3 ms·
I've been building Drupal sites for 6 years, and I've never had a single one get hacked, even after I stopped updating them. It's far more likely that FTP with
by danepowell 12y ago
I've been building Drupal sites for 6 years, and I've never had a single one get hacked, even after I stopped updating them. It's far more likely that FTP with a weak password was the attack vector.
- spoiler 12y agoNot sure about Drupal, but Joomla gets targeted all the time. I don't think FTP is the attack vector. Yes, it's possible the password leaked, but it's more likely a bug in Drupal was exploited. Disclaimer: I work at a hosting company, and this is my personal experience with hacked websites.
- jauer 12y agoOn Joomla I've seen exploits via the site search feature and the admin login (I too work at a company that does hosting). I haven't seen Drupal sites get taken out.
- cholmon 12y agoIt's also likely that the vector was a vulnerable module he had installed.