Re: [CODE4LIB] Terrible Drupal vulnerability

2014-11-12 Thread Heidi P Frank
/ From: Code for Libraries [CODE4LIB@LISTSERV.ND.EDU javascript:;] on behalf of Lin, Kun [l...@cua.edu javascript:;] Sent: Friday, October 31, 2014 2:10 PM To: CODE4LIB@LISTSERV.ND.EDU javascript:; Subject: Re: [CODE4LIB] Terrible Drupal vulnerability I

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-11-12 Thread Edward Iglesias
: Friday, October 31, 2014 2:10 PM To: CODE4LIB@LISTSERV.ND.EDU javascript:; Subject: Re: [CODE4LIB] Terrible Drupal vulnerability I think so. However, Cloudflare in their blog post claim they have develop a way to block the attack immediately when the vulnerability was announced

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-11-11 Thread Heidi P Frank
Sent: Friday, October 31, 2014 1:44 PM To: CODE4LIB@LISTSERV.ND.EDU javascript:; Subject: Re: [CODE4LIB] Terrible Drupal vulnerability The vulnerability was discovered in the course of an audit by SektionEins, a German security firm, and immediately reported to the Drupal Security Team

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-11-11 Thread Cary Gordon
Gordon Sent: Friday, October 31, 2014 1:44 PM To: CODE4LIB@LISTSERV.ND.EDU javascript:; Subject: Re: [CODE4LIB] Terrible Drupal vulnerability The vulnerability was discovered in the course of an audit by SektionEins, a German security firm, and immediately reported to the Drupal Security

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-11-02 Thread Cary Gordon
:;] Sent: Friday, October 31, 2014 2:10 PM To: CODE4LIB@LISTSERV.ND.EDU javascript:; Subject: Re: [CODE4LIB] Terrible Drupal vulnerability I think so. However, Cloudflare in their blog post claim they have develop a way to block the attack immediately when the vulnerability was announced

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Cary Gordon
This is what I posted to the Drupal4Lib list: By now, you should have seen https://www.drupal.org/PSA-2014-003 and heard about the Drupageddon exploits. and you may be wondering if you were vulnerable or iff you were hit by this, how you can tell and what you should do.

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Lin, Kun
@LISTSERV.ND.EDU] On Behalf Of Cary Gordon Sent: Friday, October 31, 2014 9:59 AM To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability This is what I posted to the Drupal4Lib list: By now, you should have seen https://www.drupal.org/PSA-2014-003 and heard

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Cary Gordon
] Terrible Drupal vulnerability This is what I posted to the Drupal4Lib list: By now, you should have seen https://www.drupal.org/PSA-2014-003 and heard about the Drupageddon exploits. and you may be wondering if you were vulnerable or iff you were hit by this, how you

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Lin, Kun
] On Behalf Of Cary Gordon Sent: Friday, October 31, 2014 11:10 AM To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability How do they receive vulnerability report ahead of general public? From whom? Cary On Friday, October 31, 2014, Lin, Kun l...@cua.edu wrote

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Joe Hourcle
-Original Message- From: Code for Libraries [mailto:CODE4LIB@LISTSERV.ND.EDU] On Behalf Of Cary Gordon Sent: Friday, October 31, 2014 11:10 AM To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability How do they receive vulnerability report ahead

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Kevin Reiss
for Libraries [mailto:CODE4LIB@LISTSERV.ND.EDU] On Behalf Of Cary Gordon Sent: Friday, October 31, 2014 11:10 AM To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability How do they receive vulnerability report ahead of general public? From whom? Cary

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Cary Gordon
, October 31, 2014 11:10 AM To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability How do they receive vulnerability report ahead of general public? From whom? Cary On Friday, October 31, 2014, Lin, Kun l...@cua.edu wrote: If you are using drupal as main

Re: [CODE4LIB] Terrible Drupal vulnerability

2014-10-31 Thread Lin, Kun
To: CODE4LIB@LISTSERV.ND.EDU Subject: Re: [CODE4LIB] Terrible Drupal vulnerability The vulnerability was discovered in the course of an audit by SektionEins, a German security firm, and immediately reported to the Drupal Security Team. Because this was a pretty obscure vulnerability with no reported