ColdFusion Code Security
Speaker Information
Introduction
ColdFusion Security
Not covered in this talk
Error handling
Error handling code
Form Validation
Why is validation important?
Underscore Validation
CFFORM Validation
Javascript Validation
CF Validation
Authentication
Fake URLs
How to checksum a URL
How to encrypt a URL
Fake form submits
Preventing Fake form submits
Fake cookies
SQL hacking
SQL hacking prevention
CFQUERYPARAM
Protect CFINCLUDE and CFMODULE files
Code to protect CFINCLUDE files
Code Defensively
Input massaging
CFCONTENT
Logins
Members Only
Session, client and cookies
Timeouts
Session Tracking
Session hang over
Remember Me
Back button hacking
Refresh Issues
Datasource password
Encryption
Hashing passwords
Resources
What Security Means
Next Steps