<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cold Fusion web sites getting compromised in Security</title>
<link>http://www.dslreports.com/forum/r22647679</link>
<description></description>
<language>en</language>
<pubDate>Sun, 06 Dec 2009 06:03:43 EDT</pubDate>
<lastBuildDate>Sun, 06 Dec 2009 06:03:43 EDT</lastBuildDate>

<item>
<title>Re: Cold Fusion web sites getting compromised</title>
<link>http://www.dslreports.com/forum/remark,22665549</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : It's a good thing that the browser is responsible for the system.<br>Imagine if that task belonged to web content.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22665549</guid>
<pubDate>Tue, 07 Jul 2009 06:10:35 EDT</pubDate>
</item>

<item>
<title>Re: Cold Fusion web sites getting compromised</title>
<link>http://www.dslreports.com/forum/remark,22665524</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Its so easy to whack a truck load of websites it hurts, insert malware and all of a sudden its a browser problem.<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22665524</guid>
<pubDate>Tue, 07 Jul 2009 05:22:58 EDT</pubDate>
</item>

<item>
<title>Re: Cold Fusion web sites getting compromised</title>
<link>http://www.dslreports.com/forum/remark,22656825</link>
<description><![CDATA[<A HREF="/useremail/u/1019247"><b>VikingBob</b></A> : Update from ISC: &raquo;<A HREF="http://isc.sans.org/diary.html?storyid=6730" >isc.sans.org/diary.html?storyid=6730</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22656825</guid>
<pubDate>Sun, 05 Jul 2009 11:56:43 EDT</pubDate>
</item>

<item>
<title>Cold Fusion web sites getting compromised</title>
<link>http://www.dslreports.com/forum/remark,22647679</link>
<description><![CDATA[<A HREF="/useremail/u/1019247"><b>VikingBob</b></A> : From &raquo;<A HREF="http://isc.sans.org/diary.html?storyid=6715" >isc.sans.org/diary.html?storyid=6715</A><br><br>There have been a high number of Cold Fusion web sites being compromised in last 24 hours. We received several e-mails about this.<br><br>It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server.<br><br>The attacks we've been seeing in the wild end up with inserted  tags into documents on compromised web sites. As you can probably guess by now, the script tags point to a whole chain of web sites which ultimately serve malware and try to exploit vulnerabilities on clients.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22647679</guid>
<pubDate>Thu, 02 Jul 2009 22:25:17 EDT</pubDate>
</item>

</channel>
</rss>
