Forum Moderators: open
Drupal Warns – Most Drupal 7 Sites Compromised Unless Patched on Oct 15
[edited by: lorax at 6:10 pm (utc) on Oct 30, 2014]
Simply updating to Drupal 7.32 will not remove backdoors.
If you have not updated or applied this patch, do so immediately, then continue reading this announcement; updating to version 7.32 or applying the patch fixes the vulnerability but does not fix an already compromised website. If you find that your site is already patched but you didn’t do it, that can be a symptom that the site was compromised - some attacks have applied the patch as a way to guarantee they are the only attacker in control of the site. Drupal Core - Highly Critical - Public Service announcement [drupal.org]
are you now glad that I made you "git" with the program?