<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ColdFusion directory traversal FAQ (CVE-2010-2861)</title>
	<atom:link href="http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Zoi</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-134108</link>
		<dc:creator>Zoi</dc:creator>
		<pubDate>Thu, 25 Oct 2012 17:19:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-134108</guid>
		<description>I tested this out it doesnt seem to work. I obtained the hash of a ColdFusion 7 system. However passing the hash does not work. I tried several times really fast the whole process. you have some video demonstrating this?</description>
		<content:encoded><![CDATA[<p>I tested this out it doesnt seem to work. I obtained the hash of a ColdFusion 7 system. However passing the hash does not work. I tried several times really fast the whole process. you have some video demonstrating this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shubham</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-134092</link>
		<dc:creator>Shubham</dc:creator>
		<pubDate>Tue, 04 Sep 2012 12:31:29 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-134092</guid>
		<description>Feel free to look at my automation of this process at http://code.google.com/p/cfide-autopwn/. Currently it supports lists, and can rip hashes via enter.cfm method. Sooner it will support the uploading of a web shell. Great if you want to mass check your servers.</description>
		<content:encoded><![CDATA[<p>Feel free to look at my automation of this process at <a href="http://code.google.com/p/cfide-autopwn/" rel="nofollow">http://code.google.com/p/cfide-autopwn/</a>. Currently it supports lists, and can rip hashes via enter.cfm method. Sooner it will support the uploading of a web shell. Great if you want to mass check your servers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mr,prince</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-134021</link>
		<dc:creator>mr,prince</dc:creator>
		<pubDate>Mon, 02 Apr 2012 12:35:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-134021</guid>
		<description>pagvac:) The attacker does not need to crack the sha1? yes and NO?</description>
		<content:encoded><![CDATA[<p>pagvac:) The attacker does not need to crack the sha1? yes and NO?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anagogue</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-129554</link>
		<dc:creator>anagogue</dc:creator>
		<pubDate>Fri, 14 Jan 2011 16:34:28 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-129554</guid>
		<description>Any hints on what to do with a ColdFusionMX password? Didn&#039;t that use a weaker hash/encryption function than 7/8+?

I assume it should be fairly easily crackable, but need a hint on what to use on it.</description>
		<content:encoded><![CDATA[<p>Any hints on what to do with a ColdFusionMX password? Didn&#8217;t that use a weaker hash/encryption function than 7/8+?</p>
<p>I assume it should be fairly easily crackable, but need a hint on what to use on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashok</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128844</link>
		<dc:creator>Ashok</dc:creator>
		<pubDate>Wed, 01 Sep 2010 23:23:18 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128844</guid>
		<description>Hi ! Thanks for the article ..... I found something wired with Gmail password. For long time I have been using a password with space at the beginning and end of the alphanumerical characters.

e.g- â€ passwd â€ But actually Gmail doesnâ€™t count if there is spaces at the beginning and end of the password. Basically you could use the space character as much as you like at the beginning and end with actual password, still you can sign in. I couldnâ€™t find any article related to this â€¦ But I could exploit this feature(!) at times when some one try to count the number of characters in the password, by adding some spaces.</description>
		<content:encoded><![CDATA[<p>Hi ! Thanks for the article &#8230;.. I found something wired with Gmail password. For long time I have been using a password with space at the beginning and end of the alphanumerical characters.</p>
<p>e.g- â€ passwd â€ But actually Gmail doesnâ€™t count if there is spaces at the beginning and end of the password. Basically you could use the space character as much as you like at the beginning and end with actual password, still you can sign in. I couldnâ€™t find any article related to this â€¦ But I could exploit this feature(!) at times when some one try to count the number of characters in the password, by adding some spaces.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128741</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Tue, 24 Aug 2010 16:11:36 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128741</guid>
		<description>@Simon: the value of the &#039;salt&#039; parameter expires after a few seconds on the server side (60 seconds IIRC). This means you need perform the steps mentioned in this post within this time window.

Why wouldn&#039;t it work? Think about it, the login form simply hashes the password entered by the user with the value of the &#039;salt&#039; parameter as returned by the application within client-side JS code. You can replicate all these steps yourself without needing to know the plaintext password.</description>
		<content:encoded><![CDATA[<p>@Simon: the value of the &#8216;salt&#8217; parameter expires after a few seconds on the server side (60 seconds IIRC). This means you need perform the steps mentioned in this post within this time window.</p>
<p>Why wouldn&#8217;t it work? Think about it, the login form simply hashes the password entered by the user with the value of the &#8216;salt&#8217; parameter as returned by the application within client-side JS code. You can replicate all these steps yourself without needing to know the plaintext password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlueThunder Blog &#187; ColdFusion Directory Traversal vulnerability</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128734</link>
		<dc:creator>BlueThunder Blog &#187; ColdFusion Directory Traversal vulnerability</dc:creator>
		<pubDate>Mon, 23 Aug 2010 23:48:11 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128734</guid>
		<description>[...] allowing the inclusion of other files from the same disk the CFAdmin section is living on.Â  AsÂ Adrian Pastor points out, CF runs under the SYSTEM account by default, which means access to any file on the drive.Â  [...]</description>
		<content:encoded><![CDATA[<p>[...] allowing the inclusion of other files from the same disk the CFAdmin section is living on.Â  AsÂ Adrian Pastor points out, CF runs under the SYSTEM account by default, which means access to any file on the drive.Â  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128722</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Thu, 19 Aug 2010 14:29:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128722</guid>
		<description>I tested this out with my client and it doesnt seem to work. I obtained the hash of a ColdFusion 8 and 7 system. However passing the hash does not work. I think you must crack it.</description>
		<content:encoded><![CDATA[<p>I tested this out with my client and it doesnt seem to work. I obtained the hash of a ColdFusion 8 and 7 system. However passing the hash does not work. I think you must crack it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128721</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Wed, 18 Aug 2010 17:05:16 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128721</guid>
		<description>Lucas: there are many ways to do this, blocking the URL with a WAF is one of them. Also, you can do it on the web server itself. For instance, on Apache you could add the following to the config file:

&lt;pre&gt;&lt;code&gt;&lt;Location /CFIDE&gt;
Order Deny,Allow
Deny from all
Allow from 127.0.0.1
&lt;/Location&gt;&lt;/code&gt;&lt;/pre&gt;

Just make sure you test the new configuration settings thoroughly before placing the server into production. For instance, some non-admin features rely on access to /CFIDE/ . E.g.: charts (cfchart) requires access to /CFIDE/GraphData.cfm. Take a look at the ColdFusion lockdown guide for more info: http://www.adobe.com/products/coldfusion/whitepapers/pdf/91025512_cf9_lockdownguide_wp_ue.pdf</description>
		<content:encoded><![CDATA[<p>Lucas: there are many ways to do this, blocking the URL with a WAF is one of them. Also, you can do it on the web server itself. For instance, on Apache you could add the following to the config file:</p>
<pre><code>&lt;Location /CFIDE&gt;
Order Deny,Allow
Deny from all
Allow from 127.0.0.1
&lt;/Location&gt;</code></pre>
<p>Just make sure you test the new configuration settings thoroughly before placing the server into production. For instance, some non-admin features rely on access to /CFIDE/ . E.g.: charts (cfchart) requires access to /CFIDE/GraphData.cfm. Take a look at the ColdFusion lockdown guide for more info: <a href="http://www.adobe.com/products/coldfusion/whitepapers/pdf/91025512_cf9_lockdownguide_wp_ue.pdf" rel="nofollow">http://www.adobe.com/products/....._wp_ue.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lek in ColdFusion kaapt webservers &#187; QTA Nieuws</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128720</link>
		<dc:creator>Lek in ColdFusion kaapt webservers &#187; QTA Nieuws</dc:creator>
		<pubDate>Wed, 18 Aug 2010 14:16:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128720</guid>
		<description>[...] daarmee de analyse van hacker Adrian Pastor die vrijdag al stelde dat het ColdFusion-lek kritiek is en niet slechts &#039;belangrijk&#039;. Exploitcode voor dit lek is inmiddels publiekelijk beschikbaar. Adobe heeft maandag nog een [...]</description>
		<content:encoded><![CDATA[<p>[...] daarmee de analyse van hacker Adrian Pastor die vrijdag al stelde dat het ColdFusion-lek kritiek is en niet slechts &#039;belangrijk&#039;. Exploitcode voor dit lek is inmiddels publiekelijk beschikbaar. Adobe heeft maandag nog een [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vulnerabilidad en Cold Fusion de Adobe mas critica de lo que se cree &#124; OpenSecurity</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128713</link>
		<dc:creator>Vulnerabilidad en Cold Fusion de Adobe mas critica de lo que se cree &#124; OpenSecurity</dc:creator>
		<pubDate>Tue, 17 Aug 2010 15:28:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128713</guid>
		<description>[...] usuarios deberÃ­an instalar una actualizaciÃ³n de seguridad. Existe mÃ¡s informaciÃ³n en el Blog GnuCitizen con mÃ¡s detalles sobre esta [...]</description>
		<content:encoded><![CDATA[<p>[...] usuarios deberÃ­an instalar una actualizaciÃ³n de seguridad. Existe mÃ¡s informaciÃ³n en el Blog GnuCitizen con mÃ¡s detalles sobre esta [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128712</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Tue, 17 Aug 2010 14:07:15 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128712</guid>
		<description>Jones: once you upload the cfm backdoor, you should be able to delete any files (SYSTEM privs by default), including the backdoor itself. After all, you can run arbitrary commands. E.g. &lt;code&gt;del \ColdFusion8\wwwroot\cfexec.cfm&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>Jones: once you upload the cfm backdoor, you should be able to delete any files (SYSTEM privs by default), including the backdoor itself. After all, you can run arbitrary commands. E.g. <code>del \ColdFusion8\wwwroot\cfexec.cfm</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ColdFusion vulnerability more critical than first thought</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128711</link>
		<dc:creator>ColdFusion vulnerability more critical than first thought</dc:creator>
		<pubDate>Tue, 17 Aug 2010 11:50:56 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128711</guid>
		<description>[...] highest priority to installing the security update. A FAQ page on security blog GnuCitizen provides further information on workarounds.  Source: [...]</description>
		<content:encoded><![CDATA[<p>[...] highest priority to installing the security update. A FAQ page on security blog GnuCitizen provides further information on workarounds.  Source: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lucas</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128710</link>
		<dc:creator>Lucas</dc:creator>
		<pubDate>Tue, 17 Aug 2010 10:30:49 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128710</guid>
		<description>Hi, just wonder why can&#039;t I just block entire CFIDE folder to anyone except one IP? Can that screw something? Cheers!</description>
		<content:encoded><![CDATA[<p>Hi, just wonder why can&#8217;t I just block entire CFIDE folder to anyone except one IP? Can that screw something? Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jones</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128708</link>
		<dc:creator>Jones</dc:creator>
		<pubDate>Tue, 17 Aug 2010 07:11:31 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128708</guid>
		<description>How would you delete a uploaded file to a exploited server? Im currently testing this in my lab at home. but i cant seem to figure out how to delete all uploaded scripts.</description>
		<content:encoded><![CDATA[<p>How would you delete a uploaded file to a exploited server? Im currently testing this in my lab at home. but i cant seem to figure out how to delete all uploaded scripts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adobe ColdFusion&#8217;s Directory Traversal Disaster &#171; ColdFusion Developers Network</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128707</link>
		<dc:creator>Adobe ColdFusion&#8217;s Directory Traversal Disaster &#171; ColdFusion Developers Network</dc:creator>
		<pubDate>Mon, 16 Aug 2010 13:04:07 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128707</guid>
		<description>[...] why I think this is a big mistake &#8230; on top of the excellent analysis Adrian has already done (check his excellent post here) I think it&#8217;s relevent to do a little digging yourself to understand the full scope of the [...]</description>
		<content:encoded><![CDATA[<p>[...] why I think this is a big mistake &#8230; on top of the excellent analysis Adrian has already done (check his excellent post here) I think it&#8217;s relevent to do a little digging yourself to understand the full scope of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128705</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Sun, 15 Aug 2010 21:34:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128705</guid>
		<description>@Niels: didn&#039;t think of that TBH. Excellent point! I haven&#039;t tested it but should definitely work. This would make cracking the SHA1 hash totally unnecessary!

@sunjester: ;D</description>
		<content:encoded><![CDATA[<p>@Niels: didn&#8217;t think of that TBH. Excellent point! I haven&#8217;t tested it but should definitely work. This would make cracking the SHA1 hash totally unnecessary!</p>
<p>@sunjester: ;D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Niels Teusink</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128703</link>
		<dc:creator>Niels Teusink</dc:creator>
		<pubDate>Sat, 14 Aug 2010 16:49:47 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128703</guid>
		<description>Thanks for the article Adrian! I have one addition: An attacker does not need to crack the SHA1-hash. The CF8 login screen does this: &lt;code&gt;onSubmit=&quot;cfadminPassword.value = hex_hmac_sha1(salt.value, hex_sha1(cfadminPassword.value));&quot;&lt;/code&gt;

This allows attackers to authenticate using the hash instead of cracking it.</description>
		<content:encoded><![CDATA[<p>Thanks for the article Adrian! I have one addition: An attacker does not need to crack the SHA1-hash. The CF8 login screen does this: <code>onSubmit="cfadminPassword.value = hex_hmac_sha1(salt.value, hex_sha1(cfadminPassword.value));"</code></p>
<p>This allows attackers to authenticate using the hash instead of cracking it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sunjester</title>
		<link>http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/comment-page-1/#comment-128702</link>
		<dc:creator>sunjester</dc:creator>
		<pubDate>Sat, 14 Aug 2010 06:35:53 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=3665#comment-128702</guid>
		<description>Maybe Adobe hires new guys.. lol</description>
		<content:encoded><![CDATA[<p>Maybe Adobe hires new guys.. lol</p>
]]></content:encoded>
	</item>
</channel>
</rss>
