I have seen evidence of SPAM spiders hunting for BAKE'd Cake sites
with unprotected admin urls. They are simply using the model names
from urls and hitting model/admin/add model/admin/edit/n in the access
logs. May seem obvious but check you lock down your admin methods and
remove unwanted baked methods. We did actually get hit by this but the
table was overwritten hourly from an external source so took us a
while to notice (Forgot to remove the un-needed baked controller).

Anyone else seen CakePHP directly targetted by SPAMers / Hackers?

Check out the new CakePHP Questions site http://cakeqs.org and help others with 
their CakePHP related questions.

You received this message because you are subscribed to the Google Groups 
"CakePHP" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected] For more options, visit this group at 
http://groups.google.com/group/cake-php?hl=en

Reply via email to