Well here's a little snippet for you.
Sandboxes do bugger all for protecting use of createobject and CFOBJECT. 
With these enabled any users on the server can delete your DSN's, verity
collections or anything else setup in the CFADMIN. They can query your DSN
from the registry and access your database, plus run various system
components without restriction and use java reflection methods to do just
about anything java allows.

So you have just advertised that Hostmysite,.com open this particular
security hole unknowingly, and proved that you thought it was great because
you also had no idea of this issue and are relying on their knowledge.
Which is exactly what I said happens below.

So as for your statement that it's all Rubbish and crap, I think you have
just proved the point.
Perhaps it might be a better idea to make sure your not talking rubbish next
time you make a hot-headed reply.


Russ 

> -----Original Message-----
> From: John Beynon [mailto:[EMAIL PROTECTED] 
> Sent: 17 August 2004 16:46
> To: [EMAIL PROTECTED]
> Subject: Re: [ cf-dev ] cfmx hosting
> 
> sorry but that's complete crap.
> 
> Hostmysite.com service is excellent whatever time of day you 
> contact them, the time difference is irrevelant, as i 
> originally stated, whatever time of day i have contacted them 
> i've got a response within 20 minutes!!! Usually i email 
> about 9am UK time which is 4am their time and i get a response.
> 
> As for cheap hosts not providing sandboxes, rubbish! They 
> provide sandboxing. I needed cfobject/createobject for CFC 
> invocation so i emailed them and they set the sandbox up 
> allowing me to use those tags. They have recently denied me 
> the use of cfx_zip as it it doesn't adhere to sandbox rules 
> and thus was insecure  - they even contacted Ben Forta on my 
> behalf to see if there was anything that can be done about it.
> 
> hmm, where has BenF just moved his personal site too? Any guesses :)
> 
> 
> On Tue, 17 Aug 2004 16:32:03 +0100,
> [EMAIL PROTECTED]
> <[EMAIL PROTECTED]> wrote:
> > 
> > there's your endorsement Russ to use in your Sales & Marketing:
> > "I think CFMX hosting is the best solution to mine & the clients 
> > needs." - Paul Swingewood, CF guru.
> > 
> > ;-)
> > 
> >                     "Paul Swingewood"
> >                     <[EMAIL PROTECTED]        To:     
> [EMAIL PROTECTED]
> >                     tmail.com>                 cc:
> >                                                Subject:     
> RE: [ cf-dev ] cfmx hosting                                  
> >                     17/08/2004 16:27
> >                     Please respond to
> >                     dev
> > 
> > 
> > 
> > 
> > oops didn't mean to start a hosting war.
> > 
> > I suggested CFMX hosting to my client for all the reasons that Russ 
> > has just said.
> > #1 that I can pick up the phone and speak to someone right now who 
> > understands what I am trying to do and who will help me 
> achieve it. Wicked!
> > 
> > I should point out that I am not paying for the hosting the 
> client is.
> > For me I think CFMX hosting is the best solution to mine & 
> the clients 
> > needs.
> > 
> > Regards - Paul
> > 
> > --
> > These lists are syncronised with the CFDeveloper forum at 
> > http://forum.cfdeveloper.co.uk/
> > Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
> > 
> > CFDeveloper Sponsors and contributors:- *Hosting and 
> support provided 
> > by CFMXhosting.co.uk* :: *ActivePDF provided by activepdf.com*
> >       *Forums provided by fusetalk.com* :: *ProWorkFlow provided by
> > proworkflow.com*
> >            *Tutorials provided by helmguru.com* :: *Lists hosted by
> > gradwell.com*
> > 
> > To unsubscribe, e-mail: [EMAIL PROTECTED]
> > 
> > --
> > These lists are syncronised with the CFDeveloper forum at 
> > http://forum.cfdeveloper.co.uk/
> > Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
> > 
> > CFDeveloper Sponsors and contributors:- *Hosting and 
> support provided 
> > by CFMXhosting.co.uk* :: *ActivePDF provided by activepdf.com*
> >       *Forums provided by fusetalk.com* :: *ProWorkFlow 
> provided by proworkflow.com*
> >            *Tutorials provided by helmguru.com* :: *Lists hosted by 
> > gradwell.com*
> > 
> > To unsubscribe, e-mail: [EMAIL PROTECTED]
> > 
> >
> 
> --
> These lists are syncronised with the CFDeveloper forum at 
> http://forum.cfdeveloper.co.uk/
> Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
>  
> CFDeveloper Sponsors and contributors:-
> *Hosting and support provided by CFMXhosting.co.uk* :: 
> *ActivePDF provided by activepdf.com*
>       *Forums provided by fusetalk.com* :: *ProWorkFlow 
> provided by proworkflow.com*
>            *Tutorials provided by helmguru.com* :: *Lists 
> hosted by gradwell.com*
> 
> To unsubscribe, e-mail: [EMAIL PROTECTED]
> 
> 



-- 
These lists are syncronised with the CFDeveloper forum at 
http://forum.cfdeveloper.co.uk/
Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
 
CFDeveloper Sponsors and contributors:-
*Hosting and support provided by CFMXhosting.co.uk* :: *ActivePDF provided by 
activepdf.com*
      *Forums provided by fusetalk.com* :: *ProWorkFlow provided by proworkflow.com*
           *Tutorials provided by helmguru.com* :: *Lists hosted by gradwell.com*

To unsubscribe, e-mail: [EMAIL PROTECTED]

Reply via email to