Has anyone else but me contemplated the potential whole in CFMX having the ability to access .java files? i.e. in CFMX although it has CFFILE/DIRECTORY flags on/off with Sandboxing, what's to stop you from manipulating files/directories from other peoples components made in .java?
or can that be controlled? If so how? Scott. "Steve Onnis" <[EMAIL PROTECTED]> wrote in message news:22794@cfaussie... > > Jason > > I personally would love to have a talk about potential security holes. > > Which state are you located in? > > Regards > Steve Onnis > Domain Concept Designs > +61 422 337 685 > +61 3 9431 4249 > http://www.domainconceptdesigns.com <http://www.domainconceptdesigns.com/> > [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> > http://www.cfcentral.com.au > <http://www.cfcentral.com.au/> [EMAIL PROTECTED] > <mailto:[EMAIL PROTECTED]> > > > ("If you think it can't be done, you haven't asked me!") - Steve Onnis > > > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of > jasongreenfield > Sent: Sunday, February 09, 2003 8:13 PM > To: CFAussie Mailing List > Subject: [cfaussie] Re: Security > > > > Its just that I personally have never seen you on this list before, and it > > was just strange that someone new would ask straight off the bat for > people > > to let you try and hack into there systems. > > I see your point. > I guess I did not explain myself well enough, I mainly just wanted to see if > there were any people interested, and would have taken it from there. > However I did not think I would be attacked like this, however I have been > attacked before like this, but figured people would be more sensible on this > list. > > Basically, how about an > > introduction from you? Who are you? Whats your background? Who do you > work > > for? > > Introduction? Not sure where to start or what to tell? > Been working with CF for over 5 years, and love it. > I work for myself at the moment. > > > I can see the reasoning for someone doing something like this, but for me, > I > > would probably only let someone that I saw as an authority on the subject > > perform this on any of my applications. > > > > And even if I did, for what purpose it this for? Time and time again, we > > see papers and articles on the web baging the crap out of Macromedia and > > ColdFusion saying that it not safe and that ASP or PHP is sooo much > better. > > This is not to attack ColdFusion, this is to make the CF community stronger. > No other language is better than CF and CF is no better than any other > language. The problem lies with the programmer (if there is one), not the > language. ASP and PHP have the same problems really, it's not a matter of > what language is used. > > > You have given no clear indication of how the results of your tests will > be > > used, or even if they will be made available to the ColdFusion community > as > > a whole. Some people, just like Scott did, could just assume that you > could > > be just some linux geek tht is out there to defame the product, and other > > people could see what your trying to do, and take advantage of it. Just > not > > knowing who you are, the purpose of the tests or how they will be used > just > > makes it harder to interperate which one you are. > > I can understand that, however I would figure if I was someone that wanted > to do something like that, I would not be asking anyone for permission, I > would just follow this list and pick any URL thrown on the list and see if > they were hackable.. > Why would I want to do something like this? Easy, the more people you get to > discuss the possible problems with, the more input you receive, the more > knowledge I and others receive. > > > No offence > > None taken, I can take discussion, but not attack. > Cheers. > > > Regards > > Steve Onnis > > Domain Concept Designs > > +61 422 337 685 > > +61 3 9431 4249 > > http://www.domainconceptdesigns.com <http://www.domainconceptdesigns.com/> > > [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> > > http://www.cfcentral.com.au > > <http://www.cfcentral.com.au/> [EMAIL PROTECTED] > > <mailto:[EMAIL PROTECTED]> > > > > > > ("If you think it can't be done, you haven't asked me!") - Steve Onnis > > > > > > -----Original Message----- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED]]On Behalf Of > > jasongreenfield > > Sent: Sunday, February 09, 2003 7:04 PM > > To: CFAussie Mailing List > > Subject: [cfaussie] Re: Security > > > > > > Mate, I think you got a serious attitude problem. > > Trying to help and make the Internet community a safer place, and what do > > you get attitude from someone like you. For some reason most guys like you > > always feel attacked, and do nothing but mistrust. What's wrong? You know > > you got security holes but don't want it to be known? > > > > Fine, if no one is interested. But I don't deserve your attitude mister. > > > > Chill out man. > > Jason > > > > > You could, but you could also run the risk of tapping the wrong > > > machine/address... maybe its a dodgey ISP or maybe its a Topgun one that > > has > > > an er33t Sysadmin... the question is... do you feel lucky... well do ya > > > punk... feel lucky... > > > > > > I seriously doubt you're chances of this project going ahead, > furthermore > > i > > > seriously question the sanity of anyone on this list considering letting > > you > > > in..... mainly for one important reason is that .. up until today?? who > > are > > > you? ie if Steve wanted to test something on my server, i'd weigh up the > > > pro's cons and knowing the fact that i have a rough idea on where he > lives > > > (in the event something bad was to happen, i can then order a hitman to > > > break his legs)... but with you? hell you're a .com address for a start > > > which means you could be a either a saint working on the behave of all > > thats > > > good.. or you could be Osama Bin Laden's pet monkey? we have no real way > > of > > > knowing you're who you say you are or what you're intentions are. > > > > > > Peace Luv, and stay the hell away from my servers punk! :) > > > > > > Scott > > > > > > --- > > You are currently subscribed to cfaussie as: [EMAIL PROTECTED] > > To unsubscribe send a blank email to > [EMAIL PROTECTED] > > > > MX Downunder AsiaPac DevCon - http://mxdu.com/ > > > > > > --- > > You are currently subscribed to cfaussie as: [EMAIL PROTECTED] > > To unsubscribe send a blank email to > [EMAIL PROTECTED] > > > > MX Downunder AsiaPac DevCon - http://mxdu.com/ > > > > --- > You are currently subscribed to cfaussie as: [EMAIL PROTECTED] > To unsubscribe send a blank email to [EMAIL PROTECTED] > > MX Downunder AsiaPac DevCon - http://mxdu.com/ > > > --- You are currently subscribed to cfaussie as: [email protected] To unsubscribe send a blank email to [EMAIL PROTECTED] MX Downunder AsiaPac DevCon - http://mxdu.com/
