Using FileReadLine() With Seekable Files In ColdFusion

Ben Nadel explores the use of fileReadLine() in conjunction with seekable files in ColdFusion....

From: Ben Nadel

Working Code Podcast - Episode 144: The Power Of One

Ben Nadel and the crew talk about the "Power of One" - picking a single, small goal that can be accomplished (and celebrated)....

From: Ben Nadel

Exploiting CVE-2017-11286 Six Years Later: XXE in ColdFusion via WDDX Packet

IntroductionπŸŽˆπŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚πŸŽ‚πŸŽˆSix years ago today, on September 12, 2017, Adobe released APSB17-30.

From: Hoya Haxa - A Security Research Blog

Coming Soon: Feature Flags - From Concept To Cultural Revolution

Ben Nadel is going to try his hand at writing a book: Feature Flags - From Concept to Cultural Revolution, an opinionated guide to product development....

From: Ben Nadel

A First Look at the new JDBC Client in Spring Boot 3.2

In this tutorial, we'll be diving into the fresh waters of the new JDBC client in Spring Framework 6.1 and Spring Boot 3.2.

From: Dan Vega

A First Look at the new Rest Client in Spring Boot 3.2

Greetings, folks! It's Dan Vega, Spring developer advocate at VMware. Today, I am thrilled to dive into Spring Boot 3.2 and its new REST client. But before we do, let's take a moment to examine our journey to this moment.

From: Dan Vega

A First Look at the new Rest Client in Spring Boot 3.2

This is my first look at the new Rest Client in Spring Boot 3.2. In this tutorial we will discuss what a client is, what are the different implementations of clients available and how to get started with the new Rest Client in Spring Framework 6.1 and Spring Boot 3.2

From: Dan Vega

Using Labeled Loops In JavaScript

Ben Nadel explores labeled loops in JavaScript, exerting control flow on an outer loop from within an inner loop context....

From: Ben Nadel

Working Code Podcast - Episode 143: Moving On, Rewriting, And Replatforming

Ben Nadel and the crew talk about moving on - from jobs, from relationships, from roles, from tech stacks, etc....

From: Ben Nadel

Links For You

Welcome to another collection of links, and for today, a very "component" flavored set of links.

From: Raymond Camden

Including CSS File Content Using CFInclude In ColdFusion

Ben Nadel uses the CFInclude tag to inline a .CSS file into his ColdFusion page in order to reduce network requests and latency....

From: Ben Nadel

Using Labeled Loops In ColdFusion

Ben Nadel explores the use of loop labels in ColdFusion to control and outer loop from an inner loop....

From: Ben Nadel

Join Us at The Undefined Show!

On September 11th, Todd Sharp, Scott Stroz, and myself will be launching a new livestream called The Undefined Show.

From: Raymond Camden

Using Seekable Read Files In ColdFusion

Ben Nadel looks at using fileSeek() to randomly access seekable files in ColdFusion....

From: Ben Nadel

Fun With Front Matter: Part 3 - Handling Edits

I hope by now that folks are getting that the point of this series isn't so much technical but inspirational.

From: Raymond Camden

Using CFLoop To Iterate Over A File Line-By-Line In ColdFusion

Ben Nadel demonstrates how to read a text file line-by-line using CFLoop in ColdFusion....

From: Ben Nadel

Using Feature Flags To Hack Your Own Psychology

Ben Nadel discusses the psychological benefits of using feature flags as a way to provide landmarks and a sense of continual progress....

From: Ben Nadel

Working Code Podcast - Episode 142: Tangents All The Way Down

Ben Nadel and the crew talk all manner of randomness from vendoring files to the trap of innovation....

From: Ben Nadel

Technical Details for CVE-2023-29301: Adobe ColdFusion Access Control Bypass for a CFAdmin Authentication Component

BackgroundIn this post I'll be walking though CVE-2023-29301, which is an access control bypass / password brute force vulnerability in Adobe ColdFusion that I reported to Adobe and was fixed on July 11, 2023 in Adobe Product Security Bulletin APSB23-40.

From: Hoya Haxa - A Security Research Blog