Quantcast
Channel: Adobe Community: Message List - ColdFusion
Viewing all articles
Browse latest Browse all 21760

Re: CFIDE directory

$
0
0

You should not have a publiclly accessible CFIDE directory.  It is highly recommended to not only add request filtering to prevent people from getting to these restricted areas, but to add IP address restrictions as well.

 

All ColdFusion needs to operate is the jakarta virtual directory, since it provides access to the needed isapi_rewrite.dll file.

 

If you are using tags which need to access CF's scripts directory, it is highly recommended that you utilize a virtual directory like 'cf-scripts' and then setup in the CF Admin the use of that virtual directory rather than /CFIDE/scripts.

 

If you get a moment, I'd look over the principles put forth in the ColdFusion 10 Server Lockdown Guide and make sure your application adheres to those best practices.


Viewing all articles
Browse latest Browse all 21760

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>