Skip to content

Comment on One of my Drupal sites was hackedparent

Comments

Agree!

You don't need to bother with old-school stuff like grsec, iptables, IDS, chrooted applications or any stack-protection technologies.

Get a WAF, audit your web-app source-code and use a pen-test tool regularly instead.

SQL-injections walk right in, through the front door. They stuff their pockets full of data and then leave the same way they came, unnoticed most of the time.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.