hello,
may be your client thinks that the the mach-ii.xml file, which drive the app, can be easily modified by a malicious hacker: you can move this file, and views too as they are <cfimport>-ed, in a folder outside of site root; you can also map another folder, say com, that contains the framework and, for each app, subfolders containing all cfc's: listeners, BO,DAO's etc: this way only index.cfm and application.cfm are exposed.
Bye
salvatore
----- Original Message -----
Sent: Tuesday, January 11, 2005 11:02 PM
Subject: [CFCDev] implicit invocation security concerns

A client of mine said that he was concerned with Mach-ii because he was worried about implicit invocation security concerns. I've searched around but I haven't been able to get much information about implicit invocation and security and nothing about Mach-ii security concerns. How do I reply to his query in a way that will make him confident in the framework?

Reply via email to