[drupal-support] Drupal 4.6.3 released (security alert)

risiyanto budi risiyanto at budi.or.id
Tue Aug 16 03:26:13 UTC 2005


Rob wrote:

> Using a remote posting tool was one of the main reasons I picked 
> Drupal. I use BlogJet and can post entries in just a few seconds which 
> saves me a lot of time. If the file is deleted will that prevent me 
> from ever using remote applications again?
>
> Rob
>
Thats right,
to overcome this situation, you can restrict access to this xmlrcp.php 
to serve  your IP (network) only.
But i'm not sure how to do that, since i don't know how this xmlrpc works.

Thanks
Aris




More information about the drupal-support mailing list