-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> >     I found a simple way to "crash" CF..  just include a 
> file in itself..
> > or an endless loop.
> > I think that uses up all available resources until cf can't 
> function anymore!
> >
> > For example: in header.cfm
> >
> > -----------------------
> > ...
> > <cfinclude template = "header.cm">
> > ...
> > ----------------------

That's why you should set a maximum page request timeout in your CF
Administrator.  You're still up for a nasty DoS attack there if
someone keeps hitting the page over & over, but at least the threads
will eventually time out & start doing some useful work again...

Best regards,
Zac Bedell

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOYllcAraVoMWBwRBEQIifgCeM0MCX+PdFNjjC0sQUYFxuWhrY9UAnjRr
5X7OJiEGKDL8hdEHkDGfLiHp
=50At
-----END PGP SIGNATURE-----
------------------------------------------------------------------------------
Archives: http://www.mail-archive.com/[email protected]/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

Reply via email to