RE: Preventing SQL injection attacks...?
Hey, Is CFID and CFTOKEN vulnerable to this if they are stored as COOKIES and you are using a DB to store client variables? Since I assume you could easily modify the CFID and CFTOKEN in your cookie file that browser maintains. -Original Message- From: Zac Spitzer [mailto:[EMAIL PROTECTED]] Sent: Friday, April 12, 2002 1:06 PM To: CF-Talk Subject: Re: Preventing SQL injection attacks...? [EMAIL PROTECTED] wrote: >you can't forget that form fields also play a part in this. after reading >the informaiton provided in jeff's link, it did shine a light. although i >have been taught from the beginning to always use val() around numberic >values (thank Adam) and to use regex to validate text input (props Raymond). >if your anal and take the time to make sure that the information that people >are passing you is in the extact fomrat you want, you shouldn't have a >problem. also, don't rely on javascript, i always do server-side validation >even after client side, just to make certain. i even go as far as putting as >much validation as i can into my stored procedures and triggers. although >SQL server doesn't support regular expressions , which sucks! anyone know a >way it could? > why not just use cfqueryparam, it validates and it makes your sql code run faster??? __ This list and all House of Fusion resources hosted by CFHosting.com. The place for dependable ColdFusion Hosting. FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
RE: cffile rejecting some files
Try adding "x/msword" to your accept attribute. -Original Message- From: Elizabeth [mailto:[EMAIL PROTECTED]] Sent: Monday, April 08, 2002 1:51 PM To: CF-Talk Subject: cffile rejecting some files I'm hoping someone can shed some light here. I have a small app that I have inherited. It is used to allow the public (no login required/ and yes I know this is a security issue) to upload word docs for review for possible presentation topics at conferences. The problem is occassionally the app is rejecting ms word docs even though they have been included in the 'accept' attribute. Of course everything works fine when I try and test it. Below is the cffile tag I'm using and below that a copy of a recent error message. Any ideas why it rejects some and accepts others? Error Occurred While Processing Request Error Diagnostic Information Error processing CFFILE tag The MIME type of the uploaded file (x/msword) was not accepted by the server. Please verify that you are uploading a file of the appropriate type. The error occurred while processing an element with a general identifier of (CFFILE), occupying document position (82:2) to (86:30). Date/Time: 04/05/02 04:54:42 PM Browser: Mozilla/4.7 [en] (Win98; U) Remote Address: 128.249.70.32 HTTP Referer: Query String: RequestTimeout=600 __ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
RE: Deleting CFID - CFTOKEN
Can you not delete the reference in the database? Because if you don't the CFID and CFTOKEN still exist and there is a reference to the data in the database. -Original Message- From: Dave Watts [mailto:[EMAIL PROTECTED]] Sent: Tuesday, March 12, 2002 11:23 AM To: CF-Talk Subject: RE: Deleting CFID - CFTOKEN > Currently in the ColdFusion Administrator you can tell > it to purge data for clients that remain unvisited for > X number of days. Is it possible to go from days to > hours, or even possibly minutes? To the best of my knowledge, no, you can't do that. However, you can disconnect that data from the original client by deleting the CFID and CFTOKEN cookies (assuming you're using the cookies that CF sets by default to track users) stored on the browser. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ voice: (202) 797-5496 fax: (202) 797-5444 __ Get Your Own Dedicated Windows 2000 Server PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation · $99/Month · Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusionb FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Deleting CFID - CFTOKEN
Currently in the ColdFusion Administrator you can tell it to purge data for clients that remain unvisited for X number of days. Is it possible to go from days to hours, or even possibly minutes? Steven Lewis Booz | Allen | Hamilton ADNET Software Developer Phone: 703-845-3996 Cell: 703-338-0853 Pager: 703-219-5759 __ Get Your Own Dedicated Windows 2000 Server PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation · $99/Month · Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusionb FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
RE: session without cookies - why/how does this work?
I think that when you set SETCLIENTCOOKIES="NO" that tells the appserver not to set CFID and CFTOKEN to persistent cookies, otherwise they are still being passed but just as non-persistent cookies. -Original Message- From: Bimal Shah [mailto:[EMAIL PROTECTED]] Sent: Monday, February 25, 2002 7:18 AM To: CF-Talk Subject: session without cookies - why/how does this work? Hello I have an Application.cfm page with the following: And two cf pages: page1.cfm page2.cfm #session.name# In the browser, I type in http://mywebserver/page1.cfm and then type in http://mywebserver/page2.cfm and it displays "tom.smith". Why/how does this work when I have set "setclientcookies" to "No" and I am not passing CFID,CFTOKEN (since I am typing in the URLS directly - no url or form variables being sent)? Bimal Shah Senior Web developer | Venus Internet Ltd | www.venus.co.uk e: [EMAIL PROTECTED] | t: 0207 240 5858 | f: 0207 240 5859 __ Why Share? Dedicated Win 2000 Server · PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation · $99/Month · Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusionc FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
RE: only one MD5 hash?
I was told that MD5 has a weak key and that Secure Hash Algorithm (SHA-1) is stronger. -Original Message- From: Howie Hamlin [mailto:[EMAIL PROTECTED]] Sent: Tuesday, February 19, 2002 12:53 PM To: CF-Talk Subject: Re: only one MD5 hash? You can't recover the text from an MD5 hash. The idea of the hash is that the hash is created based on a known key (a password, for example) and that you can duplicate the results of the hash if you know the original text and the key. MD5 is commonly used in SMTP authentication where the user know his password and the server knows the password. The server presents a challenge string (the string changes each time) that the client uses to produce an MD5 string (using the password as the key). The client then sends the MD5 result to the server and the server compares it to its own result. Thus, you verify the password without actually transmitting it. Regards, Howie - Original Message - From: "Cameron Childress" <[EMAIL PROTECTED]> To: "CF-Talk" <[EMAIL PROTECTED]> Sent: Tuesday, February 19, 2002 11:36 AM Subject: RE: only one MD5 hash? > Brute forcing this 100,000 character string would take a very very very long > time. -Cameron __ Dedicated Windows 2000 Server PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER Instant Activation · $99/Month · Free Setup http://www.pennyhost.com/redirect.cfm?adcode=coldfusiona FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Database Errors
Does anybody know what would cause the following error? ODBC Error Code = IM005 (Driver's SQLAllocConnect failed) Steven Lewis Booz | Allen | Hamilton ADNET Software Developer Phone: 703-845-3996 Cell: 703-338-0853 ~~ Get the mailserver that powers this list at http://www.coolfusion.com FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
CFX_IMAP4
Do any of you an opinion on CFX_IMAP4 from http://www.advancedwebmail.com/? Steven Lewis ADNET Lead ColdFusion Developer Office: 703-845-3996 Pager: 703-219-5759 ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
CF INTELLIGENT AGENT QUESTION
Is it possible to use CFHTTP to connect to a web site and establish an on going session? What I am trying to accomplish is to have the agent go into a password protected site, then query the search engine on that site and retrieve individual web pages from the links that are returned. If this is not possible does anybody know of any third party software that can accomplish this task? Steven Lewis ADNET Lead ColdFusion Developer Office: 703-845-3996 Pager: 703-219-5759 ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
CF Memory Spike
What would cause the CF Memory to all of a sudden spike? Steven Lewis ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Re: URL Parameter in window.open
what about window.open('file.cfm?name='+value, ... ) as long it is a defined JS variable it should work... correct? Steve Darren Adams wrote: > > That should work fine but if you intend to send through CF variables then > you need to wrap it in a CFOUTPUT. > > -Original Message- > From: Richard Colman [mailto:[EMAIL PROTECTED]] > Sent: 10 May 2001 15:40 > To: CF-Talk > Subject: JS:URL Parameter in window.open > > does anyone know something like this will work: > > window.open('file.cfm?name=value', ... ) > > (does not seem to be working.) > > is there another easy way to control window size while passing a parameter > in the URL??? > > TNX if you can help. > > Rick Colman > ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
OT: Just in time compliation error
What would cause a "Just in time compilation error"? ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Re: encrypt/decrypt
You can also use: cfusion_encrypt() and cfusion_decrypt(). cfusion_encrypt() encrypts the text to numbers and it is DB safe. Steve Will Swain wrote: > > Thanks Zach, > > I'll have a look at that > > Cheers > > Will > > -Original Message- > From: Zachary S. Bedell [mailto:[EMAIL PROTECTED]] > Sent: 05 April 2001 19:26 > To: CF-Talk > Subject: RE: encrypt/decrypt > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > The values that the CF Encrypt function creates usually aren't safe to > put into a database -- they're binary values if my memory serves > correctly. The error you're getting is because Decrypt throws an error > if the value it gets isn't a valid value made by the Encrypt functions. > > Before you put your values into the DB, you need to convert them to text > only values. URLEncodedFormat() would work. ToString() would probably > work too. Then when you pull the value back out of the DB, you just > URLDecode() it. I'm not sure how you turn ToString() back to it's > original form. I thought it was ToBinary() or something, but I don't > see that in my quickref book > > To guard against crashes b/c of modified, corrupted values, just > surround your Decrypt() function call in a CF Try block & handle it > accordingly. > > > > > INSERT INTO Table (Secret) VALUES( '#Gibberish#' > > > > > SELECT Secret > FROM Table > WHERE ... > > > > > > > > > > > > The secret word is: #Secret# > > Something broke... > > > Hope that's helpful. > > Best regards, > Zac Bedell > > -Original Message- > > From: Will Swain [mailto:[EMAIL PROTECTED]] > > Sent: Thursday, April 05, 2001 7:16 AM > > To: CF-Talk > > Subject: encrypt/decrypt > > > > > > Hi guys, > > > > Got an interesting one here. I am encrypting some details > > before entering > > them in a databse, then decrypting them as the authorised views them. > > > > > > However, I am getting this error on decryption: > > > > Error Diagnostic Information > > > > An error occurred while evaluating the expression: > > > > > > decryptednumber = decrypt(encryptednumber, numberkey) > > > > > > > > Error near line 25, column 8. > > -- > > -- > > > > > > The value to be decrypted is not valid > > > > > > This is the code I have in that location. Interestingly, > > decrtypting the > > name doesn't seem to cuase a problem: > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > This is the code on another page that encrypts the values: > > > > > > > > > > > > > > > > > > > > Any ideas on this anyone?? > > > > TIA > > > > Will Swain > > > > > > > > > ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Cold Fusion and Exchange
Anybody ever create an exchange account using CF? When we create the NT Account in CF it is not binding to MS Exchange like it does when you create it manually in the NT User Manager. Any help would be greatly appreciated Thanks, Steve ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Re: CF Studio 4.5.2 Memory Leak?
If you send a query requests to the CF Server and it returns a large number of records I've seen studio lock up. But thats about it Corrine Clark wrote: > > I have never experienced a problem with my studio 4.5.2 and I run it with my > database open, email, browser, and adobe photoshop. I am running on a 2000 > professional and never had a problem. > > -Original Message- > From: Nathan Stanford [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, March 13, 2001 9:50 AM > To: CF-Talk > Subject: CF Studio 4.5.2 Memory Leak? > > CF Studio 4.5.2 Memory Leak? > > My question is my fellow employees and I seem to be having lots of problems > with memory when we have CF Studio 4.5.2 open. Even if we boot up a > machine and don't do anything more then open CF Studio 4.5.2 and leave the > machine open all day it will lock up before the day is out. > > Has anyone else had this problem? > > Is Allaire addressing this problem? > > Is the a fix for this problem? > > Nathan > ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
SNMP and CF
Is there a way to monitor CF using SNMP right now? ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Re: Voice XML
Try http://www.voxeo.com They have examples using CF, ASP and PHP. Paul Campano wrote: > > Does anyone have sample code using CF and Voice XML, specfically code to query a >database and use the results?. I > have been to studio.tellme.com, but they only give example code in Perl and ASP. >Thanks. > > Paul Campano > > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Virus Scanning Uploaded Files
Has anybody written or know of a custom tag that uses any of the popular anti virus scanners to scan uploaded files for viruses? Steve ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Issues with CFX_IMAP4
Has anybody out there had any problems using the custom tag CFX_IMAP4? Steve ~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists
Verity Collection
This is a multi-part message in MIME format. --7E8F2795418F173EA3CD98B4 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit I am trying to develop a Verity Index that is going to be available to other ColdFusion Sites maintained locally. When I tell the other ColdFusion servers to MAP an existing collection the CFSEARCHes fail on the other systems except the one that did the initial indexing. Why does this happen? INFO: I am storing the verity indexes on a separate computer that all the computers connect to over the network. I have already given each CF a user account to access the network drive. Any idea? --7E8F2795418F173EA3CD98B4 Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --7E8F2795418F173EA3CD98B4-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: 4.5.1 Memory Leak
This is a multi-part message in MIME format. --58F9F744FE06BF95C0EBD65C Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Does anybody else have any other suggestions because we are having similar problems? "Michael C. Baroody" wrote: > If I remember right, CF Server 4.5.1 isnt supposed to be installed on an > NT machine running service pack 6. They said there were some problems, > though then again that was a while ago, they may have fixed them by now. > If not, I'm guessing that could be your problem > > -- > Michael C. Baroody > [EMAIL PROTECTED] > http://roody.dyndns.org > > > Rich Foster <[EMAIL PROTECTED]> wrote: > > The Symptom: > -- > cfserver.exe suddenly spikes (consumes all memory) out of control > approx. > every hour. > > System Info: > --- > CF 4.5.1 > NT 4.0 SP 6 > MDAC 2.5 > > The Questions: > > What steps should I take to isolate and resolve this problem? > What error do I look for in the CF logs? > If the cause is bad CF code, how do I identify the bad CF code? > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --58F9F744FE06BF95C0EBD65C Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --58F9F744FE06BF95C0EBD65C-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
NETSCAPE SUITE SPOT SECURITY QUESTION
This is a multi-part message in MIME format. --AAED047E1014EFB5097E7D24 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit How old is the security issue with Netscape's suite spot that deals with the %20 at the end of URL. ** For those of you who do not know, if you are using Netscape's Suite Spot and you put a %20 at the end of the url it will show you the source code. For Example: Http://www.whatever.com/application.cfm%20 Will show you the source code for the application.cfm. Steve --AAED047E1014EFB5097E7D24 Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --AAED047E1014EFB5097E7D24-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: cookies?? or what to use
This is a multi-part message in MIME format. --AB6BDC84D546A4427FCD8ACE Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Oh, ok. Thanks I didn't know that CGI.HTTP_REFER could be disabled by a SYSADMIN. But then if the CGI.HTTP_REFER can be disabled, then what other CGI variable can be disabled then? Steve Dave Hannum wrote: > Not all servers will give you the CGI.HTTP_REFERER. Some Sys Admins turn > that off. > > Dave > > = > "What we need is a list of specific unknown problems we will encounter" > > David Hannum > Web Analyst/Programmer > Ohio University > [EMAIL PROTECTED] > (740) 597-2524 > > - Original Message - > From: Lewis Steven <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Sent: Tuesday, July 18, 2000 8:56 AM > Subject: Re: cookies?? or what to use > > This is a multi-part message in MIME format. > --BE503D82797F5FE2D22281E4 > Content-Type: text/plain; charset=us-ascii > Content-Transfer-Encoding: 7bit > > Why would you want to use session variables when the CGI.HTTP_REFERER seems > to a more logical solution. > > Anthony Geoghegan wrote: > > > Hi Kim, > > Session Variables can be used for this purpose. > > > > Regards, > > Anthony Geoghegan. > > Lead Developer, > > IFTN > > www.wow.ie > > mailto:[EMAIL PROTECTED] > > > > |-Original Message- > > |From: Kim Ahlbrandt [mailto:[EMAIL PROTECTED]] > > |Sent: 15 July 2000 19:07 > > |To: [EMAIL PROTECTED] > > |Subject: cookies?? or what to use > > | > > | > > |Ok, I'm new to the list...and new to using coldfusion. I need > > |to ensure > > |that users can only go through the system in a certain order > > |(they must fill > > |out forms in a particular order and should not be allowed to > > |come into any > > |page of the system without first going through the previous > > |pages). Does > > |anyone know how this is best achieved. Any advice will be helpful. > > | > > |Thanks, Kim > > |[EMAIL PROTECTED] > > |___ > > |_ > > |Get Your Private, Free E-mail from MSN Hotmail at > > http://www.hotmail.com > > > > -- > -- > > -- > > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > > To Unsubscribe visit > > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > > the body. > > -- > > > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > > --BE503D82797F5FE2D22281E4 > Content-Type: text/x-vcard; charset=us-ascii; > name="lewis_steven.vcf" > Content-Transfer-Encoding: 7bit > Content-Description: Card for Steven Lewis > Content-Disposition: attachment; > filename="lewis_steven.vcf" > > begin:vcard > n:Lewis;Steven > tel;fax:703-845-3939 > tel;work:703-845-3996 > x-mozilla-html:FALSE > adr:;; > version:2.1 > email;internet:[EMAIL PROTECTED] > fn:Steven Lewis > end:vcard > > --BE503D82797F5FE2D22281E4-- > > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --AB6BDC84D546A4427FCD8ACE Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --AB6BDC84D546A4427FCD8ACE-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: cookies?? or what to use
This is a multi-part message in MIME format. --BE503D82797F5FE2D22281E4 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Why would you want to use session variables when the CGI.HTTP_REFERER seems to a more logical solution. Anthony Geoghegan wrote: > Hi Kim, > Session Variables can be used for this purpose. > > Regards, > Anthony Geoghegan. > Lead Developer, > IFTN > www.wow.ie > mailto:[EMAIL PROTECTED] > > |-Original Message- > |From: Kim Ahlbrandt [mailto:[EMAIL PROTECTED]] > |Sent: 15 July 2000 19:07 > |To: [EMAIL PROTECTED] > |Subject: cookies?? or what to use > | > | > |Ok, I'm new to the list...and new to using coldfusion. I need > |to ensure > |that users can only go through the system in a certain order > |(they must fill > |out forms in a particular order and should not be allowed to > |come into any > |page of the system without first going through the previous > |pages). Does > |anyone know how this is best achieved. Any advice will be helpful. > | > |Thanks, Kim > |[EMAIL PROTECTED] > |___ > |_ > |Get Your Private, Free E-mail from MSN Hotmail at > http://www.hotmail.com > > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --BE503D82797F5FE2D22281E4 Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --BE503D82797F5FE2D22281E4-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: Last post: How do I Optimize Win 2000 (IIS) for Warp speed with Cold Fusion.
This is a multi-part message in MIME format. --B21926975EE819D62D1F9427 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Mark, Can I receive a copy of your list of optimizing tips for NT 4.0? Steve "Mark W. Breneman" wrote: > This will be my last posting requesting optimizing tips. Please share any > info you have/know. The more info you share the stronger the CF community > becomes thus the stronger CF is in the marketplace. > > IF, you are looking for my NT 4.0 info, I have posted it several times to > the CF talk list in the last few days per lots of requests. > > Anyone care to share > > About 9 months ago I collected and posted a compiled list tips and tricks > (thanks for all the info, by the way) for optimizing NT4.0(IIS) and Cold > Fusion for max performance. I would like to do the same for Windows 2000 > (IIS 5) and CF 4.5. > > Please also include any gaping security holes and fixes. And / Or any handy > tricks like renaming the administrator account in NT. > > I will post all the tips and tricks compiled in a list with my own in a few > days. > > If you would like to contact me off list [EMAIL PROTECTED] > > Mark W. Breneman > -Cold Fusion Developer > -Network Administrator > Vivid Media > [EMAIL PROTECTED] > www.vividmedia.com > 608.270.9770 > > > -- > Archives: http://www.eGroups.com/list/cf-talk > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --B21926975EE819D62D1F9427 Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --B21926975EE819D62D1F9427-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: CF - Web DB by Oracle
This is a multi-part message in MIME format. --B62AEFA7440E69C8641D01DC Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit What do you mean it doesn't? We've got a customer who is interested in it and we are trying to tell him he needs to use CF instead. James Hancock wrote: > It doesn't. > > > -Original Message- > > From: Lewis Steven [mailto:[EMAIL PROTECTED]] > > Sent: Wednesday, July 05, 2000 1:40 PM > > To: [EMAIL PROTECTED] > > Subject: CF - Web DB by Oracle > > > > > > This is a multi-part message in MIME format. > > --DAB7D9E7463600EC337A690F > > Content-Type: text/plain; charset=us-ascii > > Content-Transfer-Encoding: 7bit > > > > How does Web DB by Oracle compare to Cold Fusion? > > > > > > > > --DAB7D9E7463600EC337A690F > > Content-Type: text/x-vcard; charset=us-ascii; > > name="lewis_steven.vcf" > > Content-Transfer-Encoding: 7bit > > Content-Description: Card for Steven Lewis > > Content-Disposition: attachment; > > filename="lewis_steven.vcf" > > > > begin:vcard > > n:Lewis;Steven > > tel;fax:703-845-3939 > > tel;work:703-845-3996 > > x-mozilla-html:FALSE > > adr:;; > > version:2.1 > > email;internet:[EMAIL PROTECTED] > > fn:Steven Lewis > > end:vcard > > > > --DAB7D9E7463600EC337A690F-- > > > > -- > > > > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > > To Unsubscribe visit > http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or > send a message to [EMAIL PROTECTED] with 'unsubscribe' in > the body. > -- > Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --B62AEFA7440E69C8641D01DC Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --B62AEFA7440E69C8641D01DC-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
CF - Web DB by Oracle
This is a multi-part message in MIME format. --DAB7D9E7463600EC337A690F Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit How does Web DB by Oracle compare to Cold Fusion? --DAB7D9E7463600EC337A690F Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf" begin:vcard n:Lewis;Steven tel;fax:703-845-3939 tel;work:703-845-3996 x-mozilla-html:FALSE adr:;; version:2.1 email;internet:[EMAIL PROTECTED] fn:Steven Lewis end:vcard --DAB7D9E7463600EC337A690F-- -- Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body.
Re: CF & XML ?
This is a multi-part message in MIME format. --FAA7C284CD3102899298FC16 Content-Type: multipart/alternative; boundary="063F0E0A24C5DC16A00B4514" --063F0E0A24C5DC16A00B4514 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Try this link at Allaires site. It will give you some insight on XML and CF. http://www.allaire.com/handlers/index.cfm?ID=14244 Anthony Geoghegan wrote: > WDDX is the facility provided by CF in version 4.5 onwards > Regards, > Anthony Geoghegan > Lead Developer, > IFTN > www.wow.ie > > Original Message- > From: Akbar [mailto:[EMAIL PROTECTED]] > Sent: 28 June 2000 11:37 > To: CF Talk (E-mail) > Subject: CF & XML ? > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > hello all, > > forgive me if i sound too naive. i have been programming in CF from > the past 1 yr and recently i am into XML. it feels good whenever i > read wat all XML can do and solve all those problems which we are not > aware of and all that stuff. > > but when i get down to basics, i am unable to connect XML and CF. i > mean, i know that CF *somehow* supports XML. but i am not aware how > well and in wat way. i tried to find an answer at allaire site but > wat i got is a bunch of links to XML sites which were of not much > help. i tried to find some site which would describe the link between > XML and CF, but i couldnt get. may be i am not aware of it. > > so can anyone explain or provide me links where all my Q's would be > answered?? to make it little bit more easy i would like to give an > example. > > i have a XML file and which i am using as a part of EDI. and this > file i upload into the site. wat i want is that CF should be able to > parse this XML file and insert the data from the document to the SQL > DB. this is a simple example i was trying. does CF has its own > parser?? or do i have to depend on Java?? > > i have 1 more Q. in all this big picture. where does WDDX fit into?? > > i hope u ppl wont mind my long winded mail, bcoz i am just learning > now. > > thanx in advance > > akbar > > -- > Archives: http://www.eGroups.com/list/cf-talk > To Unsubscribe visit >http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a >message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --063F0E0A24C5DC16A00B4514 Content-Type: text/html; charset=us-ascii Content-Transfer-Encoding: 7bit Try this link at Allaires site. It will give you some insight on XML and CF. http://www.allaire.com/handlers/index.cfm?ID=14244">http://www.allaire.com/handlers/index.cfm?ID=14244 Anthony Geoghegan wrote: WDDX is the facility provided by CF in version 4.5 onwards Regards, Anthony Geoghegan Lead Developer, IFTN www.wow.ie Original Message- From: Akbar [mailto:[EMAIL PROTECTED]">mailto:[EMAIL PROTECTED]] Sent: 28 June 2000 11:37 To: CF Talk (E-mail) Subject: CF & XML ? -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 hello all, forgive me if i sound too naive. i have been programming in CF from the past 1 yr and recently i am into XML. it feels good whenever i read wat all XML can do and solve all those problems which we are not aware of and all that stuff. but when i get down to basics, i am unable to connect XML and CF. i mean, i know that CF *somehow* supports XML. but i am not aware how well and in wat way. i tried to find an answer at allaire site but wat i got is a bunch of links to XML sites which were of not much help. i tried to find some site which would describe the link between XML and CF, but i couldnt get. may be i am not aware of it. so can anyone explain or provide me links where all my Q's would be answered?? to make it little bit more easy i would like to give an example. i have a XML file and which i am using as a part of EDI. and this file i upload into the site. wat i want is that CF should be able to parse this XML file and insert the data from the document to the SQL DB. this is a simple example i was trying. does CF has its own parser?? or do i have to depend on Java?? i have 1 more Q. in all this big picture. where does WDDX fit into?? i hope u ppl wont mind my long winded mail, bcoz i am just learning now. thanx in advance akbar -- Archives: http://www.eGroups.com/list/cf-talk">http://www.eGroups.com/list/cf-talk To Unsubscribe visit http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk">http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/cf_talk or send a message to [EMAIL PROTECTED] with 'unsubscribe' in the body. --063F0E0A24C5DC16A00B4514-- --FAA7C284CD3102899298FC16 Content-Type: text/x-vcard; charset=us-ascii; name="lewis_steven.vcf" Content-Transfer-Encoding: 7bit Content-Description: Card for Steven Lewis Content-Disposition: attachment; filename="lewis_steven.vcf