We're considering becoming hosting resellers. The company we're thinking of
going with (http://hotchilli.co.uk/) are in the middle of finalising how
their new CFMX set-up is going to be integrated into the features they offer
(or vice versa :-\) - I was just looking for any advice/experience people
here might have on the situation.

They say they're setting up a CFMX and a CF 5 box, and within the reseller
account, virtual CF servers that are set up can either be sandboxed on CFMX,
with CFFILE etc. enabled, or on CF 5 with CFFILE disabled.

We're trying to find out if they're claiming that each virtual CF server we
set up *within* our reseller account will have its own sandbox, or whether
the sandbox will just be for our whole reseller space.

Questions:

- If it's the latter (just one sandbox for the whole account), don't we run
the risk of one of our hosting clients with CFFILE enabled having potential
access to the files of other clients?

- Does sandboxing affect performance or anything else significantly? What do
people their likely setup will be? I don't know enough about the mechanics
of CF Server to assess it properly.

- How much of a risk is CFFILE on CFMX? I've heard of solutions to the
CFFILE problem where replacement custom tags are used that limit access, but
I can't guess how these work - anyone know? Is there are way of implementing
this sort of thing without access to the CF Server itself (my guess is no!)?
Would it be easy for the hosting company to implement if we approached them
about it?

Any thoughts on this would be really well received, it's a nightmare being
at this in-between of knowledge and trying to assess the risks before going
into reselling...

If in the end we have the option to set up CFFILE and non-CFFILE virtual
servers, we may just go with the option of not offering CFFILE servers to
people we don't know and trust. Seems like the only way around the security
hazard, short of every virtual server being sandboxed.

Finally, this host offers different platforms (Linux/NT) and server
technologies (CF/PHP/ASP) within the same reseller account. What are the
downsides to this setup?

Bear in mind among all this that we're not going to be hosting any high
traffic sites, just low-to-medium.

thanks,

- Gyrus

~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- [EMAIL PROTECTED]
work: http://www.tengai.co.uk
play: http://www.norlonto.net
- PGP key available
~~~~~~~~~~~~~~~~~~~~~~~~~~~~

______________________________________________________________________
This list and all House of Fusion resources hosted by CFHosting.com. The place for 
dependable ColdFusion Hosting.
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to