REMINDER: Remove XMLRPC from your site!
Auteur Sujet
Post 
Résumé :

We'd like to remind all admins about the latest PNSA 2005-3 - "Remote Code Injection via XML RPC (third party library used in PostNuke CMS < .760)"

If you have not already done this please follow the instructions ASAP - because there are already a couple of defacement reports.

Admins are also advised to use only the latest release builds (.750b for production and .760 RC5 for testing enviroments) and to check third party modules for security related issues - e.g. SPChat and PNphpBB have been also targeted lately (check the maintainer's sites for more information on this).

For some extra security the PostNuke Development Team additionally recommends running the webserver with register_globals=off and magic_quotes_gpc=on (see our Developer Blog for more information on this)


http://news.postnuke.com/index.php?...rticle&sid=2713

Données personnelles