<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <link>http://mikewatkins.ca/tags/security/</link>
  <atom:link href="http://mikewatkins.ca/tags/security/feeds/rss" type="application/rss+xml" rel="self"/>
  <lastBuildDate>Sat, 04 Jul 2009 16:36:57 GMT</lastBuildDate>
  <title>mike watkins dot ca</title>
  <description>XML Feed for mike watkins dot ca</description>
  <language>en</language>
  <generator>Parlez/0.1</generator>
<item>
  <title>Exploits Away</title>
  <link>http://mikewatkins.ca/2009/07/04/exploits-away/</link>
  <description><![CDATA[
<div class="document">
<p>Cold Fusion and some PHP sites are being hit hard over the last 24 hours by what appear to be Chinese cyber-criminals using an exploit found within the popular browser-based editor component <a class="reference external" href="http://www.fckeditor.net/">FCKeditor</a>. The vulnerability allows for remote code execution / uploading of files to arbitrary locations / installation of remote shells and it would appear that many sites are being attacked.</p>
<p>Versions &lt;= the current shipping version (FCKeditor &lt;= 2.6.4) are vulnerable. A patch does not yet exist; in the mean time disabling the file browser is one of the mitigation steps.</p>
<p>A number of Python projects utilize this editor component.</p>
<p>oCERT Advisory: <a class="reference external" href="http://www.ocert.org/advisories/ocert-2009-007.html">http://www.ocert.org/advisories/ocert-2009-007.html</a></p>
</div>

]]></description>
  <guid isPermaLink="false">tag:mikewatkins.ca,2007-10-10:journal:mw:entry:713</guid>
  <pubDate>Sat, 04 Jul 2009 16:36:57 GMT</pubDate>
  <category>python</category>
  <category>security</category>
</item>
</channel></rss>
