At 11:08 PM 5/11/00 -0700, Ryan Hill wrote:
>Note:
>
>The following analysis is a compilation of several technical discussions
>with Allaire that I feel should be published to allow the Allaire customer
>community to draw their own conclusions as to the actual threat risk and
>severity of this vulnerability [with cfCache]...

I interrupt this discussion of problems with cfCache to highly recommend
Xing Li's open source custom tag CF_cacheThis
(http://www1.allaire.com/developer/gallery/index.cfm?ObjectID=14160&nocache=
yes), which:

   * can cache parts of pages instead of the entire page
   * can have separate cached page sections based on the URL, or an "extra
seed"
   * does not rely on a separate thread to perform the caching

The last point means that cf_cacheThis does not suffer from the potential
DoS vulnerability, and moreover, it would not have the problems with user
authentication that cfCache seems to have.

As an aside, has anyone used cf_cacheThis to cache lots of pages?  100s?
1000s?  How far has it been pushed?

Gregory M. Saunders, Ph.D.
Senior Design Architect
Cognitive Arts Corporation (http://www.cognitivearts.com)
120 S. Riverside Plaza, Suite 1520
Chicago, IL 60606

------------------------------------------------------------------------------
Archives: http://www.eGroups.com/list/cf-talk
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

Reply via email to