Home

New Tech Heroes

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Tag cloud

AIR Apple blog blogger blogging blogs browsers buyout chris brogan CMS content management Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla Mahalo media Microsoft MySpace new media newspapers offline online Open Source patch Plone privacy radio reputation Safari Scoble security SharePoint social media social networking social publishing spam TechCrunch television Tom Kephart Twitter upgrade video virtual conversation Vista vulnerability web Web 2.0 web design WordPress Yahoo

Plone vulnerability being exploited on unpatched installations

Submitted by Tom Kephart on Sun, 02/24/2008 - 7:38pm.
  • AusCERT
  • Doorway Pages
  • patch
  • Plone
  • vulnerability

Trend Micro's Juan Castro reports today that a vulnerability in Plone, discovered in November 2007 by AusCERT, has cropped up on a number of sites. The exploit uses a technique called "Doorway Pages" and redirects visitors to pages that then download malware to the visitor's computer. Castro's analysis is that someone is using the vulnerability discovered by AusCERT as a redirector to hijack traffic and possibly infect computers.

The vulnerability was addressed in Plone's version 3.0.3 and legacy version 2.5.5. If you're using Plone for any of your CMS-based websites, make sure your installation is patched to the current version, which is 3.0.6, or to the latest legacy version, which is 2.5.5.

Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Facebook Facebook

Post new comment

The content of this field is kept private and will not be shown publicly.
Input format
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <b> <address> <blockquote> <br> <caption> <center> <code> <dd> <del> <div> <dl> <dt> <em> <font> <h2> <h3> <h4> <h5> <h6> <hr> <i> <img> <li> <ol> <p> <pre> <span> <strong> <sub> <sup> <table> <tbody> <td> <tfoot> <th> <thead> <tr> <u> <ul> <tr>
  • Lines and paragraphs break automatically.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Editor: Tom Kephart

View Tom Kephart's profile on LinkedIn

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

New Tech Heroes at Blogged

Lijit Search


follow TomKephart at http://twitter.com

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2009 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.