HackMyCF Scanner Updated

by Pete Freitag

Yesterday I added some additional functionality to the HackMyCF ColdFusion Server Security Scanner:

I have to thank the folks that have subscribed to the HackMyCF paid service for allowing me to keep the scanner up to date!

The Fixinator Code Security Scanner for ColdFusion & CFML is an easy to use security tool that every CF developer can use. It can also easily integrate into CI for automatic scanning on every commit.

Comments

Thomas Craig

Great stuff, this is always a concern of mine, safe guarding a site and then trying to break it. Do you know of any vulnerabilities with CF9 out of the box?

Pete Freitag

@Thomas - Yes there are a number of vulnerabilities in CF9 that need to be patched (a patch was just released yesterday in fact) see http://www.adobe.com/support/security/#coldfusion for more info.