[Dshield] file is_this_the_index.cfm

John Groseclose iain at caradoc.org
Sat Aug 25 14:01:01 GMT 2001

At 5:32 PM -0700 8/24/01, <miroslaws at home.com> wrote:
>I have noticed in few logs in different independent web servers the request
>for file is_this_the_index.cfm The .cfm suggests for Cold Fusion script or
>template. Because I am not expert in Cold Fusion, maybe somebody would know
>if such file has any significant meaning?
>The log entries always shows the same IP address and have the same format:
>[18/Aug/2001:13:34:06 -0700] "HEAD / HTTP/1.0" 200 0 "-" "Mozilla/4.7 [en]
>(WinNT; I)"
>[18/Aug/2001:13:34:07 -0700] "GET /is_this_the_index.cfm HTTP/1.0" 404 0 "-"
>"Mozilla/4.7 [en] (WinNT; I)"

Someone's looking for the default/example Cold Fusion scripts, which 
have a security hole.

John Groseclose
iain at caradoc.org

More information about the list mailing list