RE: [ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit

2013-05-09 Thread Charlie Arehart
er use it anyway.) /charlie From: ad...@acfug.org [mailto:ad...@acfug.org] On Behalf Of Frank Moorman Sent: Thursday, May 09, 2013 3:54 AM To: discussion@acfug.org Subject: [ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit All, In case you have not heard... A

Re: [ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit

2013-05-09 Thread John Mason
95% of the security issues that have come up lately have basically been around the same thing, locking down those areas. John ma...@fusionlink.com On 5/9/13 10:04 AM, Ajas Mohammed wrote: Nevermind, Charlie has links (How to lock down the /adminapi, /administrator, and /componentutils directo

Re: [ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit

2013-05-09 Thread Ajas Mohammed
Nevermind, Charlie has links (How to lock down the /adminapi, /administrator, and /componentutils directories) in his blog post here http://www.carehart.org/blog/client/index.cfm/2013/1/2/Part2_serious_security_threat iUseDropbox(http://db.tt/63Lvone9) http://ajashadi.blogspot.com We cannot becom

Re: [ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit

2013-05-09 Thread Ajas Mohammed
Does anyone have instructions for IIS 6.0 ? iUseDropbox(http://db.tt/63Lvone9) http://ajashadi.blogspot.com We cannot become what we need to be, remaining what we are. No matter what, find a way. Because thats what winners do. You can't improve what you don't measure. Quality is never an accident

[ACFUG Discuss] FYI - Security Advisory for ColdFusion - Active zero day exploit

2013-05-09 Thread Frank Moorman
All, In case you have not heard... Adobe mentioned this last night... https://www.adobe.com/support/security/advisories/apsa13-03.html Essentially, the believe the exploit is already out there and is actively infecting systems. However, it can be prevented through access controls on the CFID