On ColdFusion, XXE, and other XML Attacks
An IntroductionThis is the first of what may become a few blog posts based on my CFSummit 2022 talk.
An IntroductionThis is the first of what may become a few blog posts based on my CFSummit 2022 talk.
CFML developers that still say "I don't know how to use ColdBox", your excuses are now officially invalid. ;) The ColdBox Master Class video training series that I produced for Ortus Solutions is FREE for the rest of the year!
From: South of Shasta: Software Development, Web Design, Training
As of the Oct 2022 CF updates (CF2021 update 5 and CF2018 update 15), Adobe has chosen to remove the CF Admin feature to view, search, download, and delete CF logs, due to asserted (but as-yet undocumented) security concerns.
I've had a several people asking me about the openssl vulnerabilities that were patched this week: CVE-2022-3602 and CVE-2022-3786 aka Spooky SSL.
From: Pete Freitag's Homepage
I've had a several people asking me about the openssl vulnerabilities that were patched this week: CVE-2022-3602 and CVE-2022-3786 aka Spooky SSL.
From: Pete Freitag's Homepage
Early bird registration is open for my ColdFusion Security Training deep dive class in December.
From: Pete Freitag's Homepage
Early bird registration is open for my ColdFusion Security Training deep dive class in December.
From: Pete Freitag's Homepage
If you're running CF2016 or earlier, now's your chance (though the end of the year Feb 28, 2023) to save potentially thousands of dollars in upgrading to the latest current version, CF2021.
If you try to download a CF update using the ColdFusion Administrator AND you get an error, "error occurred while installing the update: Failed Signature Verification", there are both a couple of possible explanations (one of them new), both with fairly simple solutions. [More]
Someone asked on the CFML slack recently how can you find out how long your ColdFusion (or Lucee) server has been running via code.
From: Pete Freitag's Homepage
Someone asked on the CFML slack recently how can you find out how long your ColdFusion (or Lucee) server has been running via code.
From: Pete Freitag's Homepage
Here's a heads-up that some will want to hear about: there are new JVM updates released today (Oct 18, 2022) for the current long-term support (LTS) releases of Oracle Java, 8, 11, and 17, as well as the new interim update 19.
We can implement a SQL Server equivalent of MySQL/MariaDB's "INSERT IGNORE" using MERGE INTO as follows...
Here's some surprising news: Adobe has released a "refreshed" installer for CF2021, which includes update 5 (which came out last week) built-in.
This year marked the tenth anniversary of the Adobe ColdFusion Summit.
From: Brian Klaas
Using the INSERT IGNORE statement you can easily manage reference table's data using re-runnable sql scripts.
This is a call to anyone who may have a CF-oriented presentation: we would welcome you presenting it on the Online ColdFusion Meetup.
The Adobe CF Summit 2022 is done! I'm down in the hotel lobby waiting for my ride to the airport which means it's officially time to work on my conference recap! Honestly I can't think of any reason that this conference wasn't a huge success for everyone involved.
From: South of Shasta: Software Development, Web Design, Training
CloudFlare recently released a new CAPTCHA service called Turnstile, which aims to provide a better user experience for CAPTCHA's.
From: Pete Freitag's Homepage
CloudFlare recently released a new CAPTCHA service called Turnstile, which aims to provide a better user experience for CAPTCHA's.
From: Pete Freitag's Homepage