But can I just make it so that it will only process if the page requesting
the action was a certain page from a certain server?  u know with cgi vars.

cna i do that as well?

-----Original Message-----
From: Jochem van Dieten [mailto:jochemd@;oli.tudelft.nl]
Sent: Friday, October 18, 2002 10:56 AM
To: CF-Community
Subject: Re: Hey Jochem



Phoeun Pha wrote:

> OMG.  I never knew this!!!
>
> How do I protect my app against such attacks?

Input validation. You need to validate each and every byte.

Jochem


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Archives: http://www.houseoffusion.com/cf_lists/index.cfm?forumid=5
Subscription: 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_community
This list and all House of Fusion resources hosted by CFHosting.com. The place for 
dependable ColdFusion Hosting.

Reply via email to