security - Do I need a ColdFusion Administrator Password if the Admin Application is only available locally? -


i have several windows 2003 web servers running coldfusion 8 wherein coldfusion administrator application running own iis website accessible via 127.0.0.1 (localhost).

is there need password in application if users remote access server administrators?

one argue don't need one. if hacker can remote server can delete iis web site before doing via coldfusion administrator. said, may want play safe , have password in case coldfusion administrator leak outside world.

you can run hackmycf.com against site cf admin indeed locked down. if message "your scanner says our coldfusion administrator publicly accessible" may worth following advice outlined here. http://www.petefreitag.com/item/750.cfm


Comments

Popular posts from this blog

How to remove text and logo OR add Overflow on Android ActionBar using AppCompat on API 8? -

html - How to style widget with post count different than without post count -

url rewriting - How to redirect a http POST with urlrewritefilter -