> Excellent point, Dave, thanks. On "4. Block external access > to the built-in web server.", does any of cf8 > resources/functions/tags depend on it? If not I would simply > disable it.
If you're using the built-in web server to run the CF Administrator, you probably wouldn't want to disable it. You simply want to limit how it can be run. Typically, in a Windows environment, I use Remote Desktop to access the server, then run the browser from the desktop to manage the server. Also, typically, external access to the server is limited to standard HTTP/HTTPS ports. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ Fig Leaf Training: Adobe/Google/Paperthin Certified Partners http://training.figleaf.com/ WebManiacs 2008: the ultimate conference for CF/Flex/AIR developers! http://www.webmaniacsconference.com/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Adobe® ColdFusion® 8 software 8 is the most important and dramatic release to date Get the Free Trial http://ad.doubleclick.net/clk;160198600;22374440;w Archive: http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:298227 Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4

