Drupal sites have suffered Denial Of Service attacks when an attacker repeatedly ran the site's cron.php from the URL address line. It would be worth checking for this vulnerability and recommending the simple .htacces restriction described here: http://drupal.org/node/41049#comment-122705

Comments

coltrane’s picture

I think this would be eligible for #906726: Recommendations system

DrewMathers’s picture

Status: Active » Closed (duplicate)