Home

New Tech Heroes

New Media and Social Publishing

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Thought provoking

  • Brown Paper Tickets
  • My Best Advice About Blogging
  • Roel De Meester: Mollom: 100% protection against spam attacks
  • Why Twitter Hasn’t Failed: The Power Of Audience
  • Friday Funnies: Real Follower
  • 12 Common Blogging Mistakes To Avoid
  • What do you buy when you buy a newspaper?
  • WordPress Launches Mobile Blogging App for iPhone
more

Tag cloud

Adobe AIR amateurs Apple blog blogger blogging blogs browsers buyout CMS content management development Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla Mahalo marketing Microsoft new media online Open Source patch Plone privacy radio reputation Safari Scoble security SEO SharePoint SilverStripe social social networking social publishing spam TechCrunch Tom Kephart upgrade venture capital video virtual conversation Vista vulnerability web Web 2.0 web design WordPress Yahoo

AusCERT

Plone vulnerability being exploited on unpatched installations

Submitted by Tom Kephart on Sun, 02/24/2008 - 7:38pm.
  • AusCERT
  • Doorway Pages
  • patch
  • Plone
  • vulnerability

Trend Micro's Juan Castro reports today that a vulnerability in Plone, discovered in November 2007 by AusCERT, has cropped up on a number of sites. The exploit uses a technique called "Doorway Pages" and redirects visitors to pages that then download malware to the visitor's computer. Castro's analysis is that someone is using the vulnerability discovered by AusCERT as a redirector to hijack traffic and possibly infect computers.

The vulnerability was addressed in Plone's version 3.0.3 and legacy version 2.5.5. If you're using Plone for any of your CMS-based websites, make sure your installation is patched to the current version, which is 3.0.6, or to the latest legacy version, which is 2.5.5.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • Add a comment

New Tech Heroes

Editor: Tom Kephart

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

View Tom Kephart's profile on LinkedIn

Lijit Search


follow TomKephart at http://twitter.com

Popular content

Today's:

  • JavaScript vulnerability in Drupal prompts 6.1 release
  • Drupal issues maintenance upgrade to 5.7
  • [flashback] The Spot - lonelygirl15's beach party ancestors

All time:

  • JavaScript vulnerability in Drupal prompts 6.1 release
  • Drupal issues maintenance upgrade to 5.7
  • Scoble cries; blogosphere freaks; Jesus returns

Blogroll

CMS versions

  • Drupal 6.3
    (legacy 5.8)
  • Joomla! 1.5.4
    (legacy 1.0.15)
  • WordPress 2.6
  • Movable Type 4.12
  • Plone 3.1.2
  • CMS Made Simple 1.3.1
  • MODx 0.9.6.1
  • SilverStripe 2.2.2
  • ExpressionEngine 1.6.4
  • Alfresco Community 2.9B
  • Midgard CMS 1.8.8

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2008 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.

Kephart & Associates