Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Cold Fusion web sites getting compromised
Search Topic:
Uniqs:
375
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 06 Jul 2009 »
« (topic move) Router session  
AuthorAll Replies


VikingBob

join:2004-06-05
Ste Anne, MB
·MTS

 Cold Fusion web sites getting compromised

From »isc.sans.org/diary.html?storyid=6715

There have been a high number of Cold Fusion web sites being compromised in last 24 hours. We received several e-mails about this.

It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server.

The attacks we've been seeing in the wild end up with inserted tags into documents on compromised web sites. As you can probably guess by now, the script tags point to a whole chain of web sites which ultimately serve malware and try to exploit vulnerabilities on clients.


VikingBob

join:2004-06-05
Ste Anne, MB
Update from ISC: »isc.sans.org/diary.html?storyid=6730


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
reply to VikingBob
Its so easy to whack a truck load of websites it hurts, insert malware and all of a sudden its a browser problem.

Blake


SnowyOne
Premium
join:2003-04-05
Kailua, HI
It's a good thing that the browser is responsible for the system.
Imagine if that task belonged to web content.
-
Forums » Up and Running » Security » SecuritySecurity Software Updates - 06 Jul 2009 »
« (topic move) Router session  


Thursday, 03-Dec 01:31:38 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [95] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [55] Rogers Unveils The ISP Dream Model
· [55] Avast Antivirus Has Gone Mad
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [39] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· [Equipment] Ubiquiti third party firmware for the M series Bulle [Wireless Service Providers]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Albums to get a stressed person in the Christmas spirit? [General Questions]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· Working in a Stairwell and Surrounding High Walls [Home Repair & Improvement]
· Tomato/MLPPP v3 alpha 6 released! [TekSavvy]
· Poll: Have you ever been charged an overage fee since ... [TekSavvy]
· [WIN7] When exactly should you flash bios when installing new OS [Microsoft Help]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]