|
||||||
| JavaScript and CSS Extensible Markup Language, Java Script, and CSS questions here. |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Display Modes |
|
|||
|
Hello again,
You got to be kidding me right? I am going to assume your not. By spoofing, you mean taking an EXE file and giving it a JPG extension right? So what happens when you do something like the following when a file is spoofed? <img src="spoofedFile.JPG"> My first thought it would show a box with an X through it. That is at least what happens when a JPG can not be found. My biggest question is how do you tell a file is spoofed upon uploading it? How is that prevented? The more I learn about securing a website, the more I hate hackers. The worst thing is I bet the majority of programmers do not even take measures to secure a website like this. Thanks again for any information you can provide me with. If there was a security class in my area, I would definately take that. For now, this is the best I got so I really appreciate it. Sincerely, Travis Walters admin@codebuyers.com
__________________
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. providing To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. for To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. Last edited by twalters84; 01-15-2008 at 12:48 PM. |
|
|||||
|
So you are saying that we should not even accept JPG/GIF files to be uploaded?
__________________
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. | To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. | To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. | To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. | To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. |
|
|||
|
Hey there,
I found another good article here: Application Security with Coldfusion The part that I found very interesting and is related to our latest discussion is the following: Quote:
However, I wonder if I created a seperate directory just for uploads if that would solve the problem. I am wondering maybe if there is a way to make everything non-executable in that folder some how? Sincerely, Travis Walters
__________________
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. providing To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. for To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. |
|
|||
|
Hello again,
For other coldfusion developers, I found a few things that are quite useful. This feature is undocumented in coldfusion 7 but it works: Script Protection Attribute in Cfapplication It does not protect against all XSS attacks, but its better than nothing. The Adobe Coldfusion Security Center also has some nice information: Adobe Coldfusion Security Center Hope this helps other developers. Sincerely, Travis Walters
__________________
To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. providing To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. for To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts. |
| Sponsored Links |
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Memory leak prevention methodogies | c___newbie | C and C++ | 2 | 11-18-2007 10:29 AM |
| Dynamic Email insertion in HTML | Gibster | HTML Programming | 5 | 07-17-2007 04:22 PM |
| Xav | ........ | 1276.19 |
| MeTh0Dz|Reb0rn | ........ | 1048.58 |
| marwex89 | ........ | 869.98 |
| morefood2001 | ........ | 868.04 |
| John | ........ | 865.15 |
| WingedPanther | ........ | 761.06 |
| Brandon W | ........ | 684.87 |
| chili5 | ........ | 294.12 |
| Steve.L | ........ | 216.18 |
| dargueta | ........ | 192.86 |
Goal: 100,000 Posts
Complete: 81%