Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #14450 > unrolled thread

[CM] Drupal 7 compromised, vuln disclosure/management procedure criticized too

Started byRS Wood <rsw@therandymon.com>
First post2014-11-03 20:30 +0000
Last post2014-11-03 15:55 -0500
Articles 2 — 2 participants

Back to article view | Back to comp.lang.php


Contents

  [CM] Drupal 7 compromised, vuln disclosure/management procedure criticized too RS Wood  <rsw@therandymon.com> - 2014-11-03 20:30 +0000
    Re: [CM] Drupal 7 compromised, vuln disclosure/management procedure criticized too Jerry Stuckle <jstucklex@attglobal.net> - 2014-11-03 15:55 -0500

#14450 — [CM] Drupal 7 compromised, vuln disclosure/management procedure criticized too

FromRS Wood <rsw@therandymon.com>
Date2014-11-03 20:30 +0000
Subject[CM] Drupal 7 compromised, vuln disclosure/management procedure criticized too
Message-ID<m38okv$6lv$1@solani.org>
From the «sad blue waterdrop» department:
Title: Drupalgeddon megaflaw raises questions over CMS bods' crisis mgmt
Author: John Leyden
Date: Mon, 03 Nov 2014 06:43:07 -0500
Link: http://go.theregister.com/feed/www.theregister.co.uk/2014/11/03/drupal_drupalgeddon_analysis/

Fallout spreads as securobods issue warnings

The security world has been shocked to its foundations following ominous
warnings that millions of Drupal websites that didn't apply a critical patch
within hours of its release earlier this month should be regarded as hopelessly
compromised.…

[toc] | [next] | [standalone]


#14451

FromJerry Stuckle <jstucklex@attglobal.net>
Date2014-11-03 15:55 -0500
Message-ID<m38q4m$3ur$1@dont-email.me>
In reply to#14450
On 11/3/2014 3:30 PM, RS Wood wrote:
> From the «sad blue waterdrop» department:
> Title: Drupalgeddon megaflaw raises questions over CMS bods' crisis mgmt
> Author: John Leyden
> Date: Mon, 03 Nov 2014 06:43:07 -0500
> Link: http://go.theregister.com/feed/www.theregister.co.uk/2014/11/03/drupal_drupalgeddon_analysis/
> 
> Fallout spreads as securobods issue warnings
> 
> The security world has been shocked to its foundations following ominous
> warnings that millions of Drupal websites that didn't apply a critical patch
> within hours of its release earlier this month should be regarded as hopelessly
> compromised.…
> 

Although Drupal is written in PHP, they have their own support
structure.  This is not a PHP vulnerability, and is off-topic in this
newsgroup - as you've been told before.

Just because a product is written in PHP doesn't mean its
vulnerabilities are pertinent to this newsgroup.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
jstucklex@attglobal.net
==================

[toc] | [prev] | [standalone]


Back to top | Article view | comp.lang.php


csiph-web