Has anyone else but me contemplated the potential whole in CFMX having the
ability to access .java files? i.e. in CFMX although it has CFFILE/DIRECTORY
flags on/off with Sandboxing, what's to stop you from manipulating
files/directories from other peoples components made in .java?

or can that be controlled? If so how?

Scott.



"Steve Onnis" <[EMAIL PROTECTED]> wrote in message news:22794@cfaussie...
>
> Jason
>
> I personally would love to have a talk about potential security holes.
>
> Which state are you located in?
>
> Regards
> Steve Onnis
> Domain Concept Designs
> +61 422 337 685
> +61 3 9431 4249
> http://www.domainconceptdesigns.com <http://www.domainconceptdesigns.com/>
> [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
> http://www.cfcentral.com.au
> <http://www.cfcentral.com.au/> [EMAIL PROTECTED]
> <mailto:[EMAIL PROTECTED]>
>
>
> ("If you think it can't be done, you haven't asked me!") - Steve Onnis
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of
> jasongreenfield
> Sent: Sunday, February 09, 2003 8:13 PM
> To: CFAussie Mailing List
> Subject: [cfaussie] Re: Security
>
>
> > Its just that I personally have never seen you on this list before, and
it
> > was just strange that someone new would ask straight off the bat for
> people
> > to let you try and hack into there systems.
>
> I see your point.
> I guess I did not explain myself well enough, I mainly just wanted to see
if
> there were any people interested, and would have taken it from there.
> However I did not think I would be attacked like this, however I have been
> attacked before like this, but figured people would be more sensible on
this
> list.
>
> Basically, how about an
> > introduction from you?  Who are you?  Whats your background? Who do you
> work
> > for?
>
> Introduction? Not sure where to start or what to tell?
> Been working with CF for over 5 years, and love it.
> I work for myself at the moment.
>
> > I can see the reasoning for someone doing something like this, but for
me,
> I
> > would probably only let someone that I saw as an authority on the
subject
> > perform this on any of my applications.
> >
> > And even if I did, for what purpose it this for?  Time and time again,
we
> > see papers and articles on the web baging the crap out of Macromedia and
> > ColdFusion saying that it not safe and that ASP or PHP is sooo much
> better.
>
> This is not to attack ColdFusion, this is to make the CF community
stronger.
> No other language is better than CF and CF is no better than any other
> language. The problem lies with the programmer (if there is one), not the
> language. ASP and PHP have the same problems really, it's not a matter of
> what language is used.
>
> > You have given no clear indication of how the results of your tests will
> be
> > used, or even if they will be made available to the ColdFusion community
> as
> > a whole.  Some people, just like Scott did, could just assume that you
> could
> > be just some linux geek tht is out there to defame the product, and
other
> > people could see what your trying to do, and take advantage of it.  Just
> not
> > knowing who you are, the purpose of the tests or how they will be used
> just
> > makes it harder to interperate which one you are.
>
> I can understand that, however I would figure if I was someone that wanted
> to do something like that, I would not be asking anyone for permission, I
> would just follow this list and pick any URL thrown on the list and see if
> they were hackable..
> Why would I want to do something like this? Easy, the more people you get
to
> discuss the possible problems with, the more input you receive, the more
> knowledge I and others receive.
>
> > No offence
>
> None taken, I can take discussion, but not attack.
> Cheers.
>
> > Regards
> > Steve Onnis
> > Domain Concept Designs
> > +61 422 337 685
> > +61 3 9431 4249
> > http://www.domainconceptdesigns.com
<http://www.domainconceptdesigns.com/>
> > [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
> > http://www.cfcentral.com.au
> > <http://www.cfcentral.com.au/> [EMAIL PROTECTED]
> > <mailto:[EMAIL PROTECTED]>
> >
> >
> > ("If you think it can't be done, you haven't asked me!") - Steve Onnis
> >
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED]]On Behalf Of
> > jasongreenfield
> > Sent: Sunday, February 09, 2003 7:04 PM
> > To: CFAussie Mailing List
> > Subject: [cfaussie] Re: Security
> >
> >
> > Mate, I think you got a serious attitude problem.
> > Trying to help and make the Internet community a safer place, and what
do
> > you get attitude from someone like you. For some reason most guys like
you
> > always feel attacked, and do nothing but mistrust. What's wrong? You
know
> > you got security holes but don't want it to be known?
> >
> > Fine, if no one is interested. But I don't deserve your attitude mister.
> >
> > Chill out man.
> > Jason
> >
> > > You could, but you could also run the risk of tapping the wrong
> > > machine/address... maybe its a dodgey ISP or maybe its a Topgun one
that
> > has
> > > an er33t Sysadmin... the question is... do you feel lucky... well do
ya
> > > punk... feel lucky...
> > >
> > > I seriously doubt you're chances of this project going ahead,
> furthermore
> > i
> > > seriously question the sanity of anyone on this list considering
letting
> > you
> > > in..... mainly for one important reason is that .. up until today??
who
> > are
> > > you? ie if Steve wanted to test something on my server, i'd weigh up
the
> > > pro's cons and knowing the fact that i have a rough idea on where he
> lives
> > > (in the event something bad was to happen, i can then order a hitman
to
> > > break his legs)... but with you? hell you're a .com address for a
start
> > > which means you could be a either a saint working on the behave of all
> > thats
> > > good.. or you could be Osama Bin Laden's pet monkey? we have no real
way
> > of
> > > knowing you're who you say you are or what you're intentions are.
> > >
> > > Peace Luv, and stay the hell away from my servers punk! :)
> > >
> > > Scott
> >
> >
> > ---
> > You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> > To unsubscribe send a blank email to
> [EMAIL PROTECTED]
> >
> > MX Downunder AsiaPac DevCon - http://mxdu.com/
> >
> >
> > ---
> > You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> > To unsubscribe send a blank email to
> [EMAIL PROTECTED]
> >
> > MX Downunder AsiaPac DevCon - http://mxdu.com/
> >
>
> ---
> You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> To unsubscribe send a blank email to [EMAIL PROTECTED]
>
> MX Downunder AsiaPac DevCon - http://mxdu.com/
>
>
>



---
You are currently subscribed to cfaussie as: [email protected]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to