Adobe 38043740 Lockdown Guide - Page 23

Create a Website For ColdFusion Administrator

Page 23 highlights

URI /cffileservlet Purpose Safe to Block Serves dynamically generated assets. It supports the cfreport, cfpresentation, and cfimage (with action=captcha and action=writeToBrowser) tags Only if cfreport, cfpresentations and cfimage are not used. /rest /WSRPProducer .svn Used for CF10 Rest web services support. Only if CF10 REST web services are not used. Web Services Endpoint for WSRP. Usually, unless WSRP is used. If you use subversion to deploy Yes your ColdFusion applications you can block the .svn folders, which may allow source code disclosure. 2.2.9 Create a Website For ColdFusion Administrator First create a self signed certificate (or preferably utilize a certificate from a trusted certificate authority) by clicking on the Server Certificates icon under the IIS root. Click on the link to Create Self-Signed Certificate on the right. Create an empty directory for the web site root of the ColdFusion administrator web site (eg f:\web\cfadmin\) 23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

23
URI
Purpose
Safe to Block
/cffileservlet
Serves dynamically generated
assets. It supports the cfreport,
cfpresentation, and cfimage
(with action=captcha and
action=writeToBrowser) tags
Only if cfreport, cfpresentations
and cfimage are not used.
/rest
Used for CF10 Rest web
services support.
Only if CF10 REST web services
are not used.
/WSRPProducer
Web Services Endpoint for
WSRP.
Usually, unless WSRP is used.
.svn
If you use subversion to deploy
your ColdFusion applications
you can block the .svn folders,
which may allow source code
disclosure.
Yes
2.2.9 Create a Website For ColdFusion Administrator
First create a self signed certificate (or preferably utilize a certificate from a trusted certificate authority) by
clicking on the
Server Certificates
icon under the IIS root. Click on the link to
Create Self-Signed Certificate
on the right.
Create an empty directory for the web site root of the ColdFusion administrator web site (eg f:\web\cfadmin\)