RE: Preventing SQL injection attacks...?

2002-04-12 Thread Lewis Steven

Hey,

Is CFID and CFTOKEN vulnerable to this if they are stored as COOKIES and you
are using a DB to store client variables?

Since I assume you could easily modify the CFID and CFTOKEN in your cookie
file that browser maintains.

-Original Message-
From: Zac Spitzer [mailto:[EMAIL PROTECTED]]
Sent: Friday, April 12, 2002 1:06 PM
To: CF-Talk
Subject: Re: Preventing SQL injection attacks...?


[EMAIL PROTECTED] wrote:

>you can't forget that form fields also play a part in this. after reading
>the informaiton provided in jeff's link, it did shine a light. although i
>have been taught from the beginning to always use val() around numberic
>values (thank Adam) and to use regex to validate text input (props
Raymond).
>if your anal and take the time to make sure that the information that
people
>are passing you is in the extact fomrat you want, you shouldn't have a
>problem. also, don't rely on javascript, i always do server-side validation
>even after client side, just to make certain. i even go as far as putting
as
>much validation as i can into my stored procedures and triggers. although
>SQL server doesn't support regular expressions , which sucks! anyone know a
>way it could?
>
why not just use cfqueryparam, it validates and it makes your sql code
run faster???


__
This list and all House of Fusion resources hosted by CFHosting.com. The place for 
dependable ColdFusion Hosting.
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



RE: cffile rejecting some files

2002-04-08 Thread Lewis Steven

Try adding "x/msword" to your accept attribute.

-Original Message-
From: Elizabeth [mailto:[EMAIL PROTECTED]]
Sent: Monday, April 08, 2002 1:51 PM
To: CF-Talk
Subject: cffile rejecting some files


I'm hoping someone can shed some light here.  I have a small app that I
have inherited.  It is used to allow the public (no login required/ and
yes I know this is a security issue) to upload word docs for review for
possible presentation topics at conferences.  The problem is
occassionally the app is rejecting ms word docs even though they have
been included in the 'accept' attribute.  Of course everything works
fine when I try and test it.  Below is the cffile tag I'm using and
below that a copy of a recent error message.  Any ideas why it rejects
some and accepts others?




Error Occurred While Processing Request

 Error Diagnostic Information

 Error processing CFFILE tag

 The MIME type of the uploaded file (x/msword) was not accepted by the
server. Please verify that you are uploading a file
 of the appropriate type.

 The error occurred while processing an element with a general
identifier of (CFFILE), occupying document position (82:2)
 to (86:30).

 Date/Time: 04/05/02 04:54:42 PM
 Browser: Mozilla/4.7 [en] (Win98; U)
 Remote Address: 128.249.70.32
 HTTP Referer:
 Query String: RequestTimeout=600




__
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



RE: Deleting CFID - CFTOKEN

2002-03-13 Thread Lewis Steven

Can you not delete the reference in the database?  Because if you don't the
CFID and CFTOKEN still exist and there is a reference to the data in the
database.

-Original Message-
From: Dave Watts [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, March 12, 2002 11:23 AM
To: CF-Talk
Subject: RE: Deleting CFID - CFTOKEN


> Currently in the ColdFusion Administrator you can tell
> it to purge data for clients that remain unvisited for
> X number of days. Is it possible to go from days to
> hours, or even possibly minutes?

To the best of my knowledge, no, you can't do that. However, you can
disconnect that data from the original client by deleting the CFID and
CFTOKEN cookies (assuming you're using the cookies that CF sets by default
to track users) stored on the browser.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
voice: (202) 797-5496
fax: (202) 797-5444


__
Get Your Own Dedicated Windows 2000 Server
  PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER
  Instant Activation · $99/Month · Free Setup
  http://www.pennyhost.com/redirect.cfm?adcode=coldfusionb
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Deleting CFID - CFTOKEN

2002-03-11 Thread Lewis Steven

Currently in the ColdFusion Administrator you can tell it to purge data for
clients that remain unvisited for X number of days.  Is it possible to go
from days to hours, or even possibly minutes?

Steven Lewis
Booz | Allen | Hamilton
ADNET Software Developer
Phone: 703-845-3996
Cell: 703-338-0853
Pager: 703-219-5759

__
Get Your Own Dedicated Windows 2000 Server
  PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER
  Instant Activation · $99/Month · Free Setup
  http://www.pennyhost.com/redirect.cfm?adcode=coldfusionb
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



RE: session without cookies - why/how does this work?

2002-02-25 Thread Lewis Steven

I think that when you set SETCLIENTCOOKIES="NO" that tells the appserver not
to set CFID and CFTOKEN to persistent cookies, otherwise they are still
being passed but just as non-persistent cookies.

-Original Message-
From: Bimal Shah [mailto:[EMAIL PROTECTED]]
Sent: Monday, February 25, 2002 7:18 AM
To: CF-Talk
Subject: session without cookies - why/how does this work?


Hello

I have an Application.cfm page with the following:



And two cf pages:

page1.cfm



page2.cfm

#session.name#

In the browser, I type in http://mywebserver/page1.cfm and
then type in http://mywebserver/page2.cfm and it displays
"tom.smith".

Why/how does this work when I have set "setclientcookies" to
"No" and I am not passing CFID,CFTOKEN (since I am typing in
the URLS directly - no url or form variables being sent)?

Bimal Shah
Senior Web developer | Venus Internet Ltd | www.venus.co.uk
e: [EMAIL PROTECTED] | t: 0207 240 5858 | f: 0207 240 5859

__
Why Share?
  Dedicated Win 2000 Server · PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER
  Instant Activation · $99/Month · Free Setup
  http://www.pennyhost.com/redirect.cfm?adcode=coldfusionc
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



RE: only one MD5 hash?

2002-02-19 Thread Lewis Steven

I was told that MD5 has a weak key and that Secure Hash Algorithm (SHA-1) is
stronger.

-Original Message-
From: Howie Hamlin [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, February 19, 2002 12:53 PM
To: CF-Talk
Subject: Re: only one MD5 hash?


You can't recover the text from an MD5 hash.  The idea of the hash is that
the hash is created based on a known key (a password, for
example) and that you can duplicate the results of the hash if you know the
original text and the key.  MD5 is commonly used in SMTP
authentication where the user know his password and the server knows the
password.  The server presents a challenge string (the
string changes each time) that the client uses to produce an MD5 string
(using the password as the key).  The client then sends the
MD5 result to the server and the server compares it to its own result.
Thus, you verify the password without actually transmitting
it.

Regards,

Howie

- Original Message -
From: "Cameron Childress" <[EMAIL PROTECTED]>
To: "CF-Talk" <[EMAIL PROTECTED]>
Sent: Tuesday, February 19, 2002 11:36 AM
Subject: RE: only one MD5 hash?



> Brute forcing this 100,000 character string would take a very very very
long
> time.

 -Cameron


__
Dedicated Windows 2000 Server
  PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER
  Instant Activation · $99/Month · Free Setup
  http://www.pennyhost.com/redirect.cfm?adcode=coldfusiona
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Database Errors

2001-11-29 Thread Lewis Steven

Does anybody know what would cause the following error?

ODBC Error Code = IM005 (Driver's SQLAllocConnect failed)

Steven Lewis
Booz | Allen | Hamilton
ADNET Software Developer
Phone: 703-845-3996
Cell: 703-338-0853
~~
Get the mailserver that powers this list at http://www.coolfusion.com
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



CFX_IMAP4

2001-08-13 Thread Lewis Steven

Do any of you an opinion on CFX_IMAP4 from http://www.advancedwebmail.com/?

Steven Lewis
ADNET Lead ColdFusion Developer
Office: 703-845-3996
Pager: 703-219-5759

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



CF INTELLIGENT AGENT QUESTION

2001-07-31 Thread Lewis Steven

Is it possible to use CFHTTP to connect to a web site and establish an on
going session?

What I am trying to accomplish is to have the agent go into a password
protected site, then query the search engine on that site and retrieve
individual web pages from the links that are returned.

If this is not possible does anybody know of any third party software that
can accomplish this task?

Steven Lewis
ADNET Lead ColdFusion Developer
Office: 703-845-3996
Pager: 703-219-5759

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



CF Memory Spike

2001-06-20 Thread Lewis Steven

What would cause the CF Memory to all of a sudden spike?

Steven Lewis



~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Re: URL Parameter in window.open

2001-05-11 Thread Lewis Steven

what about window.open('file.cfm?name='+value, ... )

as long it is a defined JS variable it should work... correct?

Steve

Darren Adams wrote:
> 
> That should work fine but if you intend to send through CF variables then
> you need to wrap it in a CFOUTPUT.
> 
> -Original Message-
> From: Richard Colman [mailto:[EMAIL PROTECTED]]
> Sent: 10 May 2001 15:40
> To: CF-Talk
> Subject: JS:URL Parameter in window.open
> 
> does anyone know something like this will work:
> 
> window.open('file.cfm?name=value', ... )
> 
> (does not seem to be working.)
> 
> is there another easy way to control window size while passing a parameter
> in the URL???
> 
> TNX if you can help.
> 
> Rick Colman
>
~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



OT: Just in time compliation error

2001-05-11 Thread Lewis Steven

What would cause a "Just in time compilation error"?

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Re: encrypt/decrypt

2001-04-09 Thread Lewis Steven

You can also use: cfusion_encrypt() and cfusion_decrypt().

cfusion_encrypt() encrypts the text to numbers and it is DB safe.

Steve

Will Swain wrote:
> 
> Thanks Zach,
> 
> I'll have a look at that
> 
> Cheers
> 
> Will
> 
> -Original Message-
> From: Zachary S. Bedell [mailto:[EMAIL PROTECTED]]
> Sent: 05 April 2001 19:26
> To: CF-Talk
> Subject: RE: encrypt/decrypt
> 
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
> The values that the CF Encrypt function creates usually aren't safe to
> put into a database -- they're binary values if my memory serves
> correctly.  The error you're getting is because Decrypt throws an error
> if the value it gets isn't a valid value made by the Encrypt functions.
> 
> Before you put your values into the DB, you need to convert them to text
> only values.  URLEncodedFormat() would work.  ToString() would probably
> work too.  Then when you pull the value back out of the DB, you just
> URLDecode() it.  I'm not sure how you turn ToString() back to it's
> original form.  I thought it was ToBinary() or something, but I don't
> see that in my quickref book
> 
> To guard against crashes b/c of modified, corrupted values, just
> surround your Decrypt() function call in a CF Try block & handle it
> accordingly.
> 
> 
> 
> 
> INSERT INTO Table (Secret) VALUES( '#Gibberish#'
> 
> 
> 
> 
> SELECT Secret
> FROM Table
> WHERE ...
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> The secret word is: #Secret#
> 
> Something broke...
> 
> 
> Hope that's helpful.
> 
> Best regards,
> Zac Bedell
> > -Original Message-
> > From: Will Swain [mailto:[EMAIL PROTECTED]]
> > Sent: Thursday, April 05, 2001 7:16 AM
> > To: CF-Talk
> > Subject: encrypt/decrypt
> >
> >
> > Hi guys,
> >
> > Got an interesting one here. I am encrypting some details
> > before entering
> > them in a databse, then decrypting them as the authorised views them.
> >
> >
> > However, I am getting this error on decryption:
> >
> > Error Diagnostic Information
> >
> > An error occurred while evaluating the expression:
> >
> >
> >  decryptednumber = decrypt(encryptednumber, numberkey)
> >
> >
> >
> > Error near line 25, column 8.
> > --
> > --
> > 
> >
> > The value to be decrypted is not valid
> >
> >
> > This is the code I have in that location. Interestingly,
> > decrtypting the
> > name doesn't seem to cuase a problem:
> >
> > 
> >
> > 
> >
> > 
> >
> > 
> >
> > 
> >
> > 
> >
> >
> > This is the code on another page that encrypts the values:
> >
> > 
> >
> > 
> >
> > 
> >
> > 
> >
> > Any ideas on this anyone??
> >
> > TIA
> >
> > Will Swain
> >
> >
> >
> >
>
~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Cold Fusion and Exchange

2001-03-27 Thread Lewis Steven

Anybody ever create an exchange account using CF?

When we create the NT Account in CF it is not binding to MS Exchange
like it does when you create it manually in the NT User Manager.

Any help would be greatly appreciated

Thanks,

Steve

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Re: CF Studio 4.5.2 Memory Leak?

2001-03-13 Thread Lewis Steven

If you send a query requests to the CF Server and it returns a large
number of records I've seen studio lock up.

But thats about it

Corrine Clark wrote:
> 
> I have never experienced a problem with my studio 4.5.2 and I run it with my
> database open, email, browser, and adobe photoshop.  I am running on a 2000
> professional and never had a problem.
> 
> -Original Message-
> From: Nathan Stanford [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, March 13, 2001 9:50 AM
> To: CF-Talk
> Subject: CF Studio 4.5.2 Memory Leak?
> 
> CF Studio 4.5.2 Memory Leak?
> 
> My question is my fellow employees and I seem to be having lots of problems
> with memory when we have CF Studio 4.5.2 open.   Even if we boot up a
> machine and don't do anything more then open CF Studio 4.5.2 and leave the
> machine open all day it will lock up before the day is out.
> 
> Has anyone else had this problem?
> 
> Is Allaire addressing this problem?
> 
> Is the a fix for this problem?
> 
> Nathan
>
~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



SNMP and CF

2001-03-13 Thread Lewis Steven

Is there a way to monitor CF using SNMP right now?

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Re: Voice XML

2001-02-27 Thread Lewis Steven

Try http://www.voxeo.com

They have examples using CF, ASP and PHP.



Paul Campano wrote:
> 
> Does anyone have sample code using CF and Voice XML, specfically code to query a 
>database and use the results?.  I
> have been to studio.tellme.com, but they only give example code in Perl and ASP.  
>Thanks.
> 
> Paul Campano
> 
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Virus Scanning Uploaded Files

2001-02-19 Thread Lewis Steven

Has anybody written or know of a custom tag that uses any of the popular
anti virus scanners to scan uploaded files for viruses?

Steve

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Issues with CFX_IMAP4

2001-02-09 Thread Lewis Steven

Has anybody out there had any problems using the custom tag CFX_IMAP4?

Steve

~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm

Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists



Verity Collection

2000-08-09 Thread Lewis Steven

This is a multi-part message in MIME format.
--7E8F2795418F173EA3CD98B4
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

I am trying to develop a Verity Index that is going to be available to
other ColdFusion Sites maintained locally.  When I tell the other
ColdFusion servers to MAP an existing collection the CFSEARCHes fail on
the other systems except the one that did the initial indexing. Why does
this happen?

INFO:
I am storing the verity indexes on a separate computer that all the
computers connect to over the network.  I have already given each CF a
user account to access the network drive.

Any idea?

--7E8F2795418F173EA3CD98B4
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--7E8F2795418F173EA3CD98B4--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: 4.5.1 Memory Leak

2000-08-04 Thread Lewis Steven

This is a multi-part message in MIME format.
--58F9F744FE06BF95C0EBD65C
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Does anybody else have any other suggestions because we are having similar problems?

"Michael C. Baroody" wrote:

> If I remember right, CF Server 4.5.1 isnt supposed to be installed on an
> NT machine running service pack 6. They said there were some problems,
> though then again that was a while ago, they may have fixed them by now.
> If not, I'm guessing that could be your problem
>
> --
> Michael C. Baroody
> [EMAIL PROTECTED]
> http://roody.dyndns.org
>
> > Rich Foster <[EMAIL PROTECTED]> wrote:
>
> The Symptom:
> --
> cfserver.exe suddenly spikes (consumes all memory) out of control
> approx.
> every hour.
>
> System Info:
> ---
> CF 4.5.1
> NT 4.0 SP 6
> MDAC 2.5
>
> The Questions:
> 
> What steps should I take to isolate and resolve this problem?
> What error do I look for in the CF logs?
> If the cause is bad CF code, how do I identify the bad CF code?
>
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--58F9F744FE06BF95C0EBD65C
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--58F9F744FE06BF95C0EBD65C--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



NETSCAPE SUITE SPOT SECURITY QUESTION

2000-07-27 Thread Lewis Steven

This is a multi-part message in MIME format.
--AAED047E1014EFB5097E7D24
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

How old is the security issue with Netscape's suite spot that deals with
the %20 at the end of URL.
**
For those of you who do not know, if you are using Netscape's Suite Spot
and you put a %20 at the end of the url it will show you the source
code.

For Example:

Http://www.whatever.com/application.cfm%20

Will show you the source code for the application.cfm.


Steve

--AAED047E1014EFB5097E7D24
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--AAED047E1014EFB5097E7D24--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: cookies?? or what to use

2000-07-18 Thread Lewis Steven

This is a multi-part message in MIME format.
--AB6BDC84D546A4427FCD8ACE
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Oh, ok. Thanks I didn't know that CGI.HTTP_REFER could be disabled by a SYSADMIN.

But then if the CGI.HTTP_REFER can be disabled, then what other CGI variable can be 
disabled then?

Steve

Dave Hannum wrote:

> Not all servers will give you the CGI.HTTP_REFERER.  Some Sys Admins turn
> that off.
>
> Dave
>
> =
> "What we need is a list of specific unknown problems we will encounter"
>
> David Hannum
> Web Analyst/Programmer
> Ohio University
> [EMAIL PROTECTED]
> (740) 597-2524
>
> - Original Message -
> From: Lewis Steven <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Tuesday, July 18, 2000 8:56 AM
> Subject: Re: cookies?? or what to use
>
> This is a multi-part message in MIME format.
> --BE503D82797F5FE2D22281E4
> Content-Type: text/plain; charset=us-ascii
> Content-Transfer-Encoding: 7bit
>
> Why would you want to use session variables when the CGI.HTTP_REFERER seems
> to a more logical solution.
>
> Anthony Geoghegan wrote:
>
> > Hi Kim,
> > Session Variables can be used for this purpose.
> >
> > Regards,
> > Anthony Geoghegan.
> > Lead Developer,
> > IFTN
> > www.wow.ie
> > mailto:[EMAIL PROTECTED]
> >
> > |-Original Message-
> > |From: Kim Ahlbrandt [mailto:[EMAIL PROTECTED]]
> > |Sent: 15 July 2000 19:07
> > |To: [EMAIL PROTECTED]
> > |Subject: cookies?? or what to use
> > |
> > |
> > |Ok, I'm new to the list...and new to using coldfusion.  I need
> > |to ensure
> > |that users can only go through the system in a certain order
> > |(they must fill
> > |out forms in a particular order and should not be allowed to
> > |come into any
> > |page of the system without first going through the previous
> > |pages).  Does
> > |anyone know how this is best achieved.  Any advice will be helpful.
> > |
> > |Thanks, Kim
> > |[EMAIL PROTECTED]
> > |___
> > |_
> > |Get Your Private, Free E-mail from MSN Hotmail at
> > http://www.hotmail.com
> >
> > --
> --
> > --
> > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> > To Unsubscribe visit
> > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> > send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> > the body.
> > --
> 
> > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> > To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
>
> --BE503D82797F5FE2D22281E4
> Content-Type: text/x-vcard; charset=us-ascii;
>  name="lewis_steven.vcf"
> Content-Transfer-Encoding: 7bit
> Content-Description: Card for Steven Lewis
> Content-Disposition: attachment;
>  filename="lewis_steven.vcf"
>
> begin:vcard
> n:Lewis;Steven
> tel;fax:703-845-3939
> tel;work:703-845-3996
> x-mozilla-html:FALSE
> adr:;;
> version:2.1
> email;internet:[EMAIL PROTECTED]
> fn:Steven Lewis
> end:vcard
>
> --BE503D82797F5FE2D22281E4--
>
> 
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
>
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--AB6BDC84D546A4427FCD8ACE
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--AB6BDC84D546A4427FCD8ACE--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: cookies?? or what to use

2000-07-18 Thread Lewis Steven

This is a multi-part message in MIME format.
--BE503D82797F5FE2D22281E4
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Why would you want to use session variables when the CGI.HTTP_REFERER seems to a more 
logical solution.



Anthony Geoghegan wrote:

> Hi Kim,
> Session Variables can be used for this purpose.
>
> Regards,
> Anthony Geoghegan.
> Lead Developer,
> IFTN
> www.wow.ie
> mailto:[EMAIL PROTECTED]
>
> |-Original Message-
> |From: Kim Ahlbrandt [mailto:[EMAIL PROTECTED]]
> |Sent: 15 July 2000 19:07
> |To: [EMAIL PROTECTED]
> |Subject: cookies?? or what to use
> |
> |
> |Ok, I'm new to the list...and new to using coldfusion.  I need
> |to ensure
> |that users can only go through the system in a certain order
> |(they must fill
> |out forms in a particular order and should not be allowed to
> |come into any
> |page of the system without first going through the previous
> |pages).  Does
> |anyone know how this is best achieved.  Any advice will be helpful.
> |
> |Thanks, Kim
> |[EMAIL PROTECTED]
> |___
> |_
> |Get Your Private, Free E-mail from MSN Hotmail at
> http://www.hotmail.com
>
> 
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--BE503D82797F5FE2D22281E4
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--BE503D82797F5FE2D22281E4--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: Last post: How do I Optimize Win 2000 (IIS) for Warp speed with Cold Fusion.

2000-07-06 Thread Lewis Steven

This is a multi-part message in MIME format.
--B21926975EE819D62D1F9427
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Mark,

Can I receive a copy of your list of optimizing tips for NT 4.0?

Steve

"Mark W. Breneman" wrote:

> This will be my last posting requesting optimizing tips.  Please share any
> info you have/know.  The more info you share the stronger the CF community
> becomes thus the stronger CF is in the marketplace.
>
> IF, you are looking for my NT 4.0 info, I have posted it several times to
> the CF talk list in the last few days per lots of requests.
>
> Anyone care to share
>
> About 9 months ago I collected and posted a compiled list tips and tricks
> (thanks for all the info, by the way) for optimizing NT4.0(IIS) and Cold
> Fusion for max performance.  I would like to do the same for Windows 2000
> (IIS 5) and CF 4.5.
>
> Please also include any gaping security holes and fixes.  And / Or any handy
> tricks like renaming the administrator account in NT.
>
> I will post all the tips and tricks compiled in a list with my own in a few
> days.
>
> If you would like to contact me off list [EMAIL PROTECTED]
>
> Mark W. Breneman
> -Cold Fusion Developer
> -Network Administrator
>   Vivid Media
>   [EMAIL PROTECTED]
>   www.vividmedia.com
>   608.270.9770
>
> 
> --
> Archives: http://www.eGroups.com/list/cf-talk
> To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
>
> 
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
>
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--B21926975EE819D62D1F9427
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--B21926975EE819D62D1F9427--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: CF - Web DB by Oracle

2000-07-05 Thread Lewis Steven

This is a multi-part message in MIME format.
--B62AEFA7440E69C8641D01DC
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

What do you mean it doesn't?  We've got a customer who is interested in it and we are 
trying to tell him he needs to use CF instead.

James Hancock wrote:

> It doesn't.
>
> > -Original Message-
> > From: Lewis Steven [mailto:[EMAIL PROTECTED]]
> > Sent: Wednesday, July 05, 2000 1:40 PM
> > To: [EMAIL PROTECTED]
> > Subject: CF - Web DB by Oracle
> >
> >
> > This is a multi-part message in MIME format.
> > --DAB7D9E7463600EC337A690F
> > Content-Type: text/plain; charset=us-ascii
> > Content-Transfer-Encoding: 7bit
> >
> > How does Web DB by Oracle compare to Cold Fusion?
> >
> >
> >
> > --DAB7D9E7463600EC337A690F
> > Content-Type: text/x-vcard; charset=us-ascii;
> >  name="lewis_steven.vcf"
> > Content-Transfer-Encoding: 7bit
> > Content-Description: Card for Steven Lewis
> > Content-Disposition: attachment;
> >  filename="lewis_steven.vcf"
> >
> > begin:vcard
> > n:Lewis;Steven
> > tel;fax:703-845-3939
> > tel;work:703-845-3996
> > x-mozilla-html:FALSE
> > adr:;;
> > version:2.1
> > email;internet:[EMAIL PROTECTED]
> > fn:Steven Lewis
> > end:vcard
> >
> > --DAB7D9E7463600EC337A690F--
> >
> > --
> > 
> > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> > To Unsubscribe visit
> http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or
> send a message to [EMAIL PROTECTED] with 'unsubscribe' in
> the body.
> --
> Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--B62AEFA7440E69C8641D01DC
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--B62AEFA7440E69C8641D01DC--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



CF - Web DB by Oracle

2000-07-05 Thread Lewis Steven

This is a multi-part message in MIME format.
--DAB7D9E7463600EC337A690F
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

How does Web DB by Oracle compare to Cold Fusion?



--DAB7D9E7463600EC337A690F
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf"

begin:vcard 
n:Lewis;Steven
tel;fax:703-845-3939
tel;work:703-845-3996
x-mozilla-html:FALSE
adr:;;
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Steven Lewis
end:vcard

--DAB7D9E7463600EC337A690F--

--
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.



Re: CF & XML ?

2000-06-28 Thread Lewis Steven

This is a multi-part message in MIME format.
--FAA7C284CD3102899298FC16
Content-Type: multipart/alternative;
 boundary="063F0E0A24C5DC16A00B4514"


--063F0E0A24C5DC16A00B4514
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Try this link at Allaires site.  It will give you some insight on XML and CF.

http://www.allaire.com/handlers/index.cfm?ID=14244



Anthony Geoghegan wrote:

> WDDX is the facility provided by CF in version 4.5 onwards
> Regards,
> Anthony Geoghegan
> Lead Developer,
> IFTN
> www.wow.ie
>
> Original Message-
> From: Akbar [mailto:[EMAIL PROTECTED]]
> Sent: 28 June 2000 11:37
> To: CF Talk (E-mail)
> Subject: CF & XML ?
>
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
>
> hello all,
>
> forgive me if i sound too naive. i have been programming in CF from
> the past 1 yr and recently i am into XML. it feels good whenever i
> read wat all XML can do and solve all those problems which we are not
> aware of and all that stuff.
>
> but when i get down to basics, i am unable to connect XML and CF. i
> mean, i know that CF *somehow* supports XML. but i am not aware how
> well and in wat way. i tried to find an answer at allaire site but
> wat i got is a bunch of links to XML sites which were of not much
> help. i tried to find some site which would describe the link between
> XML and CF, but i couldnt get. may be i am not aware of it.
>
> so can anyone explain or provide me links where all my Q's would be
> answered?? to make it little bit more easy i would like to give an
> example.
>
> i have a XML file and which i am using as a part of EDI. and this
> file i upload into the site. wat i want is that CF should be able to
> parse this XML file and insert the data from the document to the SQL
> DB. this is a simple example i was trying. does CF has its own
> parser?? or do i have to depend on Java??
>
> i have 1 more Q. in all this big picture. where does WDDX fit into??
>
> i hope u ppl wont mind my long winded mail, bcoz i am just learning
> now.
>
> thanx in advance
>
> akbar
>
> --
> Archives: http://www.eGroups.com/list/cf-talk
> To Unsubscribe visit 
>http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a 
>message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

--063F0E0A24C5DC16A00B4514
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit



Try this link at Allaires site.  It will give you some insight on
XML and CF.
http://www.allaire.com/handlers/index.cfm?ID=14244">http://www.allaire.com/handlers/index.cfm?ID=14244
 
 
Anthony Geoghegan wrote:
WDDX is the facility provided by CF in version 4.5
onwards
Regards,
Anthony Geoghegan
Lead Developer,
IFTN
www.wow.ie
Original Message-
From: Akbar [mailto:[EMAIL PROTECTED]">mailto:[EMAIL PROTECTED]]
Sent: 28 June 2000 11:37
To: CF Talk (E-mail)
Subject: CF & XML ?
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
hello all,
forgive me if i sound too naive. i have been programming in CF from
the past 1 yr and recently i am into XML. it feels good whenever i
read wat all XML can do and solve all those problems which we are not
aware of and all that stuff.
but when i get down to basics, i am unable to connect XML and CF. i
mean, i know that CF *somehow* supports XML. but i am not aware how
well and in wat way. i tried to find an answer at allaire site but
wat i got is a bunch of links to XML sites which were of not much
help. i tried to find some site which would describe the link between
XML and CF, but i couldnt get. may be i am not aware of it.
so can anyone explain or provide me links where all my Q's would be
answered?? to make it little bit more easy i would like to give an
example.
i have a XML file and which i am using as a part of EDI. and this
file i upload into the site. wat i want is that CF should be able to
parse this XML file and insert the data from the document to the SQL
DB. this is a simple example i was trying. does CF has its own
parser?? or do i have to depend on Java??
i have 1 more Q. in all this big picture. where does WDDX fit into??
i hope u ppl wont mind my long winded mail, bcoz i am just learning
now.
thanx in advance
akbar
--
Archives: http://www.eGroups.com/list/cf-talk">http://www.eGroups.com/list/cf-talk
To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk">http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk
or send a message to [EMAIL PROTECTED] with 'unsubscribe'
in the body.


--063F0E0A24C5DC16A00B4514--

--FAA7C284CD3102899298FC16
Content-Type: text/x-vcard; charset=us-ascii;
 name="lewis_steven.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Steven Lewis
Content-Disposition: attachment;
 filename="lewis_steven.vcf