HomeSecurityDrupal websites are vulnerable to double-extension attacks!

Drupal websites are vulnerable to double-extension attacks!

The team behind the Drupal content management system (CMS) this week released some security updates to fix a critical vulnerability that is easy to exploit and could give attackers complete control over vulnerable websites.

Drupal

Drupal, which is currently the fourth most used CMS on the web after WordPress, Shopify and Joomla, gave the vulnerability a “Critical” rating, advising website owners to update systems as soon as possible.

The vulnerability, named CVE-2020-13671, is based on the “double extension” trick.

Attackers can add a second extension to a malicious file, upload it to a Drupal site via open upload fields, and execute the malicious file.

Normally, files with two extensions should be detected, but in a security advisory published on Wednesday, Drupal devs said the vulnerability lies in the fact that the Drupal CMS does not check certain file names, allowing some malicious files to get through.

Security updates released for Drupal versions 7, 8 and 9

However, in addition to the updates, the Drupal team urges site administrators to check recent uploads for files with two extensions, in case the bug has been discovered and exploited by some hackers before the code update.

“Pay special attention to the following file extensions, which should be considered dangerous even when followed by one or more additional extensions:

  • far
  • php
  • pl
  • py
  • cgi
  • asp
  • js
  • html
  • htm
  • phtml

It's surprising that such a bug was discovered in Drupal. The double-extension trick is one of the oldest tricks.

The issue also created a significant problem for Windows, where malware creators often distribute files with two extensions, such as the .png.exe file.

Because Windows hides the last file extension by default, EXE extensions are hidden while only the first is displayed, tricking users into thinking they are opening an image , but are actually running an executable file that ultimately installs malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS