<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Adobe security hotfix for ColdFusion 7.0.2 / 8.0.0 / 8.0.1</title>
	<atom:link href="http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/feed/" rel="self" type="application/rss+xml" />
	<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/</link>
	<description>Jochem's tech exploits</description>
	<pubDate>Tue, 09 Jun 2026 01:58:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: &#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; Shared hosting security wishlist</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-156</link>
		<dc:creator>&#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; Shared hosting security wishlist</dc:creator>
		<pubDate>Tue, 06 Jan 2009 20:26:27 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-156</guid>
		<description>[...] I have posted a number of posts on the state of shared hosting security. Unfortunately we have to conclude [...]</description>
		<content:encoded><![CDATA[<p>[...] I have posted a number of posts on the state of shared hosting security. Unfortunately we have to conclude [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-75</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Sun, 30 Nov 2008 20:11:06 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-75</guid>
		<description>I'll be publishing a number of articles about shared hosting security shortly. Those articles should provide plenty of examples on how to exploit shared ColdFusion hosting from the inside. I just have to finish the editing and clean up the example code.</description>
		<content:encoded><![CDATA[<p>I&#8217;ll be publishing a number of articles about shared hosting security shortly. Those articles should provide plenty of examples on how to exploit shared ColdFusion hosting from the inside. I just have to finish the editing and clean up the example code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastiaan</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-74</link>
		<dc:creator>Sebastiaan</dc:creator>
		<pubDate>Thu, 27 Nov 2008 13:55:25 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-74</guid>
		<description>So what was your issue with Webstekker? Maybe you can enlighten me off-site (privately via e-mail). I'm VERY happy with Webstekker at the moment.</description>
		<content:encoded><![CDATA[<p>So what was your issue with Webstekker? Maybe you can enlighten me off-site (privately via e-mail). I&#8217;m VERY happy with Webstekker at the moment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-70</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Sun, 16 Nov 2008 22:09:34 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-70</guid>
		<description>I find it very hard to believe that IIS suddenly asking for credentials can be related to the hotfix. Just think about how ColdFusion is really an application server that stands alone and runs in its own memory space. Only a very small part is loaded into the webserver, the webserver connector in the wsconfig diectory. The only way IIS is ever going to give a credentials error is if there is a credential problem in that webserver connector part. The hotfix does not alter the connector so it is not the cause of the IIS credentials errors.

Apart from that I have recently helped somebody move away from Webstekker because of the security configuration of their servers. This hotfix is really the least of their problems.</description>
		<content:encoded><![CDATA[<p>I find it very hard to believe that IIS suddenly asking for credentials can be related to the hotfix. Just think about how ColdFusion is really an application server that stands alone and runs in its own memory space. Only a very small part is loaded into the webserver, the webserver connector in the wsconfig diectory. The only way IIS is ever going to give a credentials error is if there is a credential problem in that webserver connector part. The hotfix does not alter the connector so it is not the cause of the IIS credentials errors.</p>
<p>Apart from that I have recently helped somebody move away from Webstekker because of the security configuration of their servers. This hotfix is really the least of their problems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastiaan</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-69</link>
		<dc:creator>Sebastiaan</dc:creator>
		<pubDate>Sun, 16 Nov 2008 18:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-69</guid>
		<description>Hi Jochem,

I got our hostingprovider Webstekker to install this hotfix on their webservers (shared hosting) and it jammed up all the CF 8.0.1 installations. Any ideas to why? It suddenly asked for credentials in IIS. Not really related, I know, but CF8 with the hotfix installed all crashed regularly.</description>
		<content:encoded><![CDATA[<p>Hi Jochem,</p>
<p>I got our hostingprovider Webstekker to install this hotfix on their webservers (shared hosting) and it jammed up all the CF 8.0.1 installations. Any ideas to why? It suddenly asked for credentials in IIS. Not really related, I know, but CF8 with the hotfix installed all crashed regularly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh Adams</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-65</link>
		<dc:creator>Josh Adams</dc:creator>
		<pubDate>Tue, 11 Nov 2008 21:46:04 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-65</guid>
		<description>Thanks for your help in identifying and resolving this issue, Jochem!</description>
		<content:encoded><![CDATA[<p>Thanks for your help in identifying and resolving this issue, Jochem!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Quackenbush</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-64</link>
		<dc:creator>Matt Quackenbush</dc:creator>
		<pubDate>Sat, 08 Nov 2008 19:10:33 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-64</guid>
		<description>@ Jochem- Thanks.  That is exactly what I would expect.</description>
		<content:encoded><![CDATA[<p>@ Jochem- Thanks.  That is exactly what I would expect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-63</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Fri, 07 Nov 2008 17:40:38 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-63</guid>
		<description>All our SQL Server datasource connections work correctly without passwords in every query. That is on CF 8.0.1 Enterprise in multiserver configuration though.</description>
		<content:encoded><![CDATA[<p>All our SQL Server datasource connections work correctly without passwords in every query. That is on CF 8.0.1 Enterprise in multiserver configuration though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Quackenbush</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-62</link>
		<dc:creator>Matt Quackenbush</dc:creator>
		<pubDate>Fri, 07 Nov 2008 17:16:50 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-62</guid>
		<description>Jochem,

A user on the Sava forums indicated that installing this patch caused all of his SQL Server connections to now require credentials to be passed with the  tag.  I can't fathom that being the intended behavior.  I would be interested in your thoughts.

http://www.gosava.com/sava/forum/messages.cfm?threadid=74390482-F355-D392-F9B164567059F345&#38;page=1

Thanks.  :-)</description>
		<content:encoded><![CDATA[<p>Jochem,</p>
<p>A user on the Sava forums indicated that installing this patch caused all of his SQL Server connections to now require credentials to be passed with the  tag.  I can&#8217;t fathom that being the intended behavior.  I would be interested in your thoughts.</p>
<p><a href="http://www.gosava.com/sava/forum/messages.cfm?threadid=74390482-F355-D392-F9B164567059F345&amp;page=1" rel="nofollow">http://www.gosava.com/sava/forum/messages.cfm?threadid=74390482-F355-D392-F9B164567059F345&amp;page=1</a></p>
<p>Thanks.  <img src='http://jochem.vandieten.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/comment-page-1/#comment-61</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Fri, 07 Nov 2008 10:20:22 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/11/06/adobe-security-hotfix-for-coldfusion-702-800-801/#comment-61</guid>
		<description>Considering the nature of the Sandbox Security issues I have so far personally reported to Adobe I am leaning towards a lack of prying eyes. For the issue described in &lt;a href="http://www.adobe.com/devnet/security/security_zone/mpsb01-11.html" rel="nofollow"&gt;MPSB01-11&lt;/a&gt; the engineers told me I was probably the only one in the world using the combination of features that caused the issue.</description>
		<content:encoded><![CDATA[<p>Considering the nature of the Sandbox Security issues I have so far personally reported to Adobe I am leaning towards a lack of prying eyes. For the issue described in <a href="http://www.adobe.com/devnet/security/security_zone/mpsb01-11.html" rel="nofollow">MPSB01-11</a> the engineers told me I was probably the only one in the world using the combination of features that caused the issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
