[Nfb-web] Update Your Software

David Andrews dandrews at visi.com
Thu Jul 16 02:23:53 UTC 2015


Hello,

I have added some people to the hidden webmasters list.  My records 
are mostly up to date.  I will repeat part of what I said yesterday, 
for new folks.

One of our sites was hacked, we think in part because Drupal was not 
at the latest version and was hacked.  Consequently we need to take 
care of some business!


Yesterday I wrote you about the need to keep software updated.  As an 
example, we updated PHP and Easy Apache this morning on the 
server.  Jason has scanned  the server to see what software you have, 
and what version.  Below is that information.  Please bring 
everything up to the latest version, and delete the stuff you don't need.


Hi,
I took a look at the versions of Drupal running on the system. The
latest version is 7.38.
Here is a list of the sites, and what version they have installed. We
should hound anyone with outdated versions.

blindeducators: 7.38
nabskid: 7.37 in main directory, but they have a backup directory that
has 7.12 that may still be accessible from the net.
nagdu: 7.38
nfbmd: 7.34 (this needs to be updated now!)
nfbmo: 7.37
nfbsc: 7.14
nfbtrain: 7.14
nfbweb: 7.28 (this is in a sandbox directory, so not sure if this is active)
nfbwy: 7.34
Stevebrand: 7.34


And here is Wordpress info:


Hi,
I'm seeing a similar issue with Wordpress. We have a few sites running
it and they are not all up to date. Wordpress only releases security
updates for the current version, which is currently 4.2.
Additionally, nfb of ohio seems to have a site that isn't running a
CMS, but they have what looks like an old version of Joomla in their
public_html folder. They should get rid of that if they aren't using
it. If they are using it, it should be updated




         David Andrews and long white cane Harry.
E-Mail:  dandrews at visi.com or david.andrews at nfbnet.org





More information about the NFB-Web mailing list