The security has written a security alert about a huge wave of attacks against content management systems. Also TYPO3 is one of the affected systems beside Joomla and other ones.
The team didn't found any security vulnerability in the TYPO3 core itself but they have information about problems with third party extensions. So please make sure, that you have always the most recent versions installed!
The attacks introduce iframes on the sites which loads external content from other pages. They don't do any harm now but that can change very fast.
If you understand german, you can read the security team blog. An english version is promised for later today.
[UPDATE]
Ekki has now released an official entry about this: Massive Web Server Hacks (”iFrame Attacks”) - Now Extended To TYPO3
[/UPDATE]
Greets,
Thomas
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Jun | Aug » | |||||
| 1 | ||||||
| 02 | 3 | 4 | 05 | 06 | 7 | 08 |
| 09 | 10 | 11 | 12 | 13 | 14 | 15 |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 | 25 | 26 | 27 | 28 | 29 |
| 30 | 31 | |||||
Well, one can live only so long by basically exploiting oneself, so I think it's very understood in...
As you mentioned above, " it is much faster to copy and paste the needed stuff from other files." ...
Thanks for your great work and good luck!
++ Michael Cannon! Thanks Thomas for all your work, don't disappear! I read your blog regularly ...
At the first glance it seems to be a pity, that you've stopped working at the installer ( I really ...
#1: cecio commented on Friday, 06-07-07 18:33
any clue on the english version or updates?
i found most of my typo3 websites (4.1.1 latest updates) to be infected by the iframe attack!!!!
and never intalled sqldumper anywhere :(