Skip to main content
Inspiring
November 18, 2013
Question

what's happening with cold fusion?!

  • November 18, 2013
  • 1 reply
  • 706 views

first, this very page is throwing js errors in both ie8 and firefox 24.0  , i can't reply to any posts

then, with all this flurry of security breaches on gov websites running cold fusion, do we have a comprehensive white paper showing how to plug all the security holes that were uncovered?

This topic has been closed for replies.

1 reply

Carl Von Stetten
Legend
November 18, 2013

First, it's ColdFusion, not "cold fusion".  Second, I'm not seeing any issues with this site.  Lastly, as to plugging security holes, there are two things you need to do:

  1. Keep your servers updated with the latest patch(es).  If you are on CF10, use the built-in automatic updater.  If on CF8 or CF9, take a look at David Epler's Unofficial Updater project.
  2. Follow the appropriate ColdFusion lockdown guide for the version you are running.

-Carl V.

ionAuthor
Inspiring
November 18, 2013

Thanks Carl,

when clicking the reply link on the forum, in ie8 i get:

User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1;

Trident/4.0; (R1 1.6); .NET CLR 2.0.50727; .NET CLR 3.0.04506.30;

.NET4.0C; .NET4.0E; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729;

InfoPath.3)

Timestamp: Mon, 18 Nov 2013 15:26:45 UTC

Message: Not implemented

Line: 1616

Char: 13546

Code: 0

URI:

http://forums.adobe.com/4.5.6/resources/scripts/gen/220b1b06a29f901e1d24252ac800883e.js

and in fireFox:

ReferenceError: $ is not defined

https://www.adobe.com/account/sign-in.adobedotcom.html?returnURL=%2Fcfusion%2Fmembership%2Findex%2Ecfm%3Floc%3Den%5Fus%26nl%3D1%26ref%3Dlogin

Line 70

ion amariutei | iamariutei@metlife.com | 212-578-1011

From:

Carl Von Stetten <forums_noreply@adobe.com>

To:

ion <iamariutei@metlife.com>

Date:

11/18/2013 11:19 AM

Subject:

what's happening with cold fusion?!

Re: what's happening with cold fusion?!

created by Carl Von Stetten in Advanced Techniques - View the full

discussion

Site seems to be working fine for me. As to plugging security holes,

there are two things you need to do:

1. Keep your servers updated with the latest patch(es). If you are

on CF10, use the built-in automatic updater. If on CF8 or CF9, take a

look at David Epler's Unofficial Updater project.

2. Follow the appropriate ColdFusion lockdown guide for the version

you are running.

For CF9:

http://www.adobe.com/content/dam/Adobe/en/products/coldfusion/pdfs/910

25512-cf9-lockdownguide-wp-ue.pdf

For CF10:

http://www.adobe.com/content/dam/Adobe/en/products/coldfusion/pdfs/cf1

0/cf10-lockdown-guide.pdf

-Carl V.

Please note that the Adobe Forums do not accept email attachments. If you

want to embed a screen image in your message please visit the thread in

the forum to embed the image at

http://forums.adobe.com/message/5851524#5851524

Replies to this message go to everyone subscribed to this thread, not

directly to the person who posted the message. To post a reply, either

reply to this email or visit the message page: [

http://forums.adobe.com/message/5851524#5851524]

To unsubscribe from this thread, please visit the message page at [

http://forums.adobe.com/message/5851524#5851524]. In the Actions box on

the right, click the Stop Email Notifications link.

Start a new discussion in Advanced Techniques at Adobe Community

For more information about maintaining your forum email notifications

please go to http://forums.adobe.com/thread/416458?tstart=0.

The information contained in this message may be CONFIDENTIAL and is for the intended addressee only. Any unauthorized use, dissemination of the information, or copying of this message is prohibited. If you are not the intended addressee, please notify the sender immediately and delete this message.