Don’t Patch-Slack!
Since upgrading my departmental website to Mambo, I’ve seen significantly more hacking attempts. This should have been expected as I have moved to a known software framework that’s executing a lot more than read calls to service Apache’s GET requests.
Earlier in the year I suffered a minor defacement to the site from a known security vulnerability. At the time, it could have been much worse. I quickly applied the appropriate patch and rolled back all of the changes to the system. Unfortunately I hadn’t learned my lesson about the importance of patching (horrible) and had let two more security patches go by without a second glance. That left me open to a similar hack but instead of pages defaced, scripts were uploaded.
2 hours of downtime had me with a snapshot of the drive for forensics and a skeleton page returned to service. If there is one lesson for SCAD and tech support young and old its keep up on your patching. It makes or breaks a secure system, and it deserves repeating ad naseaum.