Drupalgeddon: What happened and what lessons to remember?

Christian Hudon

You have a Drupal site and you do not know Drupalgeddon. Sorry! It may be too late!

It was a massive and dazzling attack that has contaminated thousands of websites over the last few weeks. And the level of organization to lead this attack is disturbing.

At Kiwad, we had 35 Drupal environments to upgrade, and we were also called in by other less specialized companies with Drupal. After only a few hours, we saw the first thugs appear.

The first part of this presentation will expose the nature of the fault and we will also present a panoply of elements to look at your environments to investigate a potential contamination.

In the second part of the presentation, we will present various techniques to facilitate your updates as well as methods to implement to improve the security of your sites and reduce risks.

Drupal is a registered trademark of Dries Buytaert.