SunQuest
           ColdFusion Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsProgramming Languages - MoreColdFusion Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old July 28th, 2004, 02:56 PM
Mudflap4874 Mudflap4874 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 116 Mudflap4874 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 13 h 56 m 58 sec
Reputation Power: 4
CFMX and IIS 6 Virtual Directories

Can anyone provide information on why ColdFusion creates virtual directories for the CFIDE and CFDOCS folders under each IIS website on the server?

Is removing the virtual directories through IIS a logical step to make?

Is there a major security risk having a CFIDE folder under each website? If the site uses CFFORM, isn't it necessary to include the CFIDE folder so that the javascript reference is available to perform the validation of the tag?

Sorry to throw out all of these questions in one post, but these all stem from an issue I am having with a client.

Thanks in advance - I appreciate any information provided.

Reply With Quote
  #2  
Old July 28th, 2004, 04:32 PM
kiteless kiteless is offline
Moderator
Dev Shed Expert (3500 - 3999 posts)
 
Join Date: Jun 2002
Location: Raleigh, NC
Posts: 3,627 kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Week 4 Days 10 h 8 m 55 sec
Reputation Power: 53
On a production server you probably want to remove these (copy them out of the web root). Keep in mind that once they are gone you won't have access to the CF administrator until you move them back.
__________________
Ask if you have a question, but also help answer questions that you have knowledge of! Thanks, Brian.
How to Post a Question in the Forums

Reply With Quote
  #3  
Old July 29th, 2004, 08:36 AM
Mudflap4874 Mudflap4874 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 116 Mudflap4874 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 13 h 56 m 58 sec
Reputation Power: 4
I do understand that the directories should not be in a production environment.

However, there are CFIDE folders that appear under each website that have cfform.js and wddx.js files in them. Is having this folder with those scripts under the website a major security risk?

Is it logical to remove the CFIDE virtual directory through IIS 6?

thanks

Reply With Quote
  #4  
Old July 29th, 2004, 08:59 AM
kiteless kiteless is offline
Moderator
Dev Shed Expert (3500 - 3999 posts)
 
Join Date: Jun 2002
Location: Raleigh, NC
Posts: 3,627 kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Week 4 Days 10 h 8 m 55 sec
Reputation Power: 53
The javascripts are not a security risk, they are just there to let you serialize WDDX data into javascript arrays, and to provide form validation.

If you want to be thorough, you can delete them from IIS itself. Remember again though that once you do this, you won't have access to the administrator interface any more. You'll have to move the folders back and recreate the virtual directories again if you need to access the administrator.

Reply With Quote
  #5  
Old July 29th, 2004, 09:06 AM
Mudflap4874 Mudflap4874 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 116 Mudflap4874 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 13 h 56 m 58 sec
Reputation Power: 4
Thanks for your reply. How do you delete them from IIS?

Deleting them caused javascript errors on our site because the CFFORM tag could not reference the cfform.js file. If there are no risks, then deleting the virtual directories via IIS is not necessary, correct?

Reply With Quote
  #6  
Old July 29th, 2004, 09:21 AM
kiteless kiteless is offline
Moderator
Dev Shed Expert (3500 - 3999 posts)
 
Join Date: Jun 2002
Location: Raleigh, NC
Posts: 3,627 kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Week 4 Days 10 h 8 m 55 sec
Reputation Power: 53
Well yes, if you are using the form validation in cfform then you'll have to leave those virtual directories intact. I was under the impression that you wern't using them and wanted to get rid of them.

The only directories that you need to be concerned about are the cf administrator directories and the samples. The samples should definitely be deleted. The CF administrator can be deleted, or you can secure it using Windows permissions and then anyone who wants to get to that directory must log in with an authorized Windows user name and pw as well. It's up to you, depending on which is easier for you to deal with.

Reply With Quote
  #7  
Old July 29th, 2004, 09:37 AM
Mudflap4874 Mudflap4874 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 116 Mudflap4874 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 13 h 56 m 58 sec
Reputation Power: 4
I apologize for not making clear the cfform validation is in use.

Would you be able to go into a little more detail about securing the CF Administrator using Windows permissions? I am not a server administrator (as you could probably tell and any additional information would be very helpful.

thanks

Reply With Quote
  #8  
Old July 29th, 2004, 09:55 AM
kiteless kiteless is offline
Moderator
Dev Shed Expert (3500 - 3999 posts)
 
Join Date: Jun 2002
Location: Raleigh, NC
Posts: 3,627 kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level)kiteless User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Week 4 Days 10 h 8 m 55 sec
Reputation Power: 53
In Windows explorer, you can right click on the directory and choose properties, and then one of the tabs should be security. You can assign permissions through this interface. Just be careful about what groups/users you authorize. If you have access to the server and you don't think you'll need to change much in the cf administrator once it is set up, you may find that just copying that whole administrator directory out of the web root is an easier solution. You can just copy it back when you need to make changes.

Reply With Quote
  #9  
Old July 29th, 2004, 10:29 AM
Mudflap4874 Mudflap4874 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 116 Mudflap4874 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 13 h 56 m 58 sec
Reputation Power: 4
Thank you!

You have provided very good information to me. All is very helpful.

Thanks for your time.

Reply With Quote
Reply

Viewing: Dev Shed ForumsProgramming Languages - MoreColdFusion Development > CFMX and IIS 6 Virtual Directories


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway