Skip to main content

Millions of websites hit by Drupal hack attack

Anyone who had not yet updated should do so immediately, it warned.

However, the team added, simply applying this update might not remove any
back doors that attackers have managed to insert after they got access.
Sites should begin investigations to see if attackers had got away with
data, said the warning.

"Attackers may have copied all data out of your site and could use it
maliciously," said the notice. "There may be no trace of the attack." It
also provided a link to advice that would help sites recover from being
compromised.

Mark Stockley, an analyst at security firm Sophos, said the warning was
"shocking".

The bug in version 7 of the Drupal software put attackers in a privileged
position, he wrote. Their access could be used to take control of a server
or seed a site with malware to trap visitors, he said.

He estimated that up to 5.1% of the billion or so sites on the web use
Drupal 7 to manage their content, meaning the number of sites needing
patching could be as high as 12 million.

Drupal should no longer rely on users to apply patches, said Mr Stockley.

"Many site owners will never have received the announcement and many that
did will have been asleep," he said. "What Drupal badly needs but doesn't
have is an automatic updater that rolls out security updates by default."

http://www.bbc.com/news/technology-29846539

my motto is "Keep it simple" and "don't leave anything for tomorrow that can
be done today."

Regards Gerald Crawford

Stellenbosch South Africa
Cell: +27-0720390184 (mobile)
E-mail: gerald@webcraft.ws


---
This email is free from viruses and malware because avast! Antivirus protection is active.
http://www.avast.com

Comments

Popular posts from this blog

What Is Internet Website Content?

What Is Internet Website Content? Content is made up of multiple elements, and is primarily the; * On-page visible text * Images and image Alt text * Anchor text in hyperlinks to internal or external pages * Hyperlink titles in links and menus * The descriptive Title and Description meta-data In the context of Google, a picture is NOT worth a thousand words! Moreover, words must be accessible, not embedded in images or Flash movies, JavaScript, slide shows etc. In 15 years as an SEO consultant, if there's one common denominator evident on websites, it's that there is a profound reluctance to expend time, money, and creative energy on unique text content. Brevity is the watchword - economical use of words is encouraged by design, branding and marketing advisers! * The branding gurus want you to use the textual equivalent of sound bites - bullet points and short sentences! * The website designers want the entire content of the page to be above ...

How to Write Web Copy

Actionable tips for software developers writing web copy. Scan Web site visitors read websites very differently than they might read a book or a newspaper. Web visitors scan the text, rather than reading each and every word. As a result, the web copy should be designed to be easily scannable. That is not to say the copy should not be well written, but it should be broken into small "chunks" so that the visitor can easily scan it and take away the main idea. White Space Avoid dense copy. Copy should be broken into readable, digestible "chunks" and surrounded by a good amount of white space. Font Type Font size matters. Avoid using micro fonts. Studies have shown that the easiest type faces to read on the Internet are san serif fonts. Popular sans fonts include Helvetica, Avant Garde, and Arial. Popular serif fonts include Times Roman, Courier, and Palatino. Sans-serif fonts have become the de facto standard for "body" text on-screen, because monitors pr...

The REAL Value of Keywords

An important question in SEO is how much intrinsic value resides in a specific keyword and, whether SEO has the potential to take everybody on a fool's errand? When it comes to bigger companies, for instance, can a massive SEO investment in trying to achieve top ranking for almost-generic, ultra-competitive keywords be worth all the disappointment and soul-searching? Surely, in so many cases, there has to be a better way? At the other end of the scale are smaller companies with a limited marketing budget, particularly in the business-to-business sphere. There is often a fine balance to achieve when it comes to investing in SEO for what can only be low-traffic keywords in niche sectors, even where higher gross margins per sale indicate otherwise. Realizing this, many companies will skip the on-line sales dance, or resign themselves to having a website that is little more than an 'on-line brochure' presence or a support mechanism for Pay-Per-Click or social media activities. ...