ZDNet Names 'ColdFusion Exploit' and RDS Hole Number 1 Security Problems of 1999

 
Dec 27, 1999
We were quite surprised to see the "ColdFusion Exploit" sharing the spotlight as the first in line for the Top 10 Worst Computer Glitches of 1999. This security hole, which was known by the ColdFusion community for a number of months, officially hit the news when it was written up by Rain.Forest.Puppy in an issue of Phrack magazine about a year ago. The hole was caused by a problem in the ColdFusion documentation, not in ColdFusion itself. It was easily corrected.

To compound this, ZDNet called the hole a vulnerability in Allaire's ColdFusion Server (rather than explaining that the problem was in the placement of the Allaire documentation). This gives a false impression that Allaire's systems have an innate vulnerability.

The ColdFusion Exploit was not, in our humble opinion, the scourge that the ZDNet article makes it out to be. Think of the thousands upon thousands of computers affected by Melissa. ZDNet lists the number of sites affected by the ColdFusion Exploit as "more than 100." These numbers can hardly compare.

According to Michael Dinowitz, "Anyone can go to any hacker site and find every site that was hacked using the ColdFusion hole. I doubt they'll find more than a couple of dozen. Not the 'more than 100' quoted by ZDNet. I truly believe that the news of this exploit has been exploited by others."

ZDNet Article (http://www.zdnet.com/zdnn/stories/news/0,4586,2413514,00.html)


Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting