Entries for month: September 2006

ColdFusion Sandbox Security vulnerability

CFML 1 Comment »
Adobe released a security advisory yesterday and it was reported by yours truely!! I was quite surprised to find a problem and thought it was just me messing something up with sandboxes and the cfc I was messing with, so I asked Andy Allan to see if he could see what I was doing wrong! Turns out, for once, I was actually getting it right and that this was a bug. Andy kindly reported it to the powers that be and a fix was included in the 7.0.2 update. If you're using sandboxes and haven't already installed the updater then I would recommend that you do. UPDATE : On the Scottish CFUG Google Group Alan Williamson asked about the process involved in the security issue. In my absense Andy Allan gave a nice clear explaination of the problem, so rather than rewrite it here's what Andy said :
A sandbox is essentially a "self contained" area on the file structure which a user has access to. So, in shared hosting which is where your sandboxing would come into play, you could have something like: c:\www\user1
c:\www\user2
c:\www\user3
You would set up a sandbox for each user allowing them access ONLY to their particular folder. You can set further restrictions in regards, tags, functions, datasouces, etc as well. In this particular case - I know, because I verified the issue - CFCs outside the users sandbox could still be called by cfm files within a sandbox. CFM files outside the sandbox could not be called.

SCFUG Meeting: Virtual Machines and the Development Cycle.

CFML , Scottish ColdFusion User Group 1 Comment »
The Scottish ColdFusion User Group Meeting is coming up at the end of this month. On Thursday 28th of September Kev McCabe will be giving us a presentation on the benefits of Virtual Machines in the development cycle. Kev will be presenting from the BSkyB offices in London, where UKCFUG and Thames Valley UG members will be able to attend, but will also be presenting live via Breeze.

Read more...

Blog Round Up : Week Ending 8th September

Blog Round Up No Comments »
Seeing as Andy's broken his router and by association his personal website, for the next couple of weeks I'll be hosting Andy's Blog Round Up. ** Scottish ColdFusion User Group
Shameless self promotion
SCFUG September Meeting **Adobe
New Adobe Captivate 2 Enables Rapid Creation of High-Impact eLearning Experiences
Adobe acquires InterAKT
Suggested MAX Session Path For CFers
The Greenest Office in America (One that intrigued me because of projects that are going on here at work)
**Flex
Why I think you shouldn’t use Cairngorm **Flex Data Service and ColdFusion
Do ColdFusion Developers Need Flex Data Services?
** Captcha
A couple that Andy missed last week.
Captchas: making them simpler, and dialing down the angst against them
Simplifying the captcha graphic in Lyla Captcha (and BlogCFC) ** Fusion Debug
FusionDebug : Why get excited? and Why Use FusionDebug

Creatively Restrained...

General 1 Comment »
If you were wondering whats happened to Andy Allan's blog, Creative Restraint.... Andy has been a bit creative with his router at home. He apparently knocked it off of his desk which ripped the ethernet port out of the back. Telewest have kindly agreed to replace it in a fortnight's time for £50 + £75 call out. So Andy's blog is going to be down for a little while until it gets replaced.
Powered by Mango Blog. Design and Icons by N.Design Studio
RSS Feeds