DrupalCon Barcelona 2015: Drupal and Security: what you need to know
About this talk
This talk focuses on the growing security challenges faced by organizations using Drupal, especially in light of the recent SA-CORE-2014-005 vulnerability that exposed significant risks. The speaker discusses common security issues, emphasizing the responsibilities of site builders and maintainers in mitigating risks associated with automated attacks on Drupal sites. Participants can expect to learn about proper password management, ways to defend against DDoS attacks, and the importance of quick updates. Additionally, the session covers best practices for evaluating contributed module quality and provides a developer cheat sheet to protect against vulnerabilities like XSS, SQL injection, and CSRF, highlighting security enhancements in Drupal 7 and 8.