16.04.2013 Views

Adobe® ColdFusion® 10 Server Lockdown Guide

Adobe® ColdFusion® 10 Server Lockdown Guide

Adobe® ColdFusion® 10 Server Lockdown Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Our strategy here is to block all URI’s that do not need to be accessible to the public. Some of the resources<br />

we will block here may not pose any known threat but could be used to determine the version of ColdFusion<br />

you are running. Ideally we could block all /CFIDE, however if you use cfchart the generated graphics are<br />

rendered from /CFIDE/GraphData.cfm<br />

It is not possible using request filtering to deny the URI /CFIDE but then allow /CFIDE/GraphData.cfm for<br />

example.<br />

If you are not using cfchart and do not need access to any of the URIs below you may simply deny /CFIDE<br />

instead of listing each sub directory.<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!