今天早上打开邮箱收到了来自Drupal官网的声明以及要求用户修改密码的邮件.大体内容就是讲述官方发行系统被外界通过在服务器上的第三方系统的漏洞而非法入侵,而不是社区网站本身自己的漏洞,用户的用户名,邮箱,以及hash过得密码库被泄露,邮件全文如下:
Dear community member,
We respect the privacy of your
information, which is why, as a precautionary measure, we are writing to
let you know about an incident that involves your personal information.
The Drupal.org Security and Infrastructure Teams have discovered
unauthorized access to account information on Drupal.org and
groups.drupal.org. Information exposed includes usernames, email
addresses, and country information, as well as hashed passwords.
However, we are still investigating the incident and may learn about
other types of information compromised, in which case we will notify you
accordingly.
This unauthorized access was made via third-party
software installed on the Drupal.org server infrastructure, and was not
the result of a vulnerability within the Drupal software itself. This
notice applies specifically to user account data stored on Drupal.org
and groups.drupal.org, and not to sites running Drupal generally.
We
have implemented additional security measures designed to prevent the
recurrence of such an attack, and to protect the privacy of our
community members.
The next time you attempt to log into your account, you will be required to create a new password.
Below
are steps you can take to further protect your personal information
online. We encourage you to take preventative measures now to help
prevent and detect the misuse of your information.
First,
we recommend as a precaution that you change or reset passwords on other
sites where you may use similar passwords, even though all passwords on
Drupal.org are stored salted and hashed. All Drupal.org passwords are
both hashed and salted, although some older passwords on
groups.drupal.org were not salted. To make your password stronger:
* Do not use passwords that are simple words or phrases
* Never use the same password on multiple sites or services
* Use different types of characters in your password (uppercase letters, lowercase letters, numbers, and symbols).
Second,
be cautious if you receive emails asking for your personal information
and be on the lookout for unwanted spam. It is not our practice to
request personal information by email. Also, beware of emails that
threaten to close your account if you do not take the "immediate action"
of providing personal information.
官方网站声明
https://drupal.org/news/130529SecurityUpdate
*Drupal在国外是一个非常流行的开源CMS框架,包括白宫在内的很多网站皆由此为基础进行构建.