Re: Fwd: Re: Security support for CMSes

2012-10-08 Thread Jon Dowland
On Sun, Oct 07, 2012 at 08:41:14PM +0200, Robert Pommrich wrote: > Putting it back to the list where it came from. It was already there. I'm not sure what you've done to your mail configuration, but list mail is working fine: no need to forward more copies to it. -- To UNSUBSCRIBE, email to deb

Re: Re: Security support for CMSes

2012-10-07 Thread Jan Ingvoldstad
On Mon, Oct 8, 2012 at 12:18 AM, Peter Viskup wrote: > Overlooked it was not sent to debian-user list. > … > I do not know what security issue was used to crack my site - they used > some Drupal weakness to create some php files in Drupal install dir > remotely and without getting SFTP access.

Fwd: Re: Security support for CMSes

2012-10-07 Thread Peter Viskup
Overlooked it was not sent to debian-user list. Original Message Subject:Re: Security support for CMSes Date: Mon, 08 Oct 2012 00:07:56 +0200 From: Peter Viskup To: Robert Pommrich , lu...@debian.org, secur...@debian.org Hello Nico, On 10/07/2012 08:25 PM

Fwd: Re: Security support for CMSes

2012-10-07 Thread Robert Pommrich
Putting it back to the list where it came from. Original-Nachricht Betreff: Re: Security support for CMSes Datum: Sun, 7 Oct 2012 20:25:11 +0200 Von: Nico Golde An: Robert Pommrich Kopie (CC): lu...@debian.org, secur...@debian.org Hi, * Robert Pommrich [2012-10-07 16:01

Re: Security support for CMSes

2012-10-07 Thread Nico Golde
Hi, * Robert Pommrich [2012-10-07 16:01]: > Am 07.10.2012 12:19, schrieb Peter Viskup: > > Hello everybody, > > I am using Drupal6 from Debian repositories as I thought that Debian is > > taking care of the security fixes and therefore I do not have to take > > care too much. > > Unfortunately one

Re: Security support for CMSes

2012-10-07 Thread Wolf Halton
Wolf Halton http://sourcefreedom.com Apache developer: wolfhal...@apache.org On Oct 7, 2012 11:54 AM, "Johan Grönqvist" wrote: > > 2012-10-07 17:38, Wolf Halton skrev: > >> The reason to have a drupal package or any other community or multiverse >> package is most likely that somebody had the incl

Re: Security support for CMSes

2012-10-07 Thread Wolf Halton
Wolf Halton http://sourcefreedom.com Apache developer: wolfhal...@apache.org On Oct 7, 2012 10:01 AM, "Robert Pommrich" wrote: > > Hi, > > Am 07.10.2012 12:19, schrieb Peter Viskup: > > Hello everybody, > > I am using Drupal6 from Debian repositories as I thought that Debian is > > taking care of

Re: Security support for CMSes

2012-10-07 Thread Robert Pommrich
Hi, Am 07.10.2012 12:19, schrieb Peter Viskup: > Hello everybody, > I am using Drupal6 from Debian repositories as I thought that Debian is > taking care of the security fixes and therefore I do not have to take > care too much. > Unfortunately one of my sites was cracked and there were none of >

Re: Security support for CMSes

2012-10-07 Thread Rob Owens
On Sun, Oct 07, 2012 at 09:02:23AM -0400, Wolf Halton wrote: > I am sorry to hear your site was cracked. I run Drupal on Debian as well. > The fundamental flaw here is the lag time between drupal update and > packaging on debian. I run drupal 7 for new sites. Installs are not the > simplest things

Re: Security support for CMSes

2012-10-07 Thread Wolf Halton
I am sorry to hear your site was cracked. I run Drupal on Debian as well. The fundamental flaw here is the lag time between drupal update and packaging on debian. I run drupal 7 for new sites. Installs are not the simplest things in the world, but it comes in handy in an ongoing fashion to have don

Security support for CMSes

2012-10-07 Thread Peter Viskup
Hello everybody, I am using Drupal6 from Debian repositories as I thought that Debian is taking care of the security fixes and therefore I do not have to take care too much. Unfortunately one of my sites was cracked and there were none of security fixes released in June 2012 by Drupal community