4 ms·
The hacker claims it to be a CF 0-day vulnerability: > 05:05 < ryan_> manager.linode.com was breached with a coldfusion exploit ... > 05:33 < Ruchira> ryan||
by Tomdarkness 13y ago
The hacker claims it to be a CF 0-day vulnerability:
> 05:05 < ryan_> manager.linode.com was breached with a coldfusion exploit
...
> 05:33 < Ruchira> ryan||: give us the link to cold fusion vulnerability that you are talking about
> 05:34 < ryan||> Ruchira: 0day
> 05:34 < ryan||> linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000
- tptacek 13y agoDepending on who you're talking to, an app-level vulnerability in a Linode management console might be called a "0-day". But it's true that a CF stack flaw is not impossible.
- 127001brewer 13y ago"... CF stack flaw is very possible and almost always likely ..." There, I fixed it for you. Working with ColdFusion is like this: http://25.media.tumblr.com/38d67be62da60b4d3aa1d0ac22e4e314/tumblr_mj9bp0LoLC1r3k73wo1_400.gif http://25.media.tumblr.com/38d67be62da60b4d3aa1d0ac22e4e314/...
- tptacek 13y agoThe problem I have balancing the likelihood of CF stack bugs vs. CF app bugs is that I've had to assess a bunch of CF apps, and they're uniformly coded to mid-1990s best practices. No matter how many bugs have been announced in the CF stack, as a betting man my money would always be on CF app bugs.