[HacktionLab] Drupalgeddon v2 - The drupocalypse returns...

Mike Harris mike.harris at xtreamlab.net
Sun Mar 25 14:46:39 UTC 2018


Hi Clara,

Thanks for the tips.  My plan was to have the sites totally off-line (as
in the web server points at a different directory path entirely) and
then upgrade the installation via the console once the patches become
available.

Cheers,

Mike.


On 25/03/2018 11:37, clara wrote:
> Hi,
>
> depending on what the issue is, taking sites off-line might not be a
> sufficient precaution.
>
> What you should do in any case, is making a backup (and also testing
> that it's not broken).
>
>
> If you are not around that evening, then it would also be good to give
> somebody else access to do the upgrade on Wednesday.
>
> As far as I understand the patch will also be available for older 8.x
> versions, so you don't need to have your sites upgraded to 8.5.
>
> greetings,
> clara
>
>
> On 2018-03-25 11:47, Mike Harris wrote:
>> Thanks Kate,
>>
>> I saw this myself, what a bugger eh.  I've taken the two remaining
>> Drupal sites (as I've been migrating off Drupal where I can for various
>> reason) I have off-line for the week.
>>
>> Cheers,
>>
>> Mike.
>>
>> On 23/03/2018 11:48, Kate Dawson wrote:
>>> FYI...
>>>
>>>     https://www.drupal.org/psa-2018-001
>>>
>>> Drupal 7 and 8 core highly critical release on March 28th, 2018 PSA-2018-001
>>>
>>>
>>> Description
>>> There will be a security release of Drupal 7.x, 8.3.x, 8.4.x, and 8.5.x
>>> on March 28th 2018 between 18:00 - 19:30 UTC, one week from the
>>> publication of this document, that will fix a highly critical security
>>> vulnerability. The Drupal Security Team urges you to reserve time for
>>> core updates at that time because exploits might be developed within
>>> hours or days. Security release announcements will appear on the
>>> Drupal.org security advisory page.
>>>
>>>
>>> Have fun! 
>>>
>>>
>>>
>>>
>>> _______________________________________________
>>> HacktionLab mailing list
>>> HacktionLab at lists.aktivix.org
>>> https://lists.aktivix.org/mailman/listinfo/hacktionlab
>>
>>
>> _______________________________________________
>> HacktionLab mailing list
>> HacktionLab at lists.aktivix.org
>> https://lists.aktivix.org/mailman/listinfo/hacktionlab
>>

-- 

Mike Harris . XtreamLab
w: https://xtreamlab.net
e: mike.harris at xtreamlab.net
t: 07811 671 893
s: adelayde


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 910 bytes
Desc: OpenPGP digital signature
URL: <https://lists.aktivix.org/pipermail/hacktionlab/attachments/20180325/e7dd2abd/attachment.sig>


More information about the HacktionLab mailing list