Penetration Testing mailing list archives
Re: brute force ColdFusion MX7 admin page
From: krymson () gmail com
Date: 26 Dec 2007 15:23:21 -0000
Wish I could help more, but I can offer up the ability to view the ColdFusion MX7 admin login page. Google "enter your coldfusion administrator password" and you'll see a couple MX 7 pages to check the source of. Otherwise, Joseph's details are what I'd suggest. I don't recall the ColdFusion admin login ever locking out or even logging anything useful for detecting a long-term brute force attack. Hopefully they have a strong, unique password and turn off external viewing, especially if they log in from insecure places without https... ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- brute force ColdFusion MX7 admin page Anonymous (Dec 19)
- Re: brute force ColdFusion MX7 admin page Joseph McCray (Dec 23)
- RE: brute force ColdFusion MX7 admin page Marc Ouwerkerk (Dec 23)
- <Possible follow-ups>
- Re: brute force ColdFusion MX7 admin page krymson (Dec 27)