Re: Fun with ColdFusion Denial of Service Attacks

2005-05-11 Thread Philip Arnold
Of course, requesttimeout was depricated in CFMX, so you're only looking at CF5 >From the LiveDocs: http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-pc6.htm The cfsetting requestTimeout attribute replaces the use of requestTmeOut within a URL. To enforce a page timeout, detect the URL v

Fun with ColdFusion Denial of Service Attacks

2005-05-09 Thread Cameron Childress
Curious to know how is vulnerable to DoS attacks? Just search for "allinurl: requesttimeout" in Google. This will return any site with a page that takes an unusually long amount of time to process. Look ma! A DoS attack target! Load the page in 50 browser windows at the same time and watch the