Drupal xmlrpc.php exploit

Due to a fault in an underlying code library used by Drupal, the XML-RPC mechanism for barnson.org has been temporarily disabled.

This probably doesn’t mean anything to regular users, except that you can’t log on using a Drupal, Blogger, Yahoo, or other non-Barnson.org ID. Which is only Paul, and he knows what’s up 🙂 Also, the site feed on the left hand side from Jen Gagne, Jay Barnson, and others won’t update until I fix it.

Due to a fault in an underlying code library used by Drupal, the XML-RPC mechanism for barnson.org has been temporarily disabled.

This probably doesn’t mean anything to regular users, except that you can’t log on using a Drupal, Blogger, Yahoo, or other non-Barnson.org ID. Which is only Paul, and he knows what’s up 🙂 Also, the site feed on the left hand side from Jen Gagne, Jay Barnson, and others won’t update until I fix it.

For the time being, I’m just leaving it disabled until I can fix it tonight. I work nights now, so I have to get some rest. Glad there’s a minimally-impacting workaround so I don’t have to spend the next 2 hours upgrading my software…

2 thoughts on “Drupal xmlrpc.php exploit”

  1. Turned it back on…

    Turned it back on, since I upgraded to Drupal 4.6.3. Always creepy when that type of stuff happens, though, it bit one of my friends 😉


    Matthew P. Barnson

    1. I’m up…

      I have trouble upgrading from 4.5.2 to 4.6.3 so I updated to 4.5.3. The Drupal folks claim 4.5.3 is secure. We shall see…

      — Paul PHP Geek. Comedian. Laugh, already.

Comments are closed.