[EMAIL PROTECTED] wrote:
> 
> As you know in SQL Enterprise, you're able to see the database names 
> of other people sharing the SQL server.  and by looking at the names 
> you can probably guess what they named their DSN.  I got lucky, and 
> nabbed one.  I pulled out the table names from sysobjects.  Then 
> pulled out the field names from a "very desirable" table using 
> columnlist, then was able to pull out data!  I was appalled!  Because 
> my DSNs are named after my site and anyone could have just done with 
> I've done, but with a different intent.

Set a password.


> and also, can someone tell me how many webHosts turn off the 
> CFREGISTRY tag? 

Turn off: to little
Secure in other ways: still to little

Jochem

______________________________________________________________________
Your ad could be here. Monies from ads go to support these lists and provide more 
resources for the community. http://www.fusionauthority.com/ads.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to