The Register® — Biting the hand that feeds IT

Hackers crack ColdFusion

Tzael

Misleading article titles 

Coat

Damnit, where's my free energy?!

Seanmon

Cheers el reg. 

Pint

I shall point to this article next time I'm accused of slacking off reading the papers.

Virtual beer.

Nick B (Zeus)

No application firewall? 

Stop

It strikes me that whether there are known vulnerabilities or not. If you are running an ecommerce site, you should assume that there are, and that people are going to try and exploit them!

The most simple and straightforward solution would be to deploy an application firewall into your infrastructure. With the tick of a checkbox you could then turn on generic protection against this type of problem.

Simples!

Mark 18

Epic Fail! 

Pirate

El Wedge has epicly failed at the internets rofl. Link not only spelt wrong but doesn't even go to the right place when spelt right lol.

Codfusion - The for phishing and hacking of coldfusion servers?

Anonymous Coward

ColdFusion 

FAIL

The link you provided for the coldfusion vuln is not an official adobe link. You seem to imply that it is. You might have done better to at least mention the site is not the official site for CF. The title is also bunk. Hackers have not done anything. This is an example of using a default config, without hardening the system. No different than saying "hackers crack windows 2008" and then stating that the admins are not setting a password for "Administrator".

In spite of that.... I am sure there are quite a few installs of CF that are at risk due to this configuration, so it is great that you are getting the word out for them to be able to fix this.

Don Mitchell

This has been happening for a while 

This has been going on for many weeks. I know one ISP that was massively hacked via coldfusion about two weeks ago. Everyone's web pages has a one-line js script added that called some kind of Adobe Flash player exploit.

Bert 2

Adobe response 

Official Adobe response is here

http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html

Anonymous Coward

php too 

Its really a FCKEditor Security Issue, not coldfusion. The 'news' is one version of Coldfusion (8.0.1) shipped with the FCKEditor connectors enabled

php

http://secunia.com/advisories/27123/

asp

https://strikecenter.bpointsys.com/articles/permalink?title=exploiting-iis-via-htmlencode-ms08-006&month=02&year=2008&day=13

Anonymous Coward

Hotfix 

Thumb Up

http://www.adobe.com/support/security/bulletins/apsb09-09.html