Copy link to clipboard
Copied
I need help. For the second time in three months every single .cfm page has a malicous cross-site script appended to the orginal code. It looks something like this:

I'm having a really hard time trying to figure out where this might be coming from, or where the vulnerability is. Has anyone been affected by the same scripting attack? I'm running a windows 2003 server, fusebox 4.0 framework on MS SQL database. Thanks for any help or any leds that might help solve this problem!
This is what you have:
http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/
Ken Ford
Adobe Community Expert - Dreamweaver/ColdFusion
Adobe Certified Expert - Dreamweaver CS4
Adobe Certified Expert - ColdFusion 8
Fordwebs, LLC
http://www.fordwebs.com
http://www.cfnoob.com
Copy link to clipboard
Copied
My experience is that the attack happens because some developer
machines are compromised: a trojan on the developer machine can
"steal" FTP usernames and passwords, connect to the FTP accounts and
modify the files.
Check your FTP logs for modifications to the files, change the FTP
usernames and passwords for the site, scan the computers that are
making FTP connections to the site.
Mack
Copy link to clipboard
Copied
This is what you have:
http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/
Ken Ford
Adobe Community Expert - Dreamweaver/ColdFusion
Adobe Certified Expert - Dreamweaver CS4
Adobe Certified Expert - ColdFusion 8
Fordwebs, LLC
http://www.fordwebs.com
http://www.cfnoob.com
Copy link to clipboard
Copied
This problem is necessarily caused by modification of the server-side script files. Therefore, it is necessary that the server must have been compromised. On a shared server, this is "more or less to be expected," since hundreds if not thousands of people other than yourself have accounts on the same server(s). However, there is a lot that you can do to preven it: it only takes a couple of extra steps.
Copy link to clipboard
Copied
Thanks for the great leads everybody.
So it really sounds like the preferred method of entry here is compromised FTP accounts? The server I'm hosting my websites on is a VPS solution and only has a handful of FTP accounts. For the time being I've disabled those accounts, and enabled logging for the FTP server. Once things are cleaned up, I'll restrict the ftp accoutns to the user IPs. Please, keep the information coming - this has been really helpful.
Copy link to clipboard
Copied
Get ready! An upgraded Adobe Community experience is coming in January.
Learn more