Monthly Archives: February 2009

Setting secure attribute of JSESSIONID cookie in ColdFusion 8

As part of PCI compliance our servers were run through third party security auditing and one warning we received was “Missing Secure Attribute in an Encrypted Session (SSL) Cookie”. This warning referred to the JSESSIONID cookie being set in our SSL enabled pages not having the SECURE attribute set. In ColdFusion there is no way [...]
Posted in ColdFusion, Security | Tagged , , , | Leave a comment

Web data security paranoia

My recent experiences with several hacking attacks has made me think more about application and data security on the web. In today’s world nothing can be taken for granted and security should be of the highest concern, no mater how simple you think your application or trivial the data you store. Many web applications are [...]
Posted in ColdFusion, Databases, PHP, Security | Tagged , , , , | 1 Comment

Preventing SQL Injection attacks in ColdFusion

This is an article I came across on Ben Forta’s blog. This gives some very good tips on preventing SQL  injection attacks and provides some excellent best practices.  http://www.adobe.com/devnet/coldfusion/articles/sql_injection.html When I took up my current position we had to do a vulnerability scan to become PCI compliant and well we originally failed horribly. After much work we [...]
Posted in ColdFusion, Databases, Programming, Security | Tagged , | 1 Comment

Character encoding issue with XML file

Scenario: An xml file is read using CFHTTP from a remote web service. The xml string is converted to an xml object using the XmlParse function. Xpath and XmlSearch are used to extract data from the object. Data is then inserted into a database.   Problem: All punctuation marks are replaced by non readable characters in the database and [...]
Posted in ColdFusion, Programming | Tagged , , , | Leave a comment

Computers: An evening without

I spent the evening yesterday without my computer (mostly). I spent some time with a friend, helped my daughter with her homework and played some Wii. It was quite a refreshing change and I think this is something that most IT developers need. The ability to let go. This is something I have struggled with [...]
Posted in General, Random | Tagged , | Leave a comment
  • Subscribe to my feed Subscriber via Email Follow Me on Twitter! Check me out on Facebook! Check me out on LinkedIn!