Adobe 38043740 - ColdFusion Standard - Mac Manual page 61

Server lockdown guide
Hide thumbs Also See for 38043740 - ColdFusion Standard - Mac:
Table of Contents

Advertisement

Setting
Default
Missing Template
Blank or
Handler
/CFIDE/administra
tor/templates/miss
ing_template_erro
r.cfm
Site-wide Error
Blank or
Handler
/CFIDE/administra
tor/templates/secu
re_profile_error.cf
m
Maximum number
100
of POST request
parameters
Recommendation
Description
Specified
The missing template handler HTML
should be equivalent to the 404 error
handler specified on your web
server.
The default missing template
handler allows a potential attacker to
get a rough idea of the ColdFusion
version in use.
Specified
The default site-wide error handler
may expose information about the
cause of exceptions. Specify a
custom siite-wide error handler that
discloses the same generic
message to the user for all
exceptions. Be sure to log the actual
exception.
100 or lower
Set this to the maximum number of
form fields you have on any given
page. Allowing too many form fields
may allow for a DOS attack known
as HashDOS.
61

Advertisement

Table of Contents
loading

This manual is also suitable for:

Coldfusion 10

Table of Contents