Drupal 7 compromised

Dear Reader,

In case you are using Drupal 7 (!) please read this: https://www.drupal.org/security

Drupal is a content management system, software that helps one publishing online. Drupal is free and open source software and very popular, according to Wikipedia at least 2.1% of all websites worldwide use it including WhiteHouse.gov and data.gov.uk.

At one point I had considered using it too. But for Diablog, Drupal is too bloated with features and more difficult than for example WordPress.

Now I am happy we did not use it. Because according to the Drupal team, every Drupal 7 installation, that was not updated prior to October 15, is almost certainly compromised. And compromised means, someone has taken over the server and copied all data. Within less than 24 hours after a security hole and the fix were published, servers running Drupal 7 were hacked automatically.

Drupal 7 users now have to find a two week old backup, erase all data and programs on the server, re-install all software, upload the backup, and – the most tiresome – re-write everything from October 15. The poor people lost two weeks of work, what a nightmare.

Stay sane and safe,

Engine Room

