Re: FYI - New ColdFusion Security Issue

2013-01-02 Thread Greg Morphis
I'm on ISS 7.5, how does one lock down the administrator and adminapi folders? On Wed, Jan 2, 2013 at 1:40 PM, Michael Dinowitz wrote: > > If anyone has been hit, please send me the file so I can compare it to a > previous attack file. > > Thanks > > On Wed, Jan 2, 2013 at 2:31 PM, Cameron Chi

Re: FYI - New ColdFusion Security Issue

2013-01-02 Thread Michael Dinowitz
If anyone has been hit, please send me the file so I can compare it to a previous attack file. Thanks On Wed, Jan 2, 2013 at 2:31 PM, Cameron Childress wrote: > > > http://www.carehart.org/blog/client/index.cfm/2013/1/2/serious_security_threat > > Check your CFIDE directory for a file named "h.

FYI - New ColdFusion Security Issue

2013-01-02 Thread Cameron Childress
http://www.carehart.org/blog/client/index.cfm/2013/1/2/serious_security_threat Check your CFIDE directory for a file named "h.cfm". If present, you've likely been hit. Anyone see this on your servers? -Cameron ... ~| Order th