<?xml version="1.0" encoding="utf-8"?>
			
			<rss version="2.0" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:cc="http://web.resource.org/cc/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

			<channel>
			<title>Tofinha ColdFusion Developer - Seguran&#xe7;a</title>
			<link>http://www.tofinha.com.br/index.cfm</link>
			<description>Blog para divulgar meus trabalhos e o ColdFusion pelo Brasil afora</description>
			<language>pt-br</language>
			<pubDate>Thu, 09 Sep 2010 07:07:59 -0300</pubDate>
			<lastBuildDate>Fri, 04 Dec 2009 11:10:00 -0300</lastBuildDate>
			<generator>BlogCFC</generator>
			<docs>http://blogs.law.harvard.edu/tech/rss</docs>
			<managingEditor>tofinha@gmail.com</managingEditor>
			<webMaster>tofinha@gmail.com</webMaster>
			<itunes:subtitle></itunes:subtitle>
			<itunes:summary></itunes:summary>
			<itunes:category text="Technology" />
			<itunes:category text="Technology">
				<itunes:category text="Podcasting" />
			</itunes:category>
			<itunes:category text="Technology">
				<itunes:category text="Tech News" />
			</itunes:category>
			<itunes:keywords></itunes:keywords>
			<itunes:author></itunes:author>
			<itunes:owner>
				<itunes:email>tofinha@gmail.com</itunes:email>
				<itunes:name></itunes:name>
			</itunes:owner>
			<itunes:image href="" />
			<image>
				<url></url>
				<title>Tofinha ColdFusion Developer</title>
				<link>http://www.tofinha.com.br/index.cfm</link>
			</image>
			<itunes:explicit>no</itunes:explicit>
			
			<item>
				<title>Hot Fix 4 para o ColdFusion 8.0.1</title>
				<link>http://www.tofinha.com.br/index.cfm/2009/12/4/Hot-Fix-4-para-o-ColdFusion-801</link>
				<description>
				
				&lt;p&gt;Disponibilizado o Cumulative Hot Fix 4 for ColdFusion 8.0.1. Ao que parece foi inclu&amp;iacute;dos itens de seguran&amp;ccedil;a. Estranho pois, n&amp;atilde;o &amp;eacute; costume agregar itens de seguran&amp;ccedil;a em CHFs.&lt;/p&gt;
&lt;p&gt;De qualquer forma, atualiza&amp;ccedil;&amp;atilde;o mais do que recomendada. Mais detalhes e download no link abaixo.&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://kb2.adobe.com/cps/529/cpsid_52915.html&quot; target=&quot;_blank&quot;&gt;http://kb2.adobe.com/cps/529/cpsid_52915.html&lt;/a&gt;&lt;br&gt;
&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>Seguran&#xe7;a</category>				
				
				<category>TechNote</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Fri, 04 Dec 2009 11:10:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/index.cfm/2009/12/4/Hot-Fix-4-para-o-ColdFusion-801</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			
			<item>
				<title>Adobe Releases Hotfix for FCKEditor Security Issue</title>
				<link>http://www.tofinha.com.br/index.cfm/2009/7/9/Adobe-Releases-Hotfix-for-FCKEditor-Security-Issue</link>
				<description>
				
				&lt;p&gt;A Adobe liberou ontem oficialmente o hot fix para o problema de seguran&#xe7;a envolvendo o  FCK Editor.&lt;/p&gt;
&lt;p&gt;Mais informa&#xe7;&#xf5;es em &lt;strong&gt;&lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-09.html&quot; target=&quot;_blank&quot;&gt;Hotfix available for potential ColdFusion 8 input sanitization issue&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>Seguran&#xe7;a</category>				
				
				<pubDate>Thu, 09 Jul 2009 12:20:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/index.cfm/2009/7/9/Adobe-Releases-Hotfix-for-FCKEditor-Security-Issue</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			
			<item>
				<title>Seguran&#xe7;a ColdFusion - FCKEditor</title>
				<link>http://www.tofinha.com.br/index.cfm/2009/7/4/Segurana-ColdFusion--FCKEditor</link>
				<description>
				
				&lt;p&gt;Depois de detectado falhas de seguran&amp;ccedil;a nos conectores para upload ASP e PHP do FCKeditor, e j&amp;aacute;  anunciado algum tempo, agora surge a informa&amp;ccedil;&amp;atilde;o de que esta falha est&amp;aacute; na vers&amp;atilde;o 8.01 do ColdFusion.&lt;/p&gt;
&lt;p&gt;PHP - &lt;a href=&quot;http://www.acunetix.com/vulnerabilities/GeekLog-v1.4.0-FckEditor-.htm&quot;&gt;&lt;strong&gt;GeekLog v1.4.0 FckEditor File Upload Security Vulnerability&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ASP - &lt;a href=&quot;https://strikecenter.bpointsys.com/articles/permalink?title=exploiting-iis-via-htmlencode-ms08-006&amp;month=02&amp;year=2008&amp;day=13&quot;&gt;&lt;strong&gt;Exploiting IIS via HTMLEncode (MS08-006)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Na vers&amp;atilde;o 8.0, esta falha aparentemente n&amp;atilde;o ocorre pois este recurso vinha desabilitado por padr&amp;atilde;o e n&amp;atilde;o se sabe o porque na vers&amp;atilde;o 8.0.1 vir habilitada.&lt;/p&gt;
&lt;p&gt;Alex Hubner criou um post mais do que bem vindo na lista CFBrasil e vale a pena conferir.&lt;/p&gt;
&lt;a href=&quot;http://groups.google.com/group/cfbrasil/browse_thread/thread/1f0957d4df6fb612&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;Problema de seguran&amp;ccedil;a s&amp;eacute;rio no CF 8.01 (by Alex Hubner - CFBRAZIL)&lt;/strong&gt;&lt;/a&gt;
&lt;p&gt;Al&amp;eacute;m disso outros sites fornecem mais informa&amp;ccedil;&amp;otilde;es de como se prevenir.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.codfusion.com/blog/post.cfm/cf8-and-fckeditor-security-threat&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;CF8 and FCKEditor Security threat ( by John Mason)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.petefreitag.com/item/704.cfm&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;ColdFusion 8 FCKeditor Vulnerability ( by Pete Freitag)&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style=&quot;border:dotted 1px #069; background-color:#75b3e2; padding:5px;&quot;&gt;Update: Post do blog, Adobe Product Security Incident Response Team:&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html&quot; style=&quot;color:#000;&quot; target=&quot;_blank&quot;&gt;Adobe Product Security Incident Response Team (PSIRT): Potential ColdFusion security issue&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
				</description>
				
				<category>ColdFusion 8</category>				
				
				<category>Seguran&#xe7;a</category>				
				
				<pubDate>Sat, 04 Jul 2009 13:35:00 -0300</pubDate>
				<guid>http://www.tofinha.com.br/index.cfm/2009/7/4/Segurana-ColdFusion--FCKEditor</guid>
				<author>
				<name>Tofinha</name>
				</author>
				
			</item>
			</channel></rss>