
Adobe documentation - Confidential
Contains CFCs that can act as
a service layer to Flex, or
other client side applications.
The client application must
have a username / password
and also an allowed IP.
Enabling this feature can
open up a large amount of
security risk to the
application server.
API for web socket listener
CFCs. Does not need to be
open via the web server if
integration, not needed on
Table 2.10.2: Additional URIs to consider blocking:
Block Application.cfc and
Application.cfm requests which
result in an error when accessed
directly.
WEB-INF contains configuration
data used by the java
application server. The Tomcat
connector will block this
already, but you can block it at
the web server level as well.
Used for <cfform format=flash>
Only if Flash Forms are not
used.
Adobe documentation - Confidential
Comentários a estes Manuais