republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Cold Fusion web sites getting compromised
Search Topic:
Uniqs:
368
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 06 Jul 2009 »
« (topic move) Router session  
AuthorAll Replies


VikingBob

join:2004-06-05
Ste Anne, MB
·MTS

 Cold Fusion web sites getting compromised

From »isc.sans.org/diary.html?storyid=6715

There have been a high number of Cold Fusion web sites being compromised in last 24 hours. We received several e-mails about this.

It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server.

The attacks we've been seeing in the wild end up with inserted tags into documents on compromised web sites. As you can probably guess by now, the script tags point to a whole chain of web sites which ultimately serve malware and try to exploit vulnerabilities on clients.


VikingBob

join:2004-06-05
Ste Anne, MB
Update from ISC: »isc.sans.org/diary.html?storyid=6730


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
reply to VikingBob
Its so easy to whack a truck load of websites it hurts, insert malware and all of a sudden its a browser problem.

Blake


SnowyOne
Premium
join:2003-04-05
Kailua, HI
It's a good thing that the browser is responsible for the system.
Imagine if that task belonged to web content.
-
Forums » Up and Running » Security » SecuritySecurity Software Updates - 06 Jul 2009 »
« (topic move) Router session  


Tuesday, 10-Nov 00:08:33 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [82] VoIP Over 3G Still Not Working For iPhone
· [77] Verizon Keeps Swinging At AT&T
· [33] Bill Would Force ISPs To Block Financial Scams
· [21] Mediacom Hints At 50, 100 Mbps Speeds
· [13] Clearwire To Get Another $1.5 Billion
· [10] Monday Morning Links
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [5] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· Framed for child porn 151; by a PC virus [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· How in the world am I going to get into college? [General Questions]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· 60 Minutes piece on cyber security last night [Security]
· Massive Slowdowns? [cover,1584]
· Blown out Ballasts [Home Repair & Improvement]
· My cat is reluctant to exercise. [General Questions]
· [SU] Apple Releases Mac OS X 10.6.2 [All Things Macintosh]