It's about web security , but this article contains many lies that we are saying or thinking about and never try to make sure that we are not going to fall in it. These lies about web security . 1- The Lock icon is lighting on , it's ok it's amazing that everyone looks for the lock int he browser bar to believe that this site so secure, it's a big lie . you are not safe . the lock in the browser bar doesn't mean that you are fully secure , it's only the SSL , means that the data are transferred in secure way . but the agent(Hacker) who get the info can use it easily. Note : some Hackers are very good at faking SSL certificate or buying one . 2- Website Reputation It's not true that if you don't visit websites of ill repute , you are in all clear ,No No! Wrong answer. more than 83% of malware hosting sites are trusted. 3- Don't underestimate the information in your computer . This is the most dangerous poin...
Posted by Drupal Security Team on October 15, 2014 at 4:02pm Advisory ID: DRUPAL-SA-CORE-2014-005 Project: Drupal core Version: 7.x Date: 2014-Oct-15 Security risk: 25/25 ( Highly Critical ) AC:None/A:None/CI:All/II:All/E:Exploit/TD:All Vulnerability: SQL Injection Description Drupal 7 includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks. A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution, or other attacks. This vulnerability can be exploited by anonymous users. Update: Multiple exploits have been reported in the wild following the release of this security advisory, and Drupal 7 sites which did not update soon after the advisory was released may be compromised. See this follow-...