logo

NORAD Was Blind During Y2k Vigil -- Satellite Redundancy Wasnīt There


Latest News Stories:

cover-eletronicprivacy

Only $31.95

New Methodology:

shun

Product Reviews

OSAll is starting to do weekly product reviews, to be published every single Friday.  Check out software, book and hardware reviews.

 Check it out!

Front | Methods | BBS | FAQ | Adverts | Mail | Write | Link | Shop

"Y2k, all hype, all the time."

Cold Fusion Hole -- Still Not Fixed

    The Fisical Elemental

The security bug in Cold Fusion is hardly news -- it was released to the correct circles ages ago, and a bug fix was released soon thereafter.  The hole in Cold Fusion allows users to upload, download, delete and even run things on a CF server.  But the Cold Fusion bug is still being exploited across the Web.

Why has it taken so long for the bug fix to be implemented across the Web -- or at least at the major sites.  Companies like IBM and Computer Solutions found themselves with their pants down.  All in all, about a hundred sites became victims to the Cold Fusion bug after the patch was released.

All that this means is that people (and companies) have to impliment bug fixes immediately.  In other words, the word has to get out better.  Email alerts and CERT apparently arenīt doing enough.

What can we do?  Iīm not sure.  But something has to be done.  Itīs absolutely ridiculous that sites are still vulnerable after a patch has been available for weeks.

Donīt forget to discuss this issue on the OSAll BBSystem!

All content copyright 1998 - 99 unless book covers or otherwise noted.  Book covers copyright 1998 - 99 Amazon.com.  All OSAll-owned content may be reprinted with the following header added: "Copyright 1998 - 99 Owl Services.  Visit aviary-mag.com for computer security news and information."  Article authors retain a non-exclusive right to republish their work.   324