Skip to Content
Programming ColdFusion MX, 2nd Edition
book

Programming ColdFusion MX, 2nd Edition

by Rob Brooks-Bilson
August 2003
Intermediate to advanced
1140 pages
68h 45m
English
O'Reilly Media, Inc.
Content preview from Programming ColdFusion MX, 2nd Edition

Security Basics

Before we dive into the different security techniques, let’s look at some general dos and don’ts to consider when designing and implementing a security solution for your ColdFusion applications:

  • Don’t base security solely on a user’s IP address. IP addresses are easily spoofed and can often change during a user’s session (especially in the case of AOL users because of the way AOL’s network works). Additionally, dialup users most likely won’t have the same IP address the next time they dial in and use your application because most ISPs use DHCP.

  • Do use SSL wherever necessary to encrypt the session between the server and the browser. Because SSL is handled at the web-server level and not by ColdFusion, you need to consult the documentation for your particular web server to determine how to set it up.

  • Do require users to choose passwords that aren’t easily guessed or found in the dictionary. If possible, require users to choose a password that contains a combination of letters, numbers, and possibly symbols. One way to handle this is by automatically assigning passwords to users. If you let users choose their own passwords, you can still ensure they contain certain characters by using ColdFusion ReFind( ) function (described in Chapter 18).

  • Do include error and exception handling in your applications to prevent users from receiving server and application information when an error or exception occurs. These concepts are covered in Chapter 9.

  • Don’t store passwords ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Programming ColdFusion

Programming ColdFusion

Rob Brooks-Bilson
macromedia® Coldfusion® MX 7 Web Application Construction Kit

macromedia® Coldfusion® MX 7 Web Application Construction Kit

Ben Forta, Raymond Camden, Leon Chalnick, Angela Buraglia

Publisher Resources

ISBN: 0596003803Errata Page