Re: Security - Tag restrictions

2004-02-19 Thread peter . tilbrook
Great idea as many shops are still using CF5 and it would be a shame to
lose it to history,

Peter Tilbrook
Transitional Services - Enterprise eSolutions
Centrelink (http://www.centrelink.gov.au)
2 Faulding Street
Symonston ACT 2609

Tel: (02) 62115927


 David Delbridge
 [EMAIL PROTECTED]To: CF-Talk [EMAIL PROTECTED] 
 cc: 
Subject:Re: Security - Tag restrictions
 19/02/2004 06:24 
 Please respond to
 cf-talk|
 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]




RE: Security - Tag restrictions

2004-02-18 Thread cfhelp
Ok this looks like the answer. I have read Ben’s book and the CF
Documentation (CF5) on Advanced security but still not getting it. Is there
a nice tutorial on-line somewhere that shows me step-by-step setup of a
sandbox.

 
Rick

 
-Original Message-
From: Taco Fleur [mailto:[EMAIL PROTECTED] 
Sent: Tuesday, February 17, 2004 10:41 PM
To: CF-Talk
Subject: RE: Security - Tag restrictions

 
You should be able to restrict tags by setting up a security sandbox, from
the CF admin panel...

Taco Fleur
Bloghttp://www.tacofleur.com/index/blog/
HYPERLINK
http://www.tacofleur.com/index/blog/http://www.tacofleur.com/index/blog/
Methodology HYPERLINK
http://www.tacofleur.com/index/methodology/http://www.tacofleur.com/index/
methodology/

Tell me and I will forget
Show me and I will remember
Teach me and I will learn 

-Original Message-
From: Tom Kitta [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, 18 February 2004 1:51 PM
To: CF-Talk
Subject: RE: Security - Tag restrictions

How about just wrapping CFDirectory inside a custom CFC/custom tag? That is
the 1st thing that comes to my mind.

TK
-Original Message-
From: cfhelp [mailto:[EMAIL PROTECTED]
Sent: Tuesday, February 17, 2004 8:48 PM
To: CF-Talk
Subject: Security - Tag restrictions

I have multiple clients on the server that use CFDirectory, but it allows
them the ability to look at the whole server. Is there a way to restrict
the
ability of CFDirectory, CFcontent, CFFILE and other tags like without
disabling them?

Rick

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004 
_
_

[HYPERLINK http://www.houseoffusion.com/lists.cfm?link=t:4Todays Threads]
[HYPERLINK http://www.houseoffusion.com/lists.cfm?link=i:4:153496This
Message] [HYPERLINK
http://www.houseoffusion.com/lists.cfm?link=s:4Subscription] [HYPERLINK
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=984.904.4Fast
Unsubscribe] [HYPERLINK http://www.houseoffusion.com/signin/User Settings]

_

HYPERLINK http://www.houseoffusion.com/banners/view.cfm?bannerid=40 \n

---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004
 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]




Re: Security - Tag restrictions

2004-02-18 Thread David Delbridge
Rick,

Managing Advanced Security on ColdFusion prior to MX is a dismal 
undertaking.If I had only one reason to upgrade, security sandboxing 
would probably be it.

That said, I have something that may be helpful to you.I wrote a 
document, ColdFusion 5.0 Advanced Security Field Guide, which was 
nearing completion when MX was released and I lost interest.At 23 
pages, even if it isn't 100% complete, it's a good read and includes 
some helpful diagrams.

Heck, if you like it, maybe I'll get motivated to finish 'er up.

If interested, please holler and I'll crank out a PDF for you.

Dave

-- 

David M. Delbridge
Circa 3000
ColdFusion Hosting
http://www.circa3k.com
866-CIRCA3K (247-2235)
Outside U.S: +1.775-832-2445

cfhelp wrote:
 Ok this looks like the answer. I have read Ben’s book and the CF
 Documentation (CF5) on Advanced security but still not getting it. Is there
 a nice tutorial on-line somewhere that shows me step-by-step setup of a
 sandbox.
 
 
 Rick
 
 
 -Original Message-
 From: Taco Fleur [mailto:[EMAIL PROTECTED]
 Sent: Tuesday, February 17, 2004 10:41 PM
 To: CF-Talk
 Subject: RE: Security - Tag restrictions
 
 
 You should be able to restrict tags by setting up a security sandbox, from
 the CF admin panel...
 
 Taco Fleur
 Bloghttp://www.tacofleur.com/index/blog/
 HYPERLINK
 http://www.tacofleur.com/index/blog/http://www.tacofleur.com/index/blog/
 Methodology HYPERLINK
 http://www.tacofleur.com/index/methodology/http://www.tacofleur.com/index/
 methodology/
 
 Tell me and I will forget
 Show me and I will remember
 Teach me and I will learn
 
 -Original Message-
 From: Tom Kitta [mailto:[EMAIL PROTECTED]
 Sent: Wednesday, 18 February 2004 1:51 PM
 To: CF-Talk
 Subject: RE: Security - Tag restrictions
 
 How about just wrapping CFDirectory inside a custom CFC/custom tag? That is
 the 1st thing that comes to my mind.
 
 TK
-Original Message-
From: cfhelp [mailto:[EMAIL PROTECTED]
Sent: Tuesday, February 17, 2004 8:48 PM
To: CF-Talk
Subject: Security - Tag restrictions
 
I have multiple clients on the server that use CFDirectory, but it allows
them the ability to look at the whole server. Is there a way to restrict
 the
ability of CFDirectory, CFcontent, CFFILE and other tags like without
disabling them?
 
Rick
 
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004
_
 _
 
 [HYPERLINK http://www.houseoffusion.com/lists.cfm?link=t:4Todays Threads]
 [HYPERLINK http://www.houseoffusion.com/lists.cfm?link=i:4:153496This
 Message] [HYPERLINK
 http://www.houseoffusion.com/lists.cfm?link=s:4Subscription] [HYPERLINK
 http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=984.904.4Fast
 Unsubscribe] [HYPERLINK http://www.houseoffusion.com/signin/User Settings]
 
 _
 
 HYPERLINK http://www.houseoffusion.com/banners/view.cfm?bannerid=40 \n
 
 ---
 Incoming mail is certified Virus Free.
 Checked by AVG anti-virus system (http://www.grisoft.com).
 Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004
 
 ---
 Outgoing mail is certified Virus Free.
 Checked by AVG anti-virus system (http://www.grisoft.com).
 Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004

 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]




Security - Tag restrictions

2004-02-17 Thread cfhelp
I have multiple clients on the server that use CFDirectory, but it allows
them the ability to look at the whole server. Is there a way to restrict the
ability of CFDirectory, CFcontent, CFFILE and other tags like without
disabling them?


Rick

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004
 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]




RE: Security - Tag restrictions

2004-02-17 Thread Tom Kitta
How about just wrapping CFDirectory inside a custom CFC/custom tag? That is
the 1st thing that comes to my mind.

TK
-Original Message-
From: cfhelp [mailto:[EMAIL PROTECTED]
Sent: Tuesday, February 17, 2004 8:48 PM
To: CF-Talk
Subject: Security - Tag restrictions

I have multiple clients on the server that use CFDirectory, but it allows
them the ability to look at the whole server. Is there a way to restrict
the
ability of CFDirectory, CFcontent, CFFILE and other tags like without
disabling them?

Rick

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004
 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]




RE: Security - Tag restrictions

2004-02-17 Thread Taco Fleur
You should be able to restrict tags by setting up a security sandbox, from
the CF admin panel...

Taco Fleur
Bloghttp://www.tacofleur.com/index/blog/
http://www.tacofleur.com/index/blog/
Methodology http://www.tacofleur.com/index/methodology/

Tell me and I will forget
Show me and I will remember
Teach me and I will learn 

-Original Message-
From: Tom Kitta [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, 18 February 2004 1:51 PM
To: CF-Talk
Subject: RE: Security - Tag restrictions

How about just wrapping CFDirectory inside a custom CFC/custom tag? That is
the 1st thing that comes to my mind.

TK
-Original Message-
From: cfhelp [mailto:[EMAIL PROTECTED]
Sent: Tuesday, February 17, 2004 8:48 PM
To: CF-Talk
Subject: Security - Tag restrictions

I have multiple clients on the server that use CFDirectory, but it allows
them the ability to look at the whole server. Is there a way to restrict
the
ability of CFDirectory, CFcontent, CFFILE and other tags like without
disabling them?

Rick

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.583 / Virus Database: 369 - Release Date: 2/10/2004 
_
 [Todays Threads] 
 [This Message] 
 [Subscription] 
 [Fast Unsubscribe] 
 [User Settings]