Cracking Drupal - marketing ftw http://crackingdrupal.com/taxonomy/term/6/0 en PandaLabs Exploit Marketing Copy to Distribute Propoganda http://crackingdrupal.com/blog/greggles/pandalabs-exploit-marketing-copy-distribute-propoganda <p>Over on the <a href="http://pandalabs.pandasecurity.com/archive/Cyber-Criminals-Exploit-Drupal-CMS-to-Distribute-Malware.aspx">pandalabs blog</a> is a post titled:</p> <blockquote><p>Cyber Criminals Exploit Drupal CMS to Distribute Malware</p> </blockquote> <p>Digging into the story a bit they write:</p> <blockquote><p>If you are using dynamic web applications, such as Content Management Software, E-Commerce or blogging software, then it's especially important to make sure that those applications are always up-to-date with the latest security patches....Today, I came across a State University website which was running a vulnerable version of the popular Drupal CMS software. The site was exploited by cyber criminals and over 3600 links were injected and indexed by Google in less than 10 hours of exploitation.</p> </blockquote> <p>So, the real message of the post is about updating your software. This is a point that I make painfully clear in chapter 3 of Cracking Drupal.</p> <h3>Software Release Dates Relative to Major Attacks</h3> <p>The below table compares the date of the patch release for several major internet worms compared to the date of the attack.</p> <p><img src="http://crackingdrupal.com/sites/crackingdrupal.com/files/cracking_drupal_table_3_1.png" /></p> <p>As you can see, using up to date software would have saved the world from some of the most costly worms of the last decade!</p> <p>If you run out of date software on a network connected computer you are basically asking to be hacked. Update regularly and you will avoid most attacks.</p> <table id="attachments" class="sticky-enabled"> <thead><tr><th>Attachment</th><th>Size</th> </tr></thead> <tbody> <tr class="odd"><td><a href="http://crackingdrupal.com/sites/crackingdrupal.com/files/cracking_drupal_table_3_1.png">cracking_drupal_table_3_1.png</a></td><td>29.84 KB</td> </tr> </tbody> </table> http://crackingdrupal.com/blog/greggles/pandalabs-exploit-marketing-copy-distribute-propoganda#comments marketing ftw Fri, 05 Jun 2009 15:34:12 +0000 greggles 22 at http://crackingdrupal.com