A security flaw, patched on July 13, in key modules embedded in the Drupal CMS has been exploited in live attacks, according to Johannes Ullrich of the SANS Internet Storm Center.
Ullrich says that over the past two months, honeypot servers have been installed all over the Internet, which have begun to detect scans that check whether Drupal installations are running older versions of a particular module and try to exploit the flaws they discover.
The issues they are scanning are in a RESTful Web Services (RESTWS) module built into Drupal 7.x installations. According to an advisory released by the Drupal team, all versions of this module prior to 7.x-2.6 and 7.x-1.7 (the patched versions) allow an attacker to execute commands on the underlying web server by accessing a URL with specially crafted parameters.
These URLs in the non-standard format are the ones that Ullrich caught with his honeypots.
“So far in honeypot , we have caught 44 attempts today alone from 16 different IP addresses,” Ullrich revealed. “The exploit attempts go back to July, right after the vulnerability was announced.”
Other vulnerabilities in other core Drupal modules were released in mid-July, along with this one. It is very likely that the fact that we are seeing exploitation attempts right now is precisely because security researchers released proof-of-concept exploit code for the RESTWS module vulnerability.
Additionally, Ullrich took a look at the IP addresses from which the exploit attempts were coming. A quick search revealed that these requests were coming from the web hosting servers of other Drupal websites.
The people behind these scans hack unpatched Drupal installations and then use these servers to invade other websites, without revealing their real IPs.
Finally, Ullrich noticed something else strange. The exposed websites do not host malware, fake ads, or pharma spam. For now, it seems that the crooks are slowly and steadily building their botnet, without giving any indication of their presence on the infected websites.

