Truth be told, I've never tried it in CFMX (which a fast analysis shows the
scammers to be using). I'll have to review the CF admin and CFDocs code to see
if a hole exists. It's a time thing which I don't have at the moment. In all
truth, I expect there to be a hole or two just waiting for me to find and
report.

> Michael,
>
> I found an article (http://www.fusionauthority.com/Article.cfm?ArticleID=2539)
where you talk about this "turning off security" method ... in this article you
illustrate how to fix this hole, but ethically chose not to expose the secret.
>
> My curiosity is peaked and I want to know more! Would you care to share the
details with the list so that we can all go over there "play around" on the
spammers backend? =)
>
> GregL
>   ----- Original Message -----
>   From: Michael Dinowitz
>   To: CF-Community
>   Sent: Monday, May 24, 2004 3:33 PM
>   Subject: hack these guys
>
>
>   OK, I just got another piece of spam and this one caught my eye for a single
>   reason. It's using CF.
>   www.networksolutions-em.com/renewal.cfm?id=29808185&link=F0524_A05H
>   I'm really tempted to hack these guys and bring them down. Their cfdocs and
>   cfide are totally open and it shouldn't take much to refind that redirect
script
>   I wrote to turn off security.
>   First things first though. Got to finish up this box packing module. They're
>   saved till then.
>
>   --
>   Michael Dinowitz
>   House of Fusion
>   http://www.houseoffusion.com
>   Finding technical solutions to the problems you didn't know you had yet
>
>
>
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to