Skip to main content
March 8, 2014
Question

Does CF have injection issues - blackhat seo

  • March 8, 2014
  • 3 replies
  • 684 views

I have been hacked by blackhat seo (type 1703) on 2 separate (and different providers) cold fusion instances.

I am wondering if my form inputs are being hijacked with indection code and somehow the hackers are gaining access to my files.

My files ultimately have a dozen or so links added to the bottom of the pages and I don't know how they are getting in.

I have heard of vulnerabilities in the CFIDE folder on the server but my provider believes its in my code.

Any insights are greatly appreciated.

This topic has been closed for replies.

3 replies

pete_freitag
Participating Frequently
March 10, 2014

Randy, I'll also mention my company makes a CF specific vulnerability scanner called HackMyCF. We have a free scan, and a paid subscription that can go into more detail.

Anit_Kumar
Inspiring
March 10, 2014

Yes, HackMyCF is a good option to test your application. At the same time, please send in your query to Adobe Product Security Incident Response Team (psirt@adobe.com).

Regards,

Anit Kumar

Legend
March 10, 2014

There are several threads on CFIDE vulnerabilities and most all have two solutions: upgrade to latest CF patch level and hide the full CFIDE branch from the Internet (kill the current CFIDE virtual directory, create a new CFIDE virtual directory pointed to an empty directory, create a CFIDE/scripts virtual directory and point it to the original CFIDE/scripts directory).

As far as what hackers can and cannot exploit, I would suggest purchasing an external site scanning service. If you accept payments via your site, this is a requirement. For the sites I run on the side, I use www.securitymetrics.com. www.trustkeeper.com is another one. There are others.