<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: ColdFusion Sandboxing and cfreport</title>
	<atom:link href="http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/feed/" rel="self" type="application/rss+xml" />
	<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/</link>
	<description>Jochem's tech exploits</description>
	<pubDate>Tue, 09 Jun 2026 04:02:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Elias</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-258</link>
		<dc:creator>Elias</dc:creator>
		<pubDate>Wed, 13 May 2009 17:58:11 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-258</guid>
		<description>Hey, finally i could fix it.

For some reason the folder \tmpCache\CFFileServlet\_cfreport was not empty in development (850 mg!!!), but in production it was.

I erased the folder and i creates the folder again, with this, cfreport works again.</description>
		<content:encoded><![CDATA[<p>Hey, finally i could fix it.</p>
<p>For some reason the folder \tmpCache\CFFileServlet\_cfreport was not empty in development (850 mg!!!), but in production it was.</p>
<p>I erased the folder and i creates the folder again, with this, cfreport works again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elias</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-257</link>
		<dc:creator>Elias</dc:creator>
		<pubDate>Tue, 12 May 2009 21:50:46 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-257</guid>
		<description>I have to servers, development and production, all reports in production are ok, but in development any report work fine.

This error happened suddenly, I do not know why.

It forgot it, my cf version is the 8.0.1

thks!!!</description>
		<content:encoded><![CDATA[<p>I have to servers, development and production, all reports in production are ok, but in development any report work fine.</p>
<p>This error happened suddenly, I do not know why.</p>
<p>It forgot it, my cf version is the 8.0.1</p>
<p>thks!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-254</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Tue, 12 May 2009 21:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-254</guid>
		<description>First try your report on another server with the same patchlevel. Then try clearing out the cfclasses folder.</description>
		<content:encoded><![CDATA[<p>First try your report on another server with the same patchlevel. Then try clearing out the cfclasses folder.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elias</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-253</link>
		<dc:creator>Elias</dc:creator>
		<pubDate>Tue, 12 May 2009 20:32:03 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-253</guid>
		<description>and when " Enable ColdFusion Sandbox Security " is not checked,  but the error is the same, what can i do??????????? please......</description>
		<content:encoded><![CDATA[<p>and when &#8221; Enable ColdFusion Sandbox Security &#8221; is not checked,  but the error is the same, what can i do??????????? please&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Holmes</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-182</link>
		<dc:creator>James Holmes</dc:creator>
		<pubDate>Tue, 20 Jan 2009 14:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-182</guid>
		<description>I just discovered that the cffeed tag can have issues (at least on CF8.01 patched to current levels as of this post) unless {cfroot}/WEB-INF/cfusion/lib is permitted in the sandbox.

http://www.houseoffusion.com/groups/cf-talk/thread.cfm/threadid:58123

BTW, anyone still getting errors after adding the sandbox rules should restart the server - classes created with the old sandbox rules are cached and may not be cleared until you restart.</description>
		<content:encoded><![CDATA[<p>I just discovered that the cffeed tag can have issues (at least on CF8.01 patched to current levels as of this post) unless {cfroot}/WEB-INF/cfusion/lib is permitted in the sandbox.</p>
<p><a href="http://www.houseoffusion.com/groups/cf-talk/thread.cfm/threadid:58123" rel="nofollow">http://www.houseoffusion.com/groups/cf-talk/thread.cfm/threadid:58123</a></p>
<p>BTW, anyone still getting errors after adding the sandbox rules should restart the server - classes created with the old sandbox rules are cached and may not be cleared until you restart.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-132</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Wed, 17 Dec 2008 16:13:44 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-132</guid>
		<description>If you want to know how your sandbox is configured just try the following code to read the neo-security.xml file:

&#60;!--- read the security configuration ---&#62;
&#60;cffile action="read" file="#server.coldfusion.rootdir#/lib/neo-security.xml" variable="fileContent" /&#62;
&#60;!--- output the security configuration ---&#62;
&#60;cfoutput&#62;#HTMLCodeFormat(fileContent)#&#60;/cfoutput&#62;</description>
		<content:encoded><![CDATA[<p>If you want to know how your sandbox is configured just try the following code to read the neo-security.xml file:</p>
<p>&lt;!&#8212; read the security configuration &#8212;&gt;<br />
&lt;cffile action=&#8221;read&#8221; file=&#8221;#server.coldfusion.rootdir#/lib/neo-security.xml&#8221; variable=&#8221;fileContent&#8221; /&gt;<br />
&lt;!&#8212; output the security configuration &#8212;&gt;<br />
&lt;cfoutput&gt;#HTMLCodeFormat(fileContent)#&lt;/cfoutput&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastiaan</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-131</link>
		<dc:creator>Sebastiaan</dc:creator>
		<pubDate>Wed, 17 Dec 2008 10:49:51 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-131</guid>
		<description>Hi Jochem,

at our servers we can use CFIMAGE en CFFILE upload no problem within our shared sandbox.

Does this mean that the sandbox is NOT limited?</description>
		<content:encoded><![CDATA[<p>Hi Jochem,</p>
<p>at our servers we can use CFIMAGE en CFFILE upload no problem within our shared sandbox.</p>
<p>Does this mean that the sandbox is NOT limited?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; ColdFusion shared hosting security and internals</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-115</link>
		<dc:creator>&#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; ColdFusion shared hosting security and internals</dc:creator>
		<pubDate>Mon, 15 Dec 2008 12:44:11 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-115</guid>
		<description>[...] we need to grant read and execute permissions on that directory to every Sandbox (you can adapt the script I posted before for that). I just ran into this this weekend when I updated my dump template to show interface [...]</description>
		<content:encoded><![CDATA[<p>[...] we need to grant read and execute permissions on that directory to every Sandbox (you can adapt the script I posted before for that). I just ran into this this weekend when I updated my dump template to show interface [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; CF shared hosting security: filesystem access and sandbox security</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-83</link>
		<dc:creator>&#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; CF shared hosting security: filesystem access and sandbox security</dc:creator>
		<pubDate>Tue, 02 Dec 2008 19:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-83</guid>
		<description>[...] To get real security against this reading of directories we need to enable Sandbox Security. Sandbox Security allows us to define a directory on the filesystem as a Sandbox and subject every request that starts from that Sandbox to a set of constraints. These constraints can include which tags are allowed, i.e. forbid cfregistry outright, or which resources can be accessed. Typically each Sandbox is defined at the root of a customers FTP and / or WWW directory and then allows for access of only some directories and datasources. Setting up the allowed resources and tags in a Sandbox can occasionally be a bit counterintuitive, for instance to allow a file to be used in a cfinclude it needs execute permissions and several extra directories need to be accessible for some tags. [...]</description>
		<content:encoded><![CDATA[<p>[...] To get real security against this reading of directories we need to enable Sandbox Security. Sandbox Security allows us to define a directory on the filesystem as a Sandbox and subject every request that starts from that Sandbox to a set of constraints. These constraints can include which tags are allowed, i.e. forbid cfregistry outright, or which resources can be accessed. Typically each Sandbox is defined at the root of a customers FTP and / or WWW directory and then allows for access of only some directories and datasources. Setting up the allowed resources and tags in a Sandbox can occasionally be a bit counterintuitive, for instance to allow a file to be used in a cfinclude it needs execute permissions and several extra directories need to be accessible for some tags. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/comment-page-1/#comment-57</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Thu, 30 Oct 2008 16:30:57 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/09/12/coldfusion-sandboxing-and-cfreport/#comment-57</guid>
		<description>I haven't seen the problem since changing the Sandbox settings.</description>
		<content:encoded><![CDATA[<p>I haven&#8217;t seen the problem since changing the Sandbox settings.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
