Drupal Vulnerability and Drupageddon

by | Oct 20, 2014 | Development

Share this post

Drupalgeddon '14

A serious code breach in Drupal 7 was unearthed last week, leaving many sites at risk. Well, actually, it just resurfaced, since it had been identified and then dismissed last year. No one can afford to ignore it now.

This vulnerability is SQL Injection, a very common hacking method for stealing data by inserting SQL commands through the backend database. It allows remote hackers to assume admin authority over a website, causing who knows how much havoc. Many thousands of sites are built on Drupal 7, and every one of them could be affected.

The threat, though severe, is fairly easy to fix. Scanning, analyzing, and patching with an upgrade to Drupal 7.32 (which was released to address this problem) should correct it. However, finding a patch does not assure that it was made by the good guys. As reported by Tamer Zoubi, hours after the Drupal SA-CORE-2014-005 fix, he found a malicious script which sifts through a list of domain names alphabetically, placing new requests into the menu router table, resulting in arbitrary SQL execution.

Any and all accounts serviced by CommonPlaces should know that we have team members who are dealing with this issue. The excellent community of Drupal developers continues to pass along any information which comes their way. If you have any concerns with your Drupal website, and you are not a client of ours, we urge you to contact the Drupal community directly.

Insights

Helping B2B leaders use technology to drive business

2026 B2B Content Marketing Trends

2026 B2B Content Marketing Trends

What Mid-Market Leaders Need to Do Right Now Over the past year, my team and I have been doing something that’s become surprisingly rare in digital business: meeting face-to-face with our clients. Whether it's healthcare technology, B2B manufacturing, nonprofits, or...

The Cost of Not Doing Anything

The Cost of Not Doing Anything

Why B2B and Nonprofits Should Invest in Their Websites and Portals In today’s digital first world, a website or customer portal isn’t just a “nice to have” ,  it’s the foundation of your organization’s success. Yet, many B2B companies and nonprofits fall into the trap...

A Guide To The Difference Between GEO, AIO and SEO

A Guide To The Difference Between GEO, AIO and SEO

For years, we built websites to earn authority with search engines.  Recent research outlines how AI summaries replacing traditional search results and are having a tremendous negative effect on website traffic.  Since SEO is no longer driving customers to your site,...