ISC StormCast for Thursday, October 30th 2014

By Johannes Ullrich #Drupal: you are pw0n3d; MSFT readies for post SSLv3 world; #CurrentC beta leaks data; ftp command line client command exec
Drupal warns users of possible compromissed sites
https://www.drupal.org/PSA-2014-003
Microsoft Releases Fix It to disable SSLv3
https://support.microsoft.com/kb/3009008
CurrentC Beta User’s Info Exposed
http://www.imore.com/depth-look-currentc-and-personal-data-they-want-collect
GMail used by malware for command and control
http://www.wired.com/2014/10/hackers-using-gmail-drafts-update-malware-steal-data/
OS 10.10 ftp remote command exec
http://cxsecurity.com/issue/WLB-2014100174 More Here