Re: Hack - Further Information

2013-02-12 Thread Russ Michaels
well I guess I never saw it because I always keep the cfadmin in the default website and lock it down, and always create a copy of the CFIDE without the admin or adminapi for all other sites. So there is always a REAL CFIDE. I have just gone and checked some cf sites on several servers for

Re: Hack - Further Information

2013-02-12 Thread Dave Watts
well I guess I never saw it because I always keep the cfadmin in the default website and lock it down, and always create a copy of the CFIDE without the admin or adminapi for all other sites. So there is always a REAL CFIDE. That, by itself, is not sufficient. You can have a real CFIDE

Re: Hack - Further Information

2013-02-05 Thread Russ Michaels
I have to say I have never once had that in my 12 years of installing cf servers, if the cfide dir or vdir doesn't exist , then cfide or the administrator doesn't work, period. So there must be some.very special.circumstances for that to happen, it certainly doesn't happen on a standard windows

Re: Hack - Further Information

2013-02-05 Thread James F
Upon further review of my server I have discovered several files were compromised, dating back to January 2, 2013. They appear in various places in the /CFIDE folder. Here is a list of the ones I found this morning: C:\Inetpub\wwwroot\CFIDE\adminapi\customtags\fusebox.cfm

Re: Hack - Further Information

2013-02-05 Thread James F
Upon further review of my server I have discovered several files were compromised, dating back to January 2, 2013. They appear in various places in the /CFIDE folder. Here is a list of the ones I found this morning: C:\Inetpub\wwwroot\CFIDE\ adminapi\customtags\fusebox.cfm

Re: Hack - Further Information

2013-02-05 Thread Dave Watts
I have to say I have never once had that in my 12 years of installing cf servers, if the cfide dir or vdir doesn't exist , then cfide or the administrator doesn't work, period. I have seen this many times. Again, as mentioned previously, it's not at all obvious - you request the URL

Re: Hack - Further Information

2013-02-04 Thread Pete Freitag
Hi Robert, CFChart relies on the URI /CFIDE/GraphData.cfm so if you block /CFIDE then cfchart also stops working, there is no way I'm aware of to tell CFChart to use a different URI (I wish there was!). This also adds confusing for some because the file /CFIDE/GraphData.cfm does not exist in

RE: Hack - Further Information

2013-02-04 Thread Paul Vernon
What should we do to allow CFChart to function without opening a security hole? What we do is this. 1. Duplicate the CFIDE directory in full. 2. In the duplicate, remove the administration folders altogether. 3. In all but the CFAdmin site itself on the server (which should really not be

Re: Hack - Further Information

2013-02-04 Thread John F
I have watched this discussion with interest for much of the day and am unsure whether I should be concerned or not. Is there a new major ColdFusion security hole at work here? Is this just an old issue that some people had not patched correctly?If this is a new issue, what do I need to do

Re: Hack - Further Information

2013-02-04 Thread Pete Freitag
Hi Paul, That approach may work in some cases, but there are cases where /CFIDE/administrator/index.cfm may still resolve even if there is no folder there (or no virtual directory). We often receive reports saying that hackmycf.com is incorrectly reporting CF administrator open because

RE: Hack - Further Information

2013-02-04 Thread Paul Vernon
Pete, That approach may work in some cases, but there are cases where /CFIDE/administrator/index.cfm may still resolve even if there is no folder there (or no virtual directory). You're going to have to explain how /CFIDE/administrator/index.cfm could resolve when the CFIDE mapping is

Re: Hack - Further Information

2013-02-04 Thread Pete Freitag
Paul, Sorry to clarify if the folder is gone 100% from the server it will not work, but if you kept it in the default install location, eg c:\inetpub\wwwroot or c:\coldfusion9\wwwroot\CFIDE and even though there is no website that points to that on the webserver it can still resolve. So in that

Re: Hack - Further Information

2013-02-04 Thread Dave Watts
That approach may work in some cases, but there are cases where /CFIDE/administrator/index.cfm may still resolve even if there is no folder there (or no virtual directory). You're going to have to explain how /CFIDE/administrator/index.cfm could resolve when the CFIDE mapping is pointing

RE: Hack - Further Information

2013-02-04 Thread Paul Vernon
That approach may work in some cases, but there are cases where /CFIDE/administrator/index.cfm may still resolve even if there is no folder there (or no virtual directory). You're going to have to explain how /CFIDE/administrator/index.cfm could resolve when the CFIDE mapping is

RE: Hack - Further Information

2013-02-04 Thread Russ Michaels
Check charlie areharts blog, he did a lengtny post pn this with links to several lockdown articles. Regards Russ Michaels www.michaels.me.uk www.cfmldeveloper.com - Free CFML hosting for developers www.cfsearch.com - CF search engine

Re: Hack - Further Information

2013-02-04 Thread Dave Watts
OK, now that you've done that: CF serves all sorts of pages that don't exist. You may read up in this very thread about CFCHART, which relies on a URL pattern that doesn't exist. CF relies on servlet mappings, which may or may not correspond with actual URLs. Typically, they do, but there

Re: Hack - Further Information

2013-02-04 Thread Bill Moniz
Great explanation Dave. Good to know. On 5 February 2013 11:21, Dave Watts dwa...@figleaf.com wrote: OK, now that you've done that: CF serves all sorts of pages that don't exist. You may read up in this very thread about CFCHART, which relies on a URL pattern that doesn't exist. CF