Automated reply sent by security.drupal.org automatically

Last updated on
14 January 2021

[Note: This is installed at http://lists.drupal.org/admin/security/?VARHELP=autoreply/autoresponse_p...

[Note: This message is also sent to users who use the Drupal.org contact form to mail the security team at http://drupal.org/admin/build/contact/edit/1]

[Note: It has to be manually synched, so if you edit it ask someone to synch it to those locations]

Thank you for contacting the Drupal security team.

All e-mails sent to us are read by a member of the team and acted upon if necessary.

The Drupal security team is a volunteer group concerned with the quality of the Drupal source code from a security perspective. That is, we work to ensure the Drupal software is free from errors which would allow various kinds of security breaches and attacks. This work includes not only releasing security announcements and fixes but also educating the developer community on best practices to avoid such problems.

Please be aware that the security team deals only with code hosted on drupal.org -- we do not provide support for individual sites which have been defaced or hacked, or for issues which are not related to security.
We have developed a FAQ at http://drupal.org/security-team/FAQ

The Drupal Security team has been receiving an increasing number of reports about hacked sites since the release of https://www.drupal.org/SA-CORE-2014-005 in October 2014. Because automated attacks started within hours and many sites were not updated on time, it is believed that many Drupal 7 sites have been hacked. If you are reporting a hacked site, you have most likely been affected by those attacks.

The follow-up PSA has more information: https://www.drupal.org/PSA-2014-003

If your site was hacked and your first message to the security team didn't follow the template at http://drupal.org/node/213320#template , please send a new message following that template.

If your e-mail resembles one of the following examples, then your query does not fall within our purpose, and you may not receive a further reply. If that is the case, we hope this brief guide will enable you to find alternative sources of support:

a) "My site is hacked! Help!"
Any Drupal installation can be made insecure through poor configuration, through a contributed or site-specific module with a security hole, or through other software running on the same host.

Check that you are using the update status module (this is part of Drupal 6 and Drupal 7 core), as it could alert you when new security and bug fix releases are available.

Also note that filter configurations can make your site insecure, as detailed here: http://drupal.org/node/224921 and http://heine.familiedeelstra.com/input-formats-beware

A general guide to common security issues is available here:
http://drupal.org/node/213320

A general trouble-shooting guide which can help to solve common issues which might not be directly related to security:
http://drupal.org/Troubleshooting-FAQ

See also b).

b) I want to do foo and bar with Drupal...

The security team does not provide site-specific support. If you need professional support, please hire a consultant, such as from the list at http://drupal.org/drupal-services or choose from the range of support options at http://drupal.org/support

c) "This site is using Drupal in an inappropriate way. I will sue you for libel, hate speech, etc."

The Drupal project has nothing to do with any Drupal site (aside from drupal.org) and the GPL license that Drupal is provided under prevents us from intervening in uses of the source code. Please contact the site owners instead of us.

d) "My personal details were posted on Drupal.org, someone defamed my company, etc."

Please open an issue for the Drupal.org site moderators at http://drupal.org/node/add/project-issue/site_moderators 

e) "I can't log in to Drupal.org. Help!"

Please send a message to help@drupal.org and the Drupal Association staff member will help you out.

f) I have a general question about Drupal and security

Please use the discussion group at http://groups.drupal.org/best-practices-drupal-security though note it is not for reporting confidential security issues.

Help improve this page

Page status: No known problems

You can: