<?xml version="1.0" encoding="utf-8"?>
			
			<rss version="2.0" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:cc="http://web.resource.org/cc/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

			<channel>
			<title>Tofinha ColdFusion Developer English - Security</title>
			<link>http://www.tofinha.com.br/blog/index.cfm</link>
			<description>Blog to publish my works and ColdFusion out for Brazil</description>
			<language>en-us</language>
			<pubDate>Thu, 09 Sep 2010 07:01:08 -0300</pubDate>
			<lastBuildDate>Fri, 04 Dec 2009 11:32:00 -0300</lastBuildDate>
			<generator>BlogCFC</generator>
			<docs>http://blogs.law.harvard.edu/tech/rss</docs>
			<managingEditor>tofinha@gmail.com</managingEditor>
			<webMaster>tofinha@gmail.com</webMaster>
			<itunes:subtitle></itunes:subtitle>
			<itunes:summary></itunes:summary>
			<itunes:category text="Technology" />
			<itunes:category text="Technology">
				<itunes:category text="Podcasting" />
			</itunes:category>
			<itunes:category text="Technology">
				<itunes:category text="Tech News" />
			</itunes:category>
			<itunes:keywords></itunes:keywords>
			<itunes:author></itunes:author>
			<itunes:owner>
				<itunes:email>tofinha@gmail.com</itunes:email>
				<itunes:name></itunes:name>
			</itunes:owner>
			<itunes:image href="" />
			<image>
				<url></url>
				<title>Tofinha ColdFusion Developer English</title>
				<link>http://www.tofinha.com.br/blog/index.cfm</link>
			</image>
			<itunes:explicit>no</itunes:explicit>
			
			<item>
				<title>Cumulative Hot Fix 4 for 8.0.1</title>
				<link>http://www.tofinha.com.br/blog/index.cfm/2009/12/4/Cumulative-Hot-Fix-4-for-801</link>
				<description>
				
				&lt;p&gt;A new cumulative hot fix for ColdFusion 8.0.1 has been released. &lt;/p&gt;
&lt;p&gt; Details and download may be found here: &lt;a href=&quot;http://kb2.adobe.com/cps/529/cpsid_52915.html&quot;&gt;http://kb2.adobe.com/cps/529/cpsid_52915.html&lt;/a&gt;&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>TechNote</category>				
				
				<category>Security</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Fri, 04 Dec 2009 11:32:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/blog/index.cfm/2009/12/4/Cumulative-Hot-Fix-4-for-801</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			
			<item>
				<title>HackMyCF, ColdFusion Server Security Scanner</title>
				<link>http://www.tofinha.com.br/blog/index.cfm/2009/10/24/HackMyCF-ColdFusion-Server-Security-Scanner</link>
				<description>
				
				&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.petefreitag.com/item/721.cfm&quot; title=&quot;ColdFusion Server Security Scanner&quot; target=&quot;_blank&quot;&gt;Pete Freitag&lt;/a&gt;&lt;/strong&gt; has launched &lt;a href=&quot;http://hackmycf.com/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;HackMyCF&lt;/strong&gt;&lt;/a&gt;, a site that can test your ColdFusion servers for security holes, missing hotfixes and patches, and more. Highly recommended!&lt;/p&gt;
&lt;div align=&quot;center&quot;&gt; &lt;a href=&quot;http://hackmycf.com/&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://www.petefreitag.com/images/blog/hackmycf-email.png&quot; alt=&quot;hack my cf email report&quot; border=&quot;0&quot; title=&quot;hack my cf email report&quot;&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
				</description>
				
				<category>Security</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Sat, 24 Oct 2009 00:16:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/blog/index.cfm/2009/10/24/HackMyCF-ColdFusion-Server-Security-Scanner</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			
			<item>
				<title>Adobe Releases Hotfix for FCKEditor Security Issue</title>
				<link>http://www.tofinha.com.br/blog/index.cfm/2009/7/9/Adobe-Releases-Hotfix-for-FCKEditor-Security-Issue</link>
				<description>
				
				&lt;p&gt;Adobe has released an official hot fix for the FCK Editor issue you may have heard about lately.  You can &lt;strong&gt;&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-09.html&quot; target=&quot;_blank&quot;&gt;read about and download the hotfix directly from Adobe&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>Security</category>				
				
				<pubDate>Thu, 09 Jul 2009 12:04:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/blog/index.cfm/2009/7/9/Adobe-Releases-Hotfix-for-FCKEditor-Security-Issue</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			
			<item>
				<title>ColdFusion 8 FCKeditor Vulnerability</title>
				<link>http://www.tofinha.com.br/blog/index.cfm/2009/7/4/ColdFusion-8-FCKeditor-Vulnerability</link>
				<description>
				
				&lt;p&gt;There is a critical point in FCKeditor, who was announced some time, when detected in connectors ASP and PHP.&lt;/p&gt;
&lt;p&gt;PHP - &lt;a href=&quot;http://www.acunetix.com/vulnerabilities/GeekLog-v1.4.0-FckEditor-.htm&quot;&gt;&lt;strong&gt;GeekLog v1.4.0 FckEditor File Upload Security Vulnerability&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ASP - &lt;a href=&quot;https://strikecenter.bpointsys.com/articles/permalink?title=exploiting-iis-via-htmlencode-ms08-006&amp;month=02&amp;year=2008&amp;day=13&quot;&gt;&lt;strong&gt;Exploiting IIS via HTMLEncode (MS08-006)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Now this vulnerability was detected in the version 8.0.1 of ColdFusion,  the version 8.0 apparently does not suffer of this failure, but it is  worth check.&lt;/p&gt;
&lt;p&gt;The solutions:&lt;br&gt;
1) Disable filemanager. In &lt;strong&gt;&quot;CFIDE\scripts\ajax\FCKeditor\editor\filemanager\connectors\cfm\config.cfm&quot;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Config.Enabled = &lt;span style=&quot;color:#F00;&quot;&gt;false;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;2) To be completely safe, delete the entire filemanager directory  found under &quot;CFIDE\scripts\ajax\FCKeditor\editor&quot;. The embedded version  of FCKeditor for CF doesn&apos;t and really shouldn&apos;t use this feature. So  removing those files completely is the safest thing to do. Be mindful  that updates to CF might re-introduce those files and naturally re-open  the problem.&lt;/p&gt;
&lt;p&gt;More informations in:&lt;/p&gt;
&lt;a href=&quot;http://groups.google.com/group/cfbrasil/browse_thread/thread/1f0957d4df6fb612&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Problem safety serious in CF 8.01 (by Alex Hubner - CFBRAZIL)&lt;/strong&gt;&lt;/a&gt;
&lt;p&gt;&lt;a href=&quot;http://www.codfusion.com/blog/post.cfm/cf8-and-fckeditor-security-threat&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;CF8 and FCKEditor Security threat ( by John Mason)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.petefreitag.com/item/704.cfm&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;ColdFusion 8 FCKeditor Vulnerability ( by Pete Freitag)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p style=&quot;border:dotted 1px #069; background-color:#75b3e2; padding:5px;&quot;&gt;Update: read this post by the Adobe Product Security Incident Response Team regarding a  security issue caused by the FCKEditor included with ColdFusion 8:&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html&quot; style=&quot;color:#000;&quot; target=&quot;_blank&quot;&gt;Adobe Product Security Incident Response Team (PSIRT): Potential ColdFusion security issue&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>Security</category>				
				
				<pubDate>Sat, 04 Jul 2009 13:10:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/blog/index.cfm/2009/7/4/ColdFusion-8-FCKeditor-Vulnerability</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			</channel></rss>