HomeSecurityMajor vulnerability in Drupal! Upgrade to the latest version immediately.

Major vulnerability in Drupal! Upgrade to the latest version immediately.

drupal

Announcement on the Drupal website : “Malicious attacks began a few hours after the new Patch was released. If you do not have the latest version installed, your website is at risk”

Drupal users were in for a surprise last week: According to Drupal, automated attacks began compromising Drupal 7 websites that had not been updated to Drupal 7.32 within hours of the announcement of SA-CORE-2014-005 – Drupal core – SQL injection . Users should update their software immediately and be aware that their Drupal 7 website was compromised if it had not been updated before Oct. 15 23:00 UTC. The vulnerability concerns an error in the database abstraction API that allows an attacker to send special requests that allow arbitrary SQL code execution . This, depending on the content of the requests, could allow privilege escalation, arbitrary PHP execution, or other malicious actions. Shortly after the security advisory was published on Oct. 15, multiple attacks were reported online.

“Once a vulnerability is discovered in popular CMS platforms like Drupal, millions of hacker-run crawlers (similar to Google bots) start searching for vulnerable websites,” says High-Tech Bridge CEO Ilia Kolochenko. Once a victim is found, the website is hacked, a patch is installed (to prevent another hacker from invading), and a backdoor is created. Within a few days, access to the website is sold on the black market to many different customers, who in turn resell it several times.

The announcement from Drupal is part of a broader trend of security challenges facing content management systems (CMSs). Such systems are frequent targets for cybercriminals, as they lend themselves to large-scale, automated attacks. Earlier this month, Imperva said in a report that WordPress websites were attacked 24% more than all other CMS platforms combined.

“Content Management Systems (CMS) are a major target for hackers and are attacked on a daily basis,” said Jerome Segura, senior security researcher at Malwarebytes. “The problem with websites is mostly due to poor security practices by the owners themselves. This latest case, where a vulnerability in Drupal was exploited by hackers just hours after it was publicly disclosed, is very concerning.” Drupal said in a statement:
“If you find that your website has already been patched, but you haven’t done so, it could be a symptom that the site has been compromised – some hackers install the patch to ensure they are the only ones in control of a website.”

The Drupal security team also recommends that site administrators consult with their hosting provider. If they have not upgraded Drupal within hours of the announcement on October 15, site owners should restore to a backup from before that date.

Many people simply don't realize their website is a very attractive target for hackers, Kolochenko says.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS