Re: onRequestEnd.cfm exploit (need help)

2009-11-13 Thread Dave Watts
> Three of my CF7-driven sites just got hit this morning with an exploit that > I'm having trouble > finding information on. > > The attack did the following: > 1) wrote 0 KB Application.cfm file to the web-root of the sites > 2) wrote an onRequestEnd.cfm file (also to the web-root) that containe

onRequestEnd.cfm exploit (need help)

2009-11-13 Thread Michael Patti
Three of my CF7-driven sites just got hit this morning with an exploit that I'm having trouble finding information on. The attack did the following: 1) wrote 0 KB Application.cfm file to the web-root of the sites 2) wrote an onRequestEnd.cfm file (also to the web-root) that contained a script s