Read article about LizaMoon mass-injection. Is Evo/Revo safe for these injection.
Here`s the article:
http://community.websense.com/blogs/securitylabs/archive/2011/03/31/update-on-lizamoon-mass-injection.aspx
[update] Or... is this just April Fools’ Day hoax.
Tassu, webmaster of Valokammi
-
☆ A M B ☆
- 24,524 Posts
If it’s an SQL injection problem as they seem to think, then MODx itself is quite safe from it. Any custom or third-party applications that don’t thoroughly validate and sanitize all user input would be vulnerable, but that’s not something MODx has any control over. Kind of like the scam emails that offer to share x million dollars with you, I have to wonder who isn’t aware of this sort of thing by now, that somebody is obviously writing scripts that don’t take care of the problem.
Interesting that all of the databases they’ve found this in are MSSQL databases.