C5 safe?
Permalink
Hi
did you read "http://thehackernews.com/2014/11/cryptophp-backdoored-cms-plugins-themes.html" ? Is C5 safe or is it also affected?
Olaf
did you read "http://thehackernews.com/2014/11/cryptophp-backdoored-cms-plugins-themes.html" ? Is C5 safe or is it also affected?
Olaf
The report states that they found the backdoor in some joomla and wordpress plug-ins and themes and some drupal themes.
All of these were pirated themes passed on for free and they do indentify some of the websites in the report.
The important difference here is that most concrete5 themes and plug-ins come from the C5 curated marketplace which 'should' make it far more difficult to introduce malicious code.
Also the backdoor has to be specifically coded to the CMS and there was no mention of C5.
Take from this what you will, but the main issue seems to be people downloading plug ins for free that should be paid for and in the process getting 'a little extra'.