Skip to main content

Patch/Update Drupal or Be Hacked by Highly Critical SQL Injection in Database Abstraction API

Drupal SQL Injection - Drupal Warns of Getting Hacked Unless Patched

Millions of Drupal 7 websites might have hit by hack attack


Drupal issued an advisory on Oct 15, 2014 about vulnerability of SQL Injection in its Drupal core 7.x versions prior to 7.32.

Drupal issued its SA-CORE-2014-005 advisory, warning of a highly critical SQL injection vulnerability that is also identified as CVE-2014-3704.

The only solution is to install the latest version i.e. Drupal core 7.32.

With the issue of advisory on 15 Oct by Drupal, multiple exploits have been reported. For this they issued follow-up announcement DRUPAL-PSA-2014-003

Drupal issued very strong words in the advisory PSA-2014-003. This shows how serious the vulnerability is. Here is what they penned down:
"You should proceed under the assumption that every Drupal 7 website was compromised unless updated or patched before Oct 15th, 11pm UTC, that is 7 hours after the announcement."
There are chances that you may not be able to update to the latest Drupal version. For those users Drupal has issued a patch for Drupal's database.inc file to fix the vulnerability. Drupal also provided a help document to recover your hacked website. Take a look at their help documentation, "Your Drupal site got hacked, now what"

Comments

Popular posts from this blog

Income Tax Proud Filer Badge for Facebook Profile Picture India

"PAN-XXXXXXXXXX Honoring the Honest-Use/Share the Proud Filer Badge" Indian Income Tax Agency is offering all the tax fillers to show up their Proud Filer Badge through Facebook profile picture. Income Tax Department of India is sending email with subject line "PAN-XXXXXXXXXX Honoring the Honest-Use/Share the Proud Filer Badge" to help guide the filers on how to show the Proud Filer Badge. How to Show Income Tax's Proud Filer Badge for Facebook Profile Picture in India Here are the steps to use the Facebook Badge on Mobile Phone: Step 1: Open your Facebook Mobile App Step 2: Click on Profile Pic and the select Add Frame Step 3: Search for Proud Filer, you will get Income Tax Official Profile Badge - Proud Filler by Income Tax India Step 4: Click on the searched Frame. Facebook will set your profile picture with the Proud Filler Badge. Step 5: Click on Save and your are done with adding Proud Filler Badge to your Facebook Profile Picture. Here are the steps to us...

BlackBerry Priv Confirmed as New Android Based Smartphone

BlackBerry Priv-An Upcoming High End Android Based Phone BlackBerry has finally confirmed it's Priv smartphone will launch at the end of 2015. BlackBerry Priv smartphone is based on Android and have a slider QWERTY keyboard. The mobile phone company, said Friday that they will release BlackBerry Priv (Short for Privacy) later this year. The Priv runs on Android instead of BlackBerry OS 10 and will feature a sliding QWERTY keyboard behind the touchscreen. "Today, I'm confirming our plans to launch Priv, and Android device named after BlackBerry's heritage and core mission of protecting our customers' privacy," wrote CEO John Chen in company's Second Quarter Financial results. "Priv combines the best of BlackBerry security and productivity with the expansive ecosystem of mobile applications available on the Android platform." Chen also said that BlackBerry OS 10 will continue to receive updates and will not be replaced by the Android op...

Microsoft's Windows-XP OS & Office 2003 Support Ends in April 8, 2014

End of Security Updates for Windows XP OS & Office 2003 Windows XP SP3 and Office 2003 Supports Ends Apirl 8, 2014  Image Credit: Microsoft Microsoft has finally announced the date for the end of security updates for its Windows XP operating system. As of now Microsoft is releasing security updates for Windows XP, but due to security issues and to move more users from XP to Windows 8, Microsoft has decided to stop updates in 2014. According to Gartner prediction, more than 15% of medium and large enterprises will still have Windows XP running on at least 10% of their PCs after Microsoft support ends in April 2014. This means, people and organizations using Windows XP SP3 will be prone to bugs and flaws in the OS, as Microsoft is not going to fix those bugs. They will be open to malware, spyware and even viruses. Office 2003 Support Also Ends in April 8, 2014 Microsoft also announced the end of support for Office 2003, in a press conference yesterday in Lagos. Acc...