<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: ColdFusion shared hosting and security</title>
	<atom:link href="http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/</link>
	<description>Jochem's tech exploits</description>
	<pubDate>Thu, 11 Mar 2010 09:59:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sebastiaan</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-98</link>
		<dc:creator>Sebastiaan</dc:creator>
		<pubDate>Wed, 10 Dec 2008 11:11:27 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-98</guid>
		<description>Jochem, could you convey the e-mail address of Ron to me, as it isn't showing up on your blog ;-) Thanx!</description>
		<content:encoded><![CDATA[<p>Jochem, could you convey the e-mail address of Ron to me, as it isn&#8217;t showing up on your blog <img src='http://jochem.vandieten.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> Thanx!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; CF shared hosting security: Java, CFEXECUTE, COM, .NET and Java again</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-96</link>
		<dc:creator>&#8220;it could be bunnies&#8221; &#187; Blog Archive &#187; CF shared hosting security: Java, CFEXECUTE, COM, .NET and Java again</dc:creator>
		<pubDate>Tue, 09 Dec 2008 21:37:22 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-96</guid>
		<description>[...] the first part we have set the stage for this series: the goal is to protect one shared hosting customer from an [...]</description>
		<content:encoded><![CDATA[<p>[...] the first part we have set the stage for this series: the goal is to protect one shared hosting customer from an [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-92</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Wed, 03 Dec 2008 16:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-92</guid>
		<description>Sebastiaan: my next posts will include some code samples that you can run against any environment you want.

Ron: I fixed your code comments.</description>
		<content:encoded><![CDATA[<p>Sebastiaan: my next posts will include some code samples that you can run against any environment you want.</p>
<p>Ron: I fixed your code comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-89</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Wed, 03 Dec 2008 13:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-89</guid>
		<description>Sebastiaan, I most certainly know that the CF environments of webstekker are anything but secure. I can easily list which other CF applications are on the same server and can then find out what their directories on the server are and simply alter their site.

Imagine what this would do ;-)

&#60;cffile action="write" file="e:\clientdir\wwwroot\Application.cfm" output="&#60;cflocation url='some_bad_site' /&#62;" /&#62;

And I can assure you it works. Email me if you want to know more.</description>
		<content:encoded><![CDATA[<p>Sebastiaan, I most certainly know that the CF environments of webstekker are anything but secure. I can easily list which other CF applications are on the same server and can then find out what their directories on the server are and simply alter their site.</p>
<p>Imagine what this would do <img src='http://jochem.vandieten.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>&lt;cffile action=&#8221;write&#8221; file=&#8221;e:\clientdir\wwwroot\Application.cfm&#8221; output=&#8221;&lt;cflocation url=&#8217;some_bad_site&#8217; /&gt;&#8221; /&gt;</p>
<p>And I can assure you it works. Email me if you want to know more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastiaan</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-87</link>
		<dc:creator>Sebastiaan</dc:creator>
		<pubDate>Wed, 03 Dec 2008 11:50:14 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-87</guid>
		<description>Is this in retrospect of your comments that Webstekker is not a secure CF environment?

If you feel it is not, I'd like to know (and why)!!!</description>
		<content:encoded><![CDATA[<p>Is this in retrospect of your comments that Webstekker is not a secure CF environment?</p>
<p>If you feel it is not, I&#8217;d like to know (and why)!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jochem</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-84</link>
		<dc:creator>Jochem</dc:creator>
		<pubDate>Wed, 03 Dec 2008 08:22:52 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-84</guid>
		<description>I'm not really sure I have anything useful to add about the ColdFusion Administrator in a shared hosting environment. I most certainly would not give access to it to any hosted customer.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not really sure I have anything useful to add about the ColdFusion Administrator in a shared hosting environment. I most certainly would not give access to it to any hosted customer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tjarko</title>
		<link>http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/comment-page-1/#comment-81</link>
		<dc:creator>Tjarko</dc:creator>
		<pubDate>Tue, 02 Dec 2008 09:10:49 +0000</pubDate>
		<guid isPermaLink="false">http://jochem.vandieten.net/2008/12/01/coldfusion-shared-hosting-and-security/#comment-81</guid>
		<description>Maybe add ColdFusion Admin control?? I'm still wondering how to incorporate that into a shared environment, and the why behind the API...</description>
		<content:encoded><![CDATA[<p>Maybe add ColdFusion Admin control?? I&#8217;m still wondering how to incorporate that into a shared environment, and the why behind the API&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
