Home

New Tech Heroes

New Media and Social Publishing

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Thought provoking

  • Goodbye, BitTorrent. Hello, Streaming.
  • How to Find Statistics on Social Media
  • Jaiku Uncaps Invites, Migrates to Google Infrastructure
  • David Peterson - Sitepoint: Rasmus Lerdorf - PHP frameworks? Think again.
  • Free Replacements for Paid Tools
  • 17 Easy Tips to Improve your Google Rank with Blogs
  • The first law of mass media
  • Out of Africa
more

Tag cloud

Adobe AIR amateurs Apple blog blogger blogging blogs browsers buyout CMS content management development Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla Mahalo marketing Microsoft new media online Open Source patch Plone privacy radio reputation Safari Scoble security SEO SharePoint SilverStripe social social networking social publishing spam TechCrunch Tom Kephart upgrade venture capital video virtual conversation Vista vulnerability web Web 2.0 web design WordPress Yahoo

Doorway Pages

Plone vulnerability being exploited on unpatched installations

Submitted by Tom Kephart on Sun, 02/24/2008 - 7:38pm.
  • AusCERT
  • Doorway Pages
  • patch
  • Plone
  • vulnerability

Trend Micro's Juan Castro reports today that a vulnerability in Plone, discovered in November 2007 by AusCERT, has cropped up on a number of sites. The exploit uses a technique called "Doorway Pages" and redirects visitors to pages that then download malware to the visitor's computer. Castro's analysis is that someone is using the vulnerability discovered by AusCERT as a redirector to hijack traffic and possibly infect computers.

The vulnerability was addressed in Plone's version 3.0.3 and legacy version 2.5.5. If you're using Plone for any of your CMS-based websites, make sure your installation is patched to the current version, which is 3.0.6, or to the latest legacy version, which is 2.5.5.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • Add a comment

New Tech Heroes

Editor: Tom Kephart

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

View Tom Kephart's profile on LinkedIn

Lijit Search


follow TomKephart at http://twitter.com

Popular content

Today's:

  • Joomla releases version 1.5.3
  • Joomla patches to 1.0.15 to fix a "security vulnerability"
  • Girls are more likely to be bloggers or designers than boys

All time:

  • JavaScript vulnerability in Drupal prompts 6.1 release
  • Drupal issues maintenance upgrade to 5.7
  • Scoble cries; blogosphere freaks; Jesus returns

Blogroll

CMS versions

  • Drupal 6.3
    (legacy 5.8)
  • Joomla! 1.5.4
    (legacy 1.0.15)
  • WordPress 2.6
  • Movable Type 4.12
  • Plone 3.1.2
  • CMS Made Simple 1.3.1
  • MODx 0.9.6.1
  • SilverStripe 2.2.2
  • ExpressionEngine 1.6.4
  • Alfresco Community 2.9B
  • Midgard CMS 1.8.8

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2008 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.

Kephart & Associates