RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Dave Watts
> Your comments raise a simple question: > > > 2. Remove the right to read files from whatever user the CF server is > > running as (typically SYSTEM). All CF needs to be able to do > > is execute. > > I presume this will not affect reading the contents of a file with > cffile/read ?? No, I'd gue

Re: Allaire security problem - anyone know solution?

2000-08-04 Thread Ann Marie Thurmond
> To: <[EMAIL PROTECTED]> Subject: Re: Allaire security problem - anyone know solution? Message-ID: <00f601bffdc7$0caa9b90$7b1610cf@desktop> Allaire security bulletin says Originally Posted: May 22, 2000 Last Updated: May 22, 2000 Why are we just finding out that our entire Serve

RE: Allaire security problem - anyone know solution? - RTM

2000-08-04 Thread Cary Gordon
-- >From: Dave Wilson [mailto:[EMAIL PROTECTED]] >Sent: Thursday, August 03, 2000 12:27 PM >To: [EMAIL PROTECTED] >Subject: Allaire security problem - anyone know solution? > > >Hi all, > >One of my hosting clients has just made me aware of this major security &

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Robert Forsyth
(CIT) [mailto:[EMAIL PROTECTED]] Sent: Friday, August 04, 2000 10:11 AM To: [EMAIL PROTECTED] Subject: RE: Allaire security problem - anyone know solution? As usual, no problem with O'Reilly WebSite Pro here. >anyone know solution? Yes ... for starters it can be found here http://websit

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Hoffman, Joe (CIT)
r System Services -Original Message- From: Steve Pierce [mailto:[EMAIL PROTECTED]] Sent: Thursday, August 03, 2000 9:14 PM To: [EMAIL PROTECTED] Subject: RE: Allaire security problem - anyone know solution? Problem doesn't seem to impact O'Reilly Website servers, only IIS. - S

Re: IIS security problem -- not Allaire security problem - anyone know solution?

2000-08-04 Thread Dave Wilson
ECTED] - Original Message - From: pan <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, August 04, 2000 10:23 AM Subject: IIS security problem -- not Allaire security problem - anyone know solution? > It seems fairly clear that the subject line of this thread needed > c

IIS security problem -- not Allaire security problem - anyone know solution?

2000-08-04 Thread pan
It seems fairly clear that the subject line of this thread needed changing. Can anyone show the .htr vulnerability on a server other than IIS? Pan -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Rich Wild
August 2000 19:10 To: '[EMAIL PROTECTED]' Subject: RE: Allaire security problem - anyone know solution? Wow, that's ugly. You don't even need to do the refresh, just view the source of the page and it is right there. It only seems to work if you know the directory where appli

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Johan Coens
EMAIL PROTECTED] Subject: RE: Allaire security problem - anyone know solution? You're kidding, right? http://devex.allaire.com/developer/gallery/info.cfm?ID=B61C031D-2CE5-11D4-83 D700508B94F85A&method=Full http://www.rixsoft.com/ColdFusion/CFX/CFMEncrypt/ http://packetstorm.se

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Rick Osborne
n one basket. Or, in this case, all of their faith in a broken system.) -Rick -Original Message- From: Johan Coens [mailto:[EMAIL PROTECTED]] Sent: Friday, August 04, 2000 3:46 AM To: [EMAIL PROTECTED] Subject: RE: Allaire security problem - anyone know solution? One easy solution to do

RE: Allaire security problem - anyone know solution?

2000-08-04 Thread Johan Coens
One easy solution to do: CFENCRYPT it -Original Message- From: Mooner Ent [mailto:[EMAIL PROTECTED]] Sent: vrijdag 4 augustus 2000 5:50 To: [EMAIL PROTECTED] Subject: Re: Allaire security problem - anyone know solution? Allaire security bulletin says Originally Posted: May 22, 2000

Re: Allaire security problem - anyone know solution?

2000-08-04 Thread Mooner Ent
. - Original Message - From: "Daniel J. Cody" <[EMAIL PROTECTED]> Newsgroups: cf-talk To: <[EMAIL PROTECTED]> Sent: Thursday, August 03, 2000 9:46 AM Subject: Re: Allaire security problem - anyone know solution? > Dave, I wasn't able to reproduce this on CF 4.5.1 on Linu

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Jared Clinton
Its in a CFQuery, so its just passing the command to whatever the dsn points to. [EMAIL PROTECTED] wrote: > > Please see: > > > > http://www.allaire.com/handlers/index.cfm?ID=15920&Method=Full > > And then *really* see http://beta.allaire.com/login.cfm+.htr. They should eat their >own d

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread David Sparkman
:05 PM To: '[EMAIL PROTECTED]' Subject: RE: Allaire security problem - anyone know solution? I can't reproduce your results on any of the 3 systems I tried, including Allaire's site. Do you have any more information? > -Original Message- > From: Dave Wil

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Jon Tillman
n O'Keefe > TriPoint Technologies > [EMAIL PROTECTED] > 954.501.3113 > > -> -Original Message- > -> From: Dave Wilson [mailto:[EMAIL PROTECTED]] > -> Sent: Thursday, August 03, 2000 11:27 AM > -> To: [EMAIL PROTECTED] > -> Subject: Allaire sec

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Steve Pierce
AIL PROTECTED]] Sent: Thursday, August 03, 2000 4:44 PM To: '[EMAIL PROTECTED]' Subject: RE: Allaire security problem - anyone know solution? http://www.allaire.com/handlers/index.cfm?ID=15920&Method=Full -Original Message- From: Dave Wilson [mailto:[EMAIL PROTECTED]] Sent: Thu

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Todd Ashworth
IL PROTECTED]> Sent: Thursday, August 03, 2000 2:09 PM Subject: RE: Allaire security problem - anyone know solution? > It also doesn't appear to work with other .cfm files. > Hi all, > > One of my hosting clients has just made me aware of this major security > problem and I'

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Dan Blickensderfer
From: "Jonathan Broome" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 03, 2000 3:36 PM Subject: RE: Allaire security problem - anyone know solution? > > On my sites using SP6a, I couldn't get this to work. On other sites, I > could. Unless som

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread peter
ts, Jesse D" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 03, 2000 12:05 PM Subject: RE: Allaire security problem - anyone know solution? > I can't reproduce your results on any of the 3 systems I tried, including > Allaire's site. Do you h

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Jon Tillman
On Thu, 03 Aug 2000, Dave Wilson spewed forth into the void: > Hi all, > > One of my hosting clients has just made me aware of this major security > problem and I'm wondering if anyone knows how to eliminate it? > > Try calling the application.cfm template on any CF site with +.htr appended > to

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Jason Egan
TECTED]' Subject: RE: Allaire security problem - anyone know solution? Wow, that's ugly. You don't even need to do the refresh, just view the source of the page and it is right there. It only seems to work if you know the directory where application.cfm exists. If you are operatin

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread ron
> Please see: > > http://www.allaire.com/handlers/index.cfm?ID=15920&Method=Full And then *really* see http://beta.allaire.com/login.cfm+.htr. They should eat their own dogfood, so to speak. BTW, what's up with this from that page: {CALL ValidateUser('#Form.UserName#', '#Form.Passwo

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Brian Thornton
st 03, 2000 11:27 AM >-> To: [EMAIL PROTECTED] >-> Subject: Allaire security problem - anyone know solution? >-> >-> >-> Hi all, >-> >-> One of my hosting clients has just made me aware of this major security >-> problem and I'm wondering if a

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Brian L. Wolfsohn
At 01:40 PM 8/3/00 , you wrote: Dave, As always, thanks for the wealth of information, explained clearly... Your comments raise a simple question: >2. Remove the right to read files from whatever user the CF server is >running as (typically SYSTEM). All CF needs to be able to do is execute. I

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dave Watts
> Wow, that's ugly. You don't even need to do the refresh, > just view the source of the page and it is right there. It > only seems to work if you know the directory where application.cfm > exists. If you are operating with a single application.cfm > you can move it up one directory, outside of t

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread ron
> Try calling the application.cfm template on any CF site with > +.htr appended > to the end of the url. You'll first see a blank page. Now hit > refresh/reload > and you'll see the full code of said application.cfm > > e.g. http://www.support.alllaire.com/application.cfm+.htr And they're definit

RE: Allaire security problem - anyone know solution? *FIX*

2000-08-03 Thread Jonathan Broome
: Jonathan Broome; '[EMAIL PROTECTED]' Subject: RE: Allaire security problem - anyone know solution? *FIX* Dave, I was only half-right earlier. Loading SP6a on a web server that had this vulnerability *did not* fix the issue. However, after loading SP6a *and* the hotfix availab

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dan O'Keefe
That fixed it for me Dan -> -Original Message- -> From: Adam Breaux [mailto:[EMAIL PROTECTED]] -> Sent: Thursday, August 03, 2000 12:31 PM -> To: [EMAIL PROTECTED] -> Subject: Re: Allaire security problem - anyone know solution? -> -> -> Remove .htr mappings from

RE: Allaire security problem - anyone know solution? *FIX*

2000-08-03 Thread Jonathan Broome
source code behavior. Jonathan -Original Message- From: Jonathan Broome Sent: Thursday, August 03, 2000 3:37 PM To: '[EMAIL PROTECTED]' Subject: RE: Allaire security problem - anyone know solution? On my sites using SP6a, I couldn't get this to work. On other sites, I

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread ron
> One of my hosting clients has just made me aware of this > major security > problem and I'm wondering if anyone knows how to eliminate it? > > Try calling the application.cfm template on any CF site with > +.htr appended > to the end of the url. You'll first see a blank page. Now hit > refresh/r

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Robert Everland
http://www.allaire.com/handlers/index.cfm?ID=15920&Method=Full -Original Message- From: Dave Wilson [mailto:[EMAIL PROTECTED]] Sent: Thursday, August 03, 2000 12:27 PM To: [EMAIL PROTECTED] Subject: Allaire security problem - anyone know solution? Hi all, One of my hosting clients

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Robert Everland
t: Allaire security problem - anyone know solution? Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the application.cfm template on any CF site with +.htr appended to the end of the ur

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Ken Wilson
Does it on my NT4/SP5 boxes here. Also on one running Win2k Server. Does not do it on the sites I manage running NT4/SP6. Ken - Original Message - From: Dave Wilson <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 03, 2000 12:26 PM Subject: Allaire secu

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Jonathan Broome
PROTECTED] Subject: Allaire security problem - anyone know solution? Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the application.cfm template on any CF site with +.htr appended to the

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Kelly Matthews
--- > -Original Message- > From: Dave Wilson [SMTP:[EMAIL PROTECTED]] > Sent: Thursday, August 03, 2000 12:27 PM > To: [EMAIL PROTECTED] > Subject: Allaire security problem - anyone know solution? > > Hi all, > > One of my ho

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Hales, John M
ROTECTED]] Sent: Thursday, August 03, 2000 12:27 PM To: [EMAIL PROTECTED] Subject: Allaire security problem - anyone know solution? Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the appl

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Roberts, Jesse D
gt; Subject: Allaire security problem - anyone know solution? > > Hi all, > > One of my hosting clients has just made me aware of this major security > problem and I'm wondering if anyone knows how to eliminate it? > > Try calling the application.cfm template on any CF

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dan O'Keefe
ursday, August 03, 2000 11:27 AM -> To: [EMAIL PROTECTED] -> Subject: Allaire security problem - anyone know solution? -> -> -> Hi all, -> -> One of my hosting clients has just made me aware of this major security -> problem and I'm wondering if anyone knows

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dan O'Keefe
Original Message- -> From: Dave Wilson [mailto:[EMAIL PROTECTED]] -> Sent: Thursday, August 03, 2000 11:27 AM -> To: [EMAIL PROTECTED] -> Subject: Allaire security problem - anyone know solution? -> -> -> Hi all, -> -> One of my hosting clients has just made me awar

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Olive, Christopher M Mr NMR
PROTECTED] Subject: Allaire security problem - anyone know solution? Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the application.cfm template on any CF site with +.htr appended to the e

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread David E. Crawford
This is a multi-part message in MIME format. --=_NextPart_000_03F1_01BFFD76.AD870AE0 Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Allaire security problem - anyone know solution?The easiest solution is = to remove the IIS

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread David E. Crawford
This is a multi-part message in MIME format. --=_NextPart_000_03E8_01BFFD75.946E22B0 Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Allaire security problem - anyone know solution?This is an IIS problem, = not a CF problem.

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dan Haley
[EMAIL PROTECTED] Subject: Allaire security problem - anyone know solution? Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the application.cfm template on any CF site with +.htr appended

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Daniel J. Cody
Dave, I wasn't able to reproduce this on CF 4.5.1 on Linux+Apache. I think this might be more of an IIS issue than a CF one. Check out http://www.securityfocus.com/focus/microsoft/iis/iismain.html for more info on .htr issues. .djc. Dave Wilson wrote: > > Hi all, > > One of my hosting clients

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Carlos Vazquez
: Thursday, August 03, 2000 12:27 PM > To: [EMAIL PROTECTED] > Subject: Allaire security problem - anyone know solution? > > > Hi all, > > One of my hosting clients has just made me aware of this major security > problem and I'm wondering if anyone knows how to eliminate it

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Dave Watts
> One of my hosting clients has just made me aware of this > major security problem and I'm wondering if anyone knows > how to eliminate it? > > Try calling the application.cfm template on any CF site with > +.htr appended to the end of the url. You'll first see a blank > page. Now hit refresh/rel

Re: Allaire security problem - anyone know solution?

2000-08-03 Thread Adam Breaux
Remove .htr mappings from your web servers unless you need that functionality. It's a know IIS hole. - Original Message - From: "Dave Wilson" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 03, 2000 12:26 PM Subject: Allaire security pro

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Kevin Queen
-Original Message- From: Kevin Queen [mailto:[EMAIL PROTECTED]] Sent: Thursday, August 03, 2000 1:22 PM To: Dave Wilson [[EMAIL PROTECTED]] Subject: RE: Allaire security problem - anyone know solution? Dave, I have seen this same error in ASP with ::$DATA, the way to fix that one is

RE: Allaire security problem - anyone know solution?

2000-08-03 Thread Jesse Noller
Dave: Please see: http://www.allaire.com/handlers/index.cfm?ID=15920&Method=Full -Jesse Noller -Original Message- From: Dave Wilson [mailto:[EMAIL PROTECTED]] Sent: Thursday, August 03, 2000 12:27 PM To: [EMAIL PROTECTED] Subject: Allaire security problem - anyone know solution?

Allaire security problem - anyone know solution?

2000-08-03 Thread Dave Wilson
Hi all, One of my hosting clients has just made me aware of this major security problem and I'm wondering if anyone knows how to eliminate it? Try calling the application.cfm template on any CF site with +.htr appended to the end of the url. You'll first see a blank page. Now hit refresh/reload