Archive for January 23rd, 2008
Securing ColdFusion (tips)
I’ve started to write a document for OWASP about ColdFusion security which I hope will be included on the site when I finish it.
Any feedback is more than welcome, if you’d like to see anything included about ColdFusion Security, let me know and I’ll do my best to include it.
Some of the items covered are:
- SQL Injection
- Database Logins
- Logging
- XSS (Cross Site Scripting)
- Cookie Hijacking
- Proper Error Handling
- Input Validation
- Securing Protected Areas
- Forms being submitted outside of your domain
- Automated data mining
The document about ColdFusion security can be downloaded here. Please note that the document is still a work in progress.
This document is sponsored by www.clickfind.com.au
Add comment January 23, 2008