How do I put an end to this reoccurring CMS/hosting security breach?
January 10, 2009 11:06 PM Subscribe
How do I put an end to this reoccurring CMS/hosting security breach?
I am using Drupal as a CMS and all my sites are hosted through the same provider. On a few of my installs (version 6.8 - the latest of Drupal) mysterious directorys full of porn and prescription drug HTML pages keeps occuring. Said host said this was due to a security breach in my CMS, which I do believe. How do I stop it though? I delete these folders when I notice inbound traffic in analytics but I want to solve this problem once and for all. If anybody has any advice or experience with this kind of situation please clue me in.
posted by serial_consign to computers & internet (12 answers total) 1 user marked this as a favorite
The only things I can think of would be:
- Make sure that your Drupal install always has the most recent version of the software.
- Change your login often, not just for Drupal but for your FTP and admin access to the webserver as well.
- Is there any way that you can ask your hosting company to only allow uploads of content to your domain from set IP addresses?
posted by gemmy at 12:04 AM on January 11, 2009