administrators and webmasters had already in advance for the security warning.


The opinion stated that administrators had to be ready to roll out the update immediately. According to security firm Sucuri is very easy via the vulnerability to gain full administrator access. Sucuri says it saw direct attacks against two popular Joomla sites within four hours after the release of the update. By trying to steal the session logged managers Both websites were at the time of the attacks are not patched. And this probably applies to many more websites.

The update was in fact rolled out on Thursday afternoon, with many administrators probably were already free. Currently there are on the whole internet scans covering all kinds of random Joomla sites are scanned. In the case of scanned websites are vulnerable to the attack is carried out. Meanwhile says Sucuri have seen tens of thousands of attacks.According to the security company have the attacks show that webmasters and administrators have less than 24 hours to roll out an update to this type of serious problems.

Friday, 23 October 2015

Joomla Close Serious Vulnerabilities In CMS Software


The creators of the popular content management system (CMS) Joomla today a major update that fixes serious vulnerabilities in the software and should be installed immediately. This is evident from the announcement of Joomla 3.4.5.

In this version, a total of addresses on the face of three security problems, one of which is a high priority has. It is a SQL Injection vulnerability. Further details on the impact are not given, but through SQL injection, attackers gain access to the database instance, take over the website or install malicious code. It also appears that this is actually about three different vulnerabilities.

Due to the problem were the developers of Joomla last week a warning given that this is a very important update. They now repeat that webmasters should immediately install the update. Joomla 3.4.5 only includes security updates and no further adjustments compared Joomla 3.4.4.

Friday, 19 June 2015

Critical Vulnerability In CMS Software Drupal Poem


There is an important security update for the popular content management system (CMS) Drupal appeared that fixes multiple vulnerabilities, including a vulnerability that allows attackers websites can take over completely. The leak is in the OpenID module and makes it possible for an attacker as any user to log in, including the manager, and their account hijacking.

Via the other vulnerabilities, it was possible to determine certain information, and to send user via an "open redirect" to a third party website through. This could, for example, can be used for a social engineering attack. Administrators are advised to upgrade to Drupal 6.36 or 7.38.

Monday, 20 April 2015

Drupal.org Accidentally Leaked Email Addresses Users


The website Drupal.org this week inadvertently leaked the email addresses of hundreds of logged in users. Drupal is a popular content management system with a vibrant community. An adjustment to the permissions of the web site on April 15 was a "small" part of the user to see a list of email addresses of users logged.

It would be a total of some 44 IP addresses that the information at that time approached. According Drupal went mainly to managers of Drupal.org and community participants who reported the incident. The problem was 13 hours after being rectified and introduced within 3 hours after such notice was made. The complete solution was made ​​to be within 24 hours after the onset. According Drupal were visible the email addresses of less than 500 people, all of which will be informed immediately. However, all users are advised to be careful with emails that ask for personal information.