I read about this site OWASP (Open Web Application Security Project) and it seems like a pretty good resource. On this list, there have been discussions about best practices for securing web applications. www.owasp. org is designed for all web apps, not just CF.
"The Open Web Application Security Project was setup to build an industry standard framework for testing the security of web applications" --------------------------------------- Ben Morris Web Site Developer American Federation of Government Employees, AFL-CIO (202) 639-6448 www.afge.org ______________________________________________________________________ Dedicated Windows 2000 Server PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation � $99/Month � Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusiona FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/[email protected]/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

