Does anyone have a fix or know how drupal is being exploited to allow posting for this JohnTT user? A lot of sites seem to be affected by this, just search JohnTT in google, network world, kde and others are being exploited. Is there a security update or fix for this issue? Thanks!

Comments

bdragon’s picture

Project: Drupal core » Drupal.org site moderators
Version: 5.6 »
Component: base system » Other
Category: bug » support
Priority: Critical » Normal

Moving to webmasters queue, which is STILL the wrong place, but at least it's the RIGHT wrong place.

sepeck’s picture

Status: Active » Closed (won't fix)

Those sites would need to implement some of the spam modules or captcha. This is not an exploit, but a configuration for those sites having this issue. There is really no information in this report to indicate otherwise.