Forum archive
Drupal Oct 2014 Vun & TKBLM
Hello, I did not have time to patch my server during the small window that was recommended when the Oct 2014 critical sql injection bug was revealed. My server does not appear to be infected but of course you never know.
I want to make sure my server is put into an uninfected state. So would restoring from a TKBLM backup from just before the vulnerability went public be enough to roll back any potential malicious programs that may have been installed? I'm guessing no since TKBLM is kind of selective.
Conversely, would starting a fresh Drupal 7 instance that is fully patched and then using TKBLM to import the current state of my potentially infected server pose a risk of carrying over potential infections? I'm am guessing yes.
Thus is my best option to use a snapshot from the hub.turnkeylinux.org that predates the known explotation of the SQL vunerability? I would assume this is pretty failsafe but my only choice is a snapshot months before Oct and I would lose a lot of content. Incidentally, I cant get any of the content exporting modules to work as I get SQL errors upon enabling them and then they never show up in my admin config. (Makes me think I may have been compormised as Iv never had this problem)
Thanks
Assuming that you are using a TKLBAM backup then yes restore pre Oct 15 TKLBAM backup on a new Drupal instance.
Also my inclination would be to keep the old server running for now and manually migrate the post Oct 15 content i.e. copy/paste... Once you have everything you want off it then just destroy it.
Like I said though, I'd strongly suggest that you enable daily TKLBAM backups and keep at least 3 months worth (i.e. 3 sets assuming monthly full backups).