ColdFusion 10 Security Enhancements Presentation
Update: If you are looking for more up to date CF security info, checkout my ColdFusion Security Training course.
I've given a couple presentations now on the security enhancements in ColdFusion 10. The most recent was today at the Adobe ColdFusion Developer 2012, but I've also given it two other times for a Carahsoft webinar, and for the Carahsoft ColdFusion 10 Preview event in Washington DC. The slide deck was very similar for all three, but today's slides are the most up to date.
I hope you find it useful, there really are quite a few security enhancements in ColdFusion 10, so many that it's difficult to cover all of them in an hour!
Here's a short list of some of the enhancements (not even including all of them):
- Secure Profile in installation
- Weak password warnings in installation
- Hotfix Installer
- CF Admin IP restrictions
- Tomcat - lots of security folks review tomcat, JRun... not so much
- Session Cookie settings
- New SessionRotate() and SessionInvalidate() functions
- CFFile Upload accept allows file extensions, strict mode now checks file content mime type, not just the mime type the browser sends (though this can still be spoofed).
- Hash iterations
- HMAC Function
- CSRF Token Functions
- Ram disk application isolation
- And several more!
Like this? Follow me ↯Tweet Follow @pfreitag
ColdFusion 10 Security Enhancements Presentation was first published on June 07, 2012.
If you like reading about coldfusion, security, cf10, presentations, or slides then you might also like:
- ColdFusion 2020 Developer Week - Securing CF
- CFSummit 2016 Slides
- Securing Legacy CFML - dev.Objective() 2016 Slides
- Adobe eSeminar on FuseGuard
- Maximum Security CFML - cfObjective Slides
- Writing Secure CFML Slides from CFUnited 2010
- Slides for NYCFUG Security Presentation
- Hardening ColdFusion - cfObjective 2009 Presentation Slides
The FuseGuard Web Application Firewall for ColdFusion & CFML is a high performance, customizable engine that blocks various attacks against your ColdFusion applications.