OJS defacing techniques

Hello all,

We just received a message from the system managers of an OJS installation (3.0.2) which was defaced.
They sent a few links to check how to perform the attack and news on the “epidemic”. Once more, this “openjournalsystems.com” is targeting OJS, but we’d like a formal response from PKP so that we can provide a safe environment and permanent solution to this defacing problem.


HOWTO attack:


Hi @ramon,

There are two relevant responses on the PKP blog:

Alec Smecher
Public Knowledge Project Team

Thank you @asmecher!!

I hoped it was those!

Their link is down, so I can’t be sure what kind of “hacking” or defacing was done.