RE: ColdFusion SP2 -install issues

2000-09-28 Thread Al Musella, DPM
for a game, but not for a server product, where lost time is money. Al Musella, DPM President Musella Foundation For Brain Tumor Research Information virtualtrials.com -- Archives: http://www.mail-archive.com/cf-talk

Re: (Admin) Delays and doubles

2000-09-28 Thread Al Musella, DPM
I run a few large lists on egroups.com. Cost about $50 a year and absolutely no headaches. It is so cheap that it isn't worth your time configuring your own email server anymore, or paying for an internet connection for it. Very rarely are there any problems Al Musella, DPM Musella

Re: TO ALL: Request for ColdFusion SP2 Input - locking

2000-09-29 Thread Al Musella, DPM
ot to have it. thanks Al Musella, DPM Musella Foundation i know one of the items that makes me very uncomfortable is the apparent code incompatibility on the locking issues. i.e. code written for CF server 4.5.1 locking doesn't easily work on 4.0 and

Re: OT: Moving SQL to new server

2000-10-04 Thread Al Musella, DPM
I am no sql expert, but I had the same problem, and solved it by using the export wizard. Just highlight the database in sql server and right click - select export... then follow the wizard and select the new sql server as the destination. Went quickly and easily. (assuming both are

Re: HEEEEEEEEELLLLLLLLLLLLPPPPPPPPPPPPPP! Access Memory Error

2000-10-12 Thread Al Musella, DPM
Also check your hard drive space on your system partition. Running low on space screws everything up, and this is one of the signs. Al Keep getting an Error Code s1001 (Memory Allocation Error) on our CFServer ... Access97 driver is running out of memory ... anyone know what causes this or

Re: [Re: Preventing Simultaneous Logins]

2000-10-18 Thread Al Musella, DPM
To kick out the first user: When someone logs in successfully, create a UUID that is stored in the database and pass along with the user ID. Then in application.cfm, I check the that the UUID and user ID match in the database. IF they don't they get kicked out to the login page. IF someone

RE: Running COldFusion server on a different box to the web server - possible?

2003-01-06 Thread Al Musella, DPM
I would think a better way to separate it would be to have the sql server by itself on one box, and the webserver with asp and cold fusion on the other box. It would get too complicated the way you said. Also - code the path for all graphics using a variable in the application.cfm

Cfpop problem

2003-01-29 Thread Al Musella, DPM
A script that has been working great for years under cf3, then cf4 then cf5 now MX started throwing the error: ~| Archives: http://www.houseoffusion.com/cf_lists/index.cfm?forumid=4 Subscription:

Re: Cfpop problem

2003-01-29 Thread Al Musella, DPM
Line monster ate your last line Sorry - here it is again... (I must have used the line that Michael uses to check for the start of the footer:) A script that has been working great for years under cf4 then cf5 and MX for a few months, then it just now started throwing the error: . . . . An

Re: all records deleted from table

2003-02-04 Thread Al Musella, DPM
A long time ago, I made a really stupid mistake that results in deletion of all data from a table... almost embarrassed to admit this in public, but it might apply here. There was an admin page with a list of all of the records in the table, along with a link to delete or edit each

Re: all records deleted from table

2003-02-05 Thread Al Musella, DPM
I also now put a confirmation page between the link to delete and the actual delete page.. this confirmation page has a form where you have to actually type the word DELETE into a form field and hit the submit button to do the deletion, so a web crawler can't trigger it. At 09:30 AM 2/5/2003,

Urgent: caching problem?

2002-08-02 Thread Al Musella, DPM
I moved 2 websites from my server, which was running CF 4.5, to a new server running CF MX. (on windows 2000) Of course, everything was fine when we tested, but when the DNS changes went live, about a week ago, everything appeared ok at first, but we just noticed something very strange: if

RE: Urgent: caching problem?

2002-08-02 Thread Al Musella, DPM
Thanks guys! Everything works now.. I should have read the manual first.. but it was panic time:) I guess they want to pad their tech support hours by leaving a gotcha like that in there! Al I don't write installer code, but at least ASK the user if they are using IIS with multiple

Re: Urgent: caching problem?

2002-08-03 Thread Al Musella, DPM
I think it is more that they expect people to read the manual. Why bother making a manual otherwise? True.But I actually did read (maybe skimmed should be more like it:) the release notes.. Perhaps wording it differently would have made it stick in my mind.. telling us what would

cfchart - frequency distributions..

2002-08-13 Thread Al Musella, DPM
I am trying to display results from a survey... When I create a bar chart for a frequency distribution of the responses, the Y axis displays how many times a response was selected, but the labels are not whole numbers. they appear as, for example: 01.4 2.33.9 etc.. I want

RE: cfchart - frequency distributions..

2002-08-13 Thread Al Musella, DPM
No - the data is already integers.. it is just the labels that are scaled wrong.. At 07:42 PM 8/13/2002 -0400, you wrote: use the #int(variable)# function will return the smallest whole number matt -Original Message- From: Al Musella, DPM [mailto:[EMAIL PROTECTED]] Sent: Tuesday

Re: Exclude pages from Verity collection

2002-08-14 Thread Al Musella, DPM
I may do things the hard way, but the approach I take is to put a comment in the files that I do not want indexed, like: ! DO NOT INDEX!!! -- Then, when indexing them, I use cffile to list the files in the directories, and cfhttp to read them. I look for that comment, and if not

Re: SOT Pages not found

2002-08-29 Thread Al Musella, DPM
What I do is set up a site-wide missing template handler (In the cold fusion admin) that points to a file that contains the following script: === cfif isdefined('http_host') cflocation url=http://#http_host#/404.cfm; addtoken=No /cfif

Re: OT: Paid by a percentage of the gross?? Anyone?

2002-09-08 Thread Al Musella, DPM
I have made a few mistakes on this topic in the past - from both sides of the fence. I won't bore you with the details, but my thoughts for the next try: 1. It is worth a try to spend a small part of your time on something like this, because you are never going to get rich working by the

Re: Generating Invoices

2002-04-28 Thread Al Musella, DPM
I am working on something similiar here - printinout out information onto medical forms - and think I got the easiest answer:) Just print it out using plain html and style sheets to exactlly position the fields where they have to be on the form. In testing, it looks like it will work on many

Geographical redundancy?

2002-05-11 Thread Al Musella, DPM
I have to put together a proposal for a medical office management application which will be used in an ASP (application service provider - not the MS language:) model.. one of the requirements is that the application has to be hosted in such a way that a major disaster (natural or

RE: Geographical redundancy?

2002-05-12 Thread Al Musella, DPM
This actually looks like a great business opportunity for some of the ISPs on this list to work together on. I got private email from a bunch of people offering to handle the hosting.. but none of their websites actually mention something like geographic redundancy. It could be a new

RE: Ways of securing email?

2002-05-17 Thread Al Musella, DPM
This might not be applicable in your case, but a technique I use instead of emailing private information (I deal with medical information, where there are strict new rules coming out for how you handle it.. HUGE fines for the non-compliant!) is to allow doctors to log in to a website using

RE: Backups

2002-06-11 Thread Al Musella, DPM
Most of my database files are in SQL server, but I have a few left over that are in access tables. Every night I run a combination of batch files and automated tasks that: 1. copy all access files to a temp directory (the files can be copied from within a dos batch file for some reason,

Bugbear killer

2003-08-22 Thread Al Musella, DPM
Hi. I am trying to write a function to check POP mailboxes and delete all bugbear viruses.. it appears that cfpop with getHeaderOnly does not tell you the name of the attachment. Is there any other way to get the names of the attachments without downloading the message? Al a1webs.com

Re: Bugbear killer

2003-08-24 Thread Al Musella, DPM
Unfortunately no, I don't have access. This worm is getting to be a pain in the neck.. How is everyone else handling it? Al At 10:22 PM 8/23/2003, you wrote: Do you have physical access to the machine with the mail? If so, get the CFX_OdsMime tag from coolfusion.com. Do a CFDIRECTORY on the dir

Re: Web Based Mail Merge? (not email!)

2005-04-02 Thread Al Musella, DPM
I do this all of the time with straight HTML.. Use style sheets to format the pages nicely and to display the letterhead part, and just use cold fusion to insert the variables at the right place. Make sure they set the browser to not print a header or footer. I have a button on a page

RE: Web Based Mail Merge? (not email!)

2005-04-02 Thread Al Musella, DPM
? I'm still using CF 4.5.2...is what you're doing possible with that? I've created printable forms using CSS and CF variables, but only as single documents, not as multiple printouts from a mail merge... Rick -Original Message- From: Al Musella, DPM [mailto:[EMAIL PROTECTED] Sent

RE: Best price for CFMX 6.1 or 7

2005-04-09 Thread Al Musella, DPM
In the old days, Allaire used to always donate CF (and studio) to my nonprofit brain cancer support organization.. but macromedia no longer does. They did donate dreamweaver and Flash, but I am stuck on CF 5 :(. Al Musella, DPM President Musella Foundation For Brain Tumor Research

Re: Best price for CFMX 6.1 or 7

2005-04-09 Thread Al Musella, DPM
I tried Blue Dragon when it was first released and it didn't support a lot of the things I use.. but I will check again. Al At 10:13 AM 4/9/2005, you wrote: Is Blue Dragon an option? ~| Discover CFTicket - The leading

Re: Have A Client with A Specific Need. Read On to See If You're the Right CF Expert for the Job

2005-05-04 Thread Al Musella, DPM
Hate to say, but how about moving back to the old servers, to give you time to work on the new servers and figure out the problem? I would then re-format the drive on the new server, and install windows and cf again.. then run diagnostics on the new disks.. then test it for a few days to see

was Re: about blue dragon. bow: upgrading to mx

2003-09-07 Thread Al Musella, DPM
I am about to upgrade a cf 5 server to cfmx6.1. (running on windows server 2000 and IIS) I tested everything on my laptop, but am worried about surprises. I have a few webistes on the server, and IF there are problems, I need a way to back out to the current version quickly while

Re: Get the beta of MM Central (private)

2003-09-25 Thread Al Musella, DPM
Mike, Are you looking for ideas to show off the Central concept? A perfect example of it's use would be a medical office management system: Central could help organize all of the different modules needed.. for example: the doctor could use a handheld device with Central just displaying

email tip!

2004-02-06 Thread Al Musella, DPM
I just started doing something interesting and thought I would share it: A customer was complaining that he was missing some emails from his website recently, probably getting lost in a sea of thousands of virus emails... I always stored the information in a database as well as email it to the

Problem with CFFILE over network

2004-02-14 Thread Al Musella, DPM
Hi. My brain is fried... was working on this all night.I am not into networking.. A friend has a network set up using a windows 2000 domain controller to control the entire network, except for 1 stand alone computer that is not part of the domain.As I said - it is my friend's network. I have no

Re: SQL BAK Files

2004-02-16 Thread Al Musella, DPM
For this 1 time project, you could also just download the trial version of sql server http://www.microsoft.com/sql/ [Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Need sql help

2004-03-12 Thread Al Musella, DPM
My brain is fried... this should be easy: 3 tables: Contacts:name and contactID(one entry for each doctor) Trials: Has List of clinical trials.TrialID, DateUpdated(each trial can have multiple doctors, each doctor can have multiple trials) ContactDetails: ContactID, Trial ID(for many to many

RE: Need sql help

2004-03-13 Thread Al Musella, DPM
-Original Message- From: Al Musella, DPM [mailto:[EMAIL PROTECTED] Sent: Friday, March 12, 2004 3:09 PM To: CF-Talk Subject: Need sql help My brain is fried... this should be easy: 3 tables: Contacts:name and contactID(one entry for each doctor) Trials: Has List of clinical trials.TrialID

CF/Acobat multiple page forms

2004-12-14 Thread Al Musella, DPM
Hi. I want to create a .pdf that contains multiple pages with forms filled in with data from cf. I found how to create a pdf with a single form with filled in data using an .fdf file, but I can't find the syntax of the fdf file format (you have to pay to get the adobe documentation on

Re: time to cluster, I thinkL

2004-12-20 Thread Al Musella, DPM
Why do you want to cluster? If it is for reliability, then that is ok. But if you need speed, you may be best off just putting the IIS/CF on one computer and the MSSQL2K on the other computer, since you already have one license of each. The computers are cheaper than the licenses. If you do

Problem connecting to mail server after changing ip addresses

2004-01-25 Thread Al Musella, DPM
Hi. What a horrible weekend.. the ISP I co-locate my server at had to change the IP range that we use.. (they changed providers) I got everything working, except for some reason, I can't get cfmail to work. I am using cf 5.0.0.0 enterprise. It was working fantastic for years until the change

Re: Problem connecting to mail server after changing ip addresses

2004-01-25 Thread Al Musella, DPM
I have another clue! New emails go right through the system..It is only the old ones. (There are about 4,000 of them) that are stuck. I cleared out the coldfusion/mail/spool directory (I moved them to a temp folder) .. thentriggered an email from a feedback form, and it worked perfectly. I

RE: Problem connecting to mail server after changing ip addresses SOLVED

2004-01-26 Thread Al Musella, DPM
Thanks. I found a utility that does search and replace on a lot of files.. took about 5 minutes and everything went out. Just file this as another gotcha in case you ever have to change IP addresses! Al Either you can grep the files and replace the address of the smtp server [Todays Threads]

Re: SOT: secure area

2004-01-27 Thread Al Musella, DPM
It works ok for me with IE5 Could someone take a look at the following link and please give me any suggestions they might have? TIA https://www.seacrets.com/secure/reservation.cfm [Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Lookup senators and representatives

2004-05-28 Thread Al Musella, DPM
I have to program a letter writing campaign to senators and representatives.What is the best way to look up the names and addresses of the senators and representatives?Is there a web service that can help? There is a way to look it up at

Re: Network problem, session aborted due to internal error..

2004-06-01 Thread Al Musella, DPM
The obvious thing is to make sure you can access the cobol server from the cfmx server.Log into the cfmxserver with the credentials cfmx runs under then see if you can navigate to the cobol server. Maybe somebody changed permissions or installed a service pack or firewall that screwed things

Re: synching local database with web

2004-10-28 Thread Al Musella, DPM
You could add a flag for transactions that are not uploaded to the server yet. When they add a new transaction, the flag is set. When they connect to the server, run a script that finds the ones with the flag set and upload them, and reset the flag At 03:00 PM 10/28/2004, you wrote: I've

Re: Migrating to a new server - CF Considerations?

2005-02-15 Thread Al Musella, DPM
I did that a few times. One problem is keeping the databases in sync.. if you run them both overlapping, some data will be entered into both servers- how do you reconcile that? What I did is set the TTL value in the dns of the old web server to a low value, so when the change is made,

Re: CF generated email.

2005-03-01 Thread Al Musella, DPM
One other thing to speed up the process... temporarily turn off your virus and/or spam filters on both the cf server and mail server while sending these. Since you don't really want to turn it off on the exchange server, set up the IIS SMTP server on the cf server and use that. -- No

Re: OT - Security Of Sensitive Data

2005-03-04 Thread Al Musella, DPM
Providing lists of id numbers that they have to look up on paper is over doing it..but I wouldn't post protected private health information on a shared server. There is no way to secure it. The techs at the ISP have a password and physical access to the computer and can browse all of your

Re: Spam to my CF-Talk address - easy fix

2007-07-05 Thread Al Musella, DPM
If you want to keep this email for houseoffusion mail only, just set a filter or whitelist/blacklist to delete mail to that email address except if it comes from 64.118.74.249 . ~| Create robust enterprise, web RIAs. Upgrade

Stolen server.

2007-07-07 Thread Al Musella, DPM
One of my clients is a law firm.. on the 4th of July, someone broke into their office and stole the server as well as all of their computers. Luckily they had a good backup plan, so they didn't lose any data from the server. The problem is that a lot of private information like names, social

Re: Stolen server.

2007-07-07 Thread Al Musella, DPM
I don't suppose they used Vista with Bitlocking on the HDD? That would make any info on the HDD virtually useless. They were still on windows2000 server. That would have been smart. I will recommend it for the new system.. Boy was this aggravating.

RE: Stolen server.

2007-07-08 Thread Al Musella, DPM
This might be a stupid question.. but if the server encrypts the hard drive, would every user have to enter the password whenver they need access? Or just the first user after the server boots? How about for a web server.. when it reboots will it refuse to work until someone types in the

Re: Breaking down mass email into chunks to beat page timeout.

2007-09-26 Thread Al Musella, DPM
I handle it the same way - with a little twist. The user starts the process going. The actual emails are sent out by a scheduled task which runs every 5 minutes - sending out the next xxx messages waiting to be sent.. the user then is redirected to a status page which shows how many of the

CFMAIL quesitons..

2007-10-31 Thread Al Musella, DPM
Hi I am on CF7, with multiple websites on multiple IP addresses. When I send mail using cfmail, I want the IP address in the headers to say it came from the IP address of each website. For example. Website 1 is at ...100 Website 2 is at ...101 The headers from mail

Re: CFMAIL quesitons..

2007-11-01 Thread Al Musella, DPM
No - that part isn't the problem.. it is one step lower.. the bottom header is the cold fusion server.. not the mail server.. here are the headers: Received: from mail.mymailserver.com (mail.mymailserver.com [xx.241.156.98]) by rly-mf08.mx.aol.com (v119.12) with ESMTP id

Re: CFMAIL quesitons..

2007-11-02 Thread Al Musella, DPM
The problem is that when you do a reverse dns lookup on the email message, it doesn't come back as the domain name that the mail was sent from. I send newsletters from a few websites, and they have been getting rejected by a lot of major ISPs. My spf is set to all mail from the correct ip

Re: CFMAIL quesitons..

2007-11-02 Thread Al Musella, DPM
, .108 is the domain of my web site, .98 is my mail server) It doesn't sound right to me. They did mention I could pay to make sure my email gets through. Sounds like they are randomly blocking email to extort me? Does anyone else get seemingly random blacklisting? Al Musella, DPM wrote

Re: CFMAIL quesitons..

2007-11-03 Thread Al Musella, DPM
Thanks. I will try changing the mailer from coldfusion to Eudora. (That is what I use and my mail always seems to go through!). I am thinking it is an extortion attempt. They want to force us into paying for email. Jochem van Dieten wrote: Can you send an email directly to me from

Re: IE7 blocking CF Administrator 'browse' java applet

2007-11-26 Thread Al Musella, DPM
First make sure you have java installed.. go to java.com and install the latest version.. If that doesn't work, go into IE's tool menu, then internet options, then advanced and allow the java stuff! At 05:03 PM 11/26/2007, you wrote: How can I get IE7 to stop protecting me from my CF

Re: Reading NMEA-183 Messages off Com Port w CF?

2007-12-16 Thread Al Musella, DPM
If you aren't familiar with Java, You may want to use a different tool.. you can create a simple windows program in something like powerbaisc (powerbasic.com) that can easily read a com port and process the data and save the lat/lon to a database. It is really simple syntax. Then your cold

Re: Question about relative and root links

2006-04-27 Thread Al Musella, DPM
I have the same problem... I handle it by setting a path variable in the application.cfm.. if the SERVER_NAME=localhost then set path to '/whmedia/' if not, set it to '/' then whereever this problem pops up, use: #path#image.gif Al At 02:30 PM 4/27/2006, Aaron Roberson wrote: You

Re: CF Administrator Files Periodically Corrupted

2006-04-29 Thread Al Musella, DPM
Is it possible that you are mixing files from different versions of cf? At 10:19 PM 4/28/2006, you wrote: On 4/28/06, brian wood [EMAIL PROTECTED] wrote: Thanks for the help. Sorry I forgot to mention if the files differ. It seems that they do: -rw-r--r--1 01157894 mkpasswd

CFMAIL problem? How to debug?

2006-06-08 Thread Al Musella, DPM
I am sending a daily newsletter to 7000 people. I used yahoogroups to send them for years , but they changed the format so now I am using cf to send the emails.. I switched over to using cf last week, and had a lot of complaints. I resolved all except for 1 who is still not getting it (I told

Re: CFMAIL problem? How to debug? SOLVED

2006-06-09 Thread Al Musella, DPM
He checked his spam filters and called his ISP - they are not filtering it. The ISP was wrong.. they were filtering it out into a black hole. We bumped it up to a higher level of support - because this was an important email - and if he wasn't getting this, he might be missing other stuff

RE: CFMX own web server

2006-08-28 Thread Al Musella, DPM
http://127.0.0.1:8500/cfide/administrator To view the website: http://your_IP_address_or_DNS_name:8500/ to go to administrator: http://your_IP_address_or_DNS_name:8500/cfide/administrator ~| Introducing the Fusion

RE: mass emailing from CF

2006-09-03 Thread Al Musella, DPM
I do it with a scheduled task that runs every 5 minutes around the clock. It checks for newsletters that have to be sent and if there are some to be sent, it sends the next 500 and marks those as sent. works nicely so far... I have an status page that refreshes itself every few minutes

RE: mass emailing from CF

2006-09-04 Thread Al Musella, DPM
I meant an elegant way of sorting a list of email addresses so that all mail to AOL (and att, yahoo, gmail) is evenly distributed throughout the batch - the reason I do this is not because of page timeouts.. but because when I send too many messages to AOL, Yahoo and ATT, they go into a

Strange security problem with googlebot

2006-10-09 Thread Al Musella, DPM
I don't know how this could possibly happen... on 2 of my websites, someone hacked into the admin areas and changed hundreds of things by clicking links. I log every action taken, along with the ip address of who did it and traced back the ip to googlebot. I was using IIS basic

RE: Strange security problem with googlebot

2006-10-10 Thread Al Musella, DPM
You hit it.. it was the web accelerator. I now know that I should not let a simple clicked link change anything. Both of these sites were written in cold fusion version 2 and 3 when I didn't know better:) WAY too many pages to go back and change them now. I thought since it was password

RE: Strange security problem with googlebot

2006-10-10 Thread Al Musella, DPM
Actually, in my defense:) the web accelerator is not supposed to follow a link that has a query parameter... and it worked correctly for a long time.. apparently a recent update to it introduced a bug where it IS following links with query parameters. I reported it to google. It

Re: SERVER EMERGENCY: updated win2k3 with patches

2006-07-13 Thread Al Musella, DPM
I had the strangest thing happen... My server was working fine with no crashes for over 2 years..no reboots except for patches.. after the last round of updates, the server slowed way down, and occasionally got so slow it wouldn't serve any pages. My monitoring software reported it was down

Re: OT - Nice site I will recommend you to all my friends.

2006-08-11 Thread Al Musella, DPM
I implemented something like that a few weeks ago ( checking time to post and also the referrer) and it does help a lot... most of the bots somehow set the referrer to be the action page.. but some set it to the original form page also.. but the time never looks right.. usually either 0

Re: A timeout occurred while attempting to lock x

2006-08-16 Thread Al Musella, DPM
I had the same problem once... I know you aren't supposed to do this, but I had to make a fast change to a database table and opened up the live sql table in enterprise manager.. I made the change fast, then got distracted and left the table open.. I got a bunch of complains about the entire

RE: Capture Alternatives

2006-11-14 Thread Al Musella, DPM
One thing that I have done that helped tremendously: I run a brain cancer web site. The feedback form would usually get about 50 real responses a day - and about 500 spams a day. One problem I have is that there is no tolerance for false negatives - these are very important messages. I

Using google as a video server?

2007-02-02 Thread Al Musella, DPM
I posted an interesting video on my website and it got so popular that it saturated my server's internet connection... so I turned to google and posted the video on google - for free, then embeded it in my webpage.. works great! My question - is there a catch? any reason NOT to use google

Re: Fusebox session wackiness in WWW.domainname.com and domainname.com

2007-02-14 Thread Al Musella, DPM
If the problem isn't solved, a band-aid fix might be to just redirect domainname.com/ to www.domainname.com/in your application.cfm Sessions work fine when someone is on http://www.domainname.com. However, the Flash developer added a link to an ad on the home page that uses

Re: A lesson in caching and performance

2007-05-24 Thread Al Musella, DPM
When my rss feed became too much of a resource hog (generating it on every request), I just made my blog software generate a new static rss page every time I added a blog entry. A few days ago, I decided to put the last 3 blog entries on those pages, using the rss CFC just like I do on my

Re: Secure login system

2008-02-05 Thread Al Musella, DPM
the only other thing I would add is a counter of bad log in attempts. if 5 attempts failed, I would lock out the account for a minute. If more than 20 attempts, I lock it out until I reset it. I have one very important page set up so that the user has to log in with the same set of credentials

RE: DB Insert error in SQL Server

2008-02-12 Thread Al Musella, DPM
You have 13 items in the field names and are trying to insert 14 values. you probably have an extra comma someplace At 01:39 PM 2/12/2008, Adkins, Randy wrote: Is WEIGHT specified as a numeric field or varchar? If varchar, you need the '' relating to null. the same for ShipBase. Other than

RE: Hosting Problems

2008-03-10 Thread Al Musella, DPM
The funniest ones are the people who want to have shared hosting for less than $10 a month with multiple domains - then they complain the servers are overloaded:) What I was addressed was the nearly continuous arguments that run like this: Poster 1: Hey guys, what's a good host? Poster 2: My

Re: (ot) URL Hack Attempt Leaves Me Scractching My Head...

2008-07-23 Thread Al Musella, DPM
One of my websites got hit.. I always use cfqueryparam - at least for the last few years, but some old code (this website started with version 1 of CF) was still hanging around that was unprotected. I used that scanning tool and it found about 20 unprotected querries out of about 20,000...

Re: (ot) URL Hack Attempt Leaves Me Scractching My Head...

2008-07-23 Thread Al Musella, DPM
That may help with this particular attack, but I already have seen 2 versions of it today.. Both happened to have the EXEC( but there are variations that use other key words. The correct way (which unfortunately I found out through failure:) is: 1. Run a scanner like:

RE: (ot) URL Hack Attempt Leaves Me Scractching My Head...

2008-07-23 Thread Al Musella, DPM
My thinking is: The way it appears, a zombie will hit about 2 -12 pages on my web server - over the course of a few seconds - then leave me alone.. On the first page they hit, if I ban them, then the next 1 to 11 tries will not succeed even if they happen to find a vulnerable file

RE: (ot) URL Hack Attempt Leaves Me Scractching My Head... To Ben Forta

2008-07-25 Thread Al Musella, DPM
Ben, Seeing as how this type of sql injection attack is succeeding so much (even my favorite fishing website has been down for days due to it (it is a .cfm site))... how about changing cfquery so that by default, only ONE sql statment can be sent. Let us override that with a parameter in

RE: (ot) URL Hack Attempt Leaves Me Scractching My Head... To Ben Forta

2008-07-25 Thread Al Musella, DPM
OK.. You are right.. drop my request.. but I would request 3 other enhancements to dreamweaver to make these changes easier: 1. Put the sql queryparam on the main CF toolbar.. 2. When you right click the file name in the Files area you can select PUT.. I would like to add that functionality

Re: (ot) URL Hack Attempt Leaves Me Scractching My Head...

2008-07-25 Thread Al Musella, DPM
I won't mention names but a few popular websites I use have been hit.. one was down for 3 days now. Recently I set up an annonymous ftp server.. I needed a few people to send me files and I thought that would be the easiest way. the url was private - not published anywhere.. 2 days later

Re: (ot) URL Hack Attempt Leaves Me Scractching My Head...

2008-07-25 Thread Al Musella, DPM
I set up a scheduled task to check my database every 15 minutes. It looks for my entry in the users table, and compares my email address and website address with what is in the database. IF it differs, I get an email. I did the same thing for 10 different tables. If I do find any

Was) URL Hack Attempt - now DNS attack..

2008-07-26 Thread Al Musella, DPM
And on top of that there is a story since Monday about DNS that is much scarier and much closer to home to most readers. I am surprised we are not hearing about this on the list.. just in case you haven't been getting the MS alerts or other news sources telling you about it: there is a new

Re: Switching to new Host question?

2008-07-27 Thread Al Musella, DPM
I would not use both database at the same time. Just forward people from the old website to the new one. If you have a static ip address on the new one, it is easy. Just do a meta refresh on the old site to bring you to the new IP address.. you can delay it and post a message about the move..

RE: [ot] - Payment Gateways?

2008-07-28 Thread Al Musella, DPM
I use google checkout for a non-profit organization - they do not charge any processing fees for nonprofits - at least until the end of 2009... they have been excellent so far. At 09:10 PM 7/27/2008, William Seiter wrote: I get the feeling that Paypal is a bad choice. I have had some runins

Re: can't enable debug output in coldfusion 8

2008-07-28 Thread Al Musella, DPM
I am still on an older version of cf, but does cf 8 have a restrict debug output to specified ips? Check that your ip address is specified. Maybe there is something in the CF code that is suppressing the debug output...? On Mon, Jul 28, 2008 at 2:54 PM, Alex I [EMAIL PROTECTED] wrote:

Re: CF 8 verity collections disappearing

2008-07-30 Thread Al Musella, DPM
I have the same problem on cf 7. It happens about once a month.. on a site that I volunteer for - just hadn't had the time to debug the problem.. I have to manually delete the directory, then recreate the collection, then repopulate it.

Re: CF 8 verity collections disappearing

2008-08-04 Thread Al Musella, DPM
It happened to me again.. a verity collection disappeared.. Any ideas on how to approach finding the cause? On my server, version 7,0,1,116466 . there are 12 verity collections. 3 are flaky.. they all belong to the same website and randomly disappear for no apparent reason. The other 9

RE: HELP! SQL Injection Attack!

2008-08-07 Thread Al Musella, DPM
Your database contains all its object names in metadata tables, which can be queried directly. It was mentioned last week, but just to re-iterate: You should set the permissions on the system table so that you can not read or write to the system tables. There is no need for it, and by

RE: HELP! SQL Injection Attack!

2008-08-07 Thread Al Musella, DPM
I meant to say: Set the deny permission on the system table to the user that you use to access the database from cf At 07:27 PM 8/7/2008, you wrote: You should set the permissions on the system table so that you can not read or write to the system tables. There

Re: SQL injection attack on House of Fusion

2008-08-09 Thread Al Musella, DPM
Here are my top 50: Note that the top 1 is in the same subnet as your top 1. I had 134,993 attempts that I caught.. IP (times) 203.160.1.52 (705) 203.162.3.160 (373) 203.160.1.76 (325) 61.164.132.230 (325) 59.15.212.125 (258) 210.112.177.244 (252) 70.189.143.59 (219) 221.253.217.138 (204)

RE: SQL injection attack - FBI

2008-08-09 Thread Al Musella, DPM
times. Users are starting to complain.. it is going on for too long. Now look at how many of those are from Asia Pacific Network Info Centre ..:.:.:.:.:.:.:.:.:.:. Bobby Hartsfield http://acoderslife.com http://cf4em.com -Original Message- From: Al Musella, DPM [mailto:[EMAIL PROTECTED

RE: SQL injection attack - FBI

2008-08-09 Thread Al Musella, DPM
I heard back from the FBI.. a live agent, not an automated response like I was expecting:) They don't seem to care, but suggested that I report it to CERT at https://www.cert.org/reporting/incident_form.txt Perhaps if a few of us reported it to CERT, they will investigate. By the way - I hit

<    1   2   3   4   >