Adobe 38043740 Lockdown Guide - Page 68

Data & Services > Flex Integration, Query, Timeout, seconds, Allowed SQL, Enable Flash, Remoting

Page 68 highlights

Setting Default Recommendation Description Query Timeout (seconds) 0 (no timeout) Specified Specify an upper limit to mitigate DOS attacks. Allowed SQL SELECT, INSERT, UPDATE , DELETE, CREATE, DROP, ALTER, GRANT, REVOKE, Stored Procedures Enable only what your application requires. The CREATE, DROP, ALTER, GRANT, and REVOKE operations are not commonly used in web applications. Ensure that the database user that ColdFusion connects as, also has limited permissions to only what is necessary. 5.7 Data & Services > Flex Integration Setting Default Enable Flash Remoting support Checked Enable RMI over SSL for Data Management Unchecked Recommendation Description Unchecked if not used. Disable Flash Remoting if it is not being used. Checked if using LiveCycle Data Services ES Enable and specify a keystore and password if using LiveCycle Data Services ES with Flex. 68

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

68
Setting
Default
Recommendation
Description
Query
Timeout
(seconds)
0 (
no timeout)
Specified
Specify an upper limit to mitigate
DOS attacks.
Allowed SQL
SELECT,
INSERT,
UPDATE ,
DELETE,
CREATE, DROP,
ALTER, GRANT,
REVOKE, Stored
Procedures
Enable only what
your application
requires.
The CREATE, DROP, ALTER,
GRANT, and REVOKE operations
are not commonly used in web
applications.
Ensure that the database user that
ColdFusion connects as, also has
limited permissions to only what is
necessary.
5.7 Data & Services > Flex Integration
Setting
Default
Recommendation
Description
Enable Flash
Remoting
support
Checked
Unchecked if not
used.
Disable Flash Remoting if it is not
being used.
Enable RMI
over SSL for
Data
Management
Unchecked
Checked if using
LiveCycle Data
Services ES
Enable and specify a keystore and
password if using LiveCycle Data
Services ES with Flex.