Wednesday, May 23, 2012    
Home My Books Blog ColdFusion About Me Back    

Calendar
<< Oct 2009 >>
S M T W T F S
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
             

Search

Categories
 • Acrobat (5) [RSS]
 • Adobe (117) [RSS]
 • AdobeMAX06 (45) [RSS]
 • AdobeMAX07 (59) [RSS]
 • AdobeMAX08 (66) [RSS]
 • AdobeMAX09 (39) [RSS]
 • AdobeMAX10 (34) [RSS]
 • AdobeMAX11 (28) [RSS]
 • AdobeMAX13 (1) [RSS]
 • AIR (299) [RSS]
 • Appearances (217) [RSS]
 • Books (86) [RSS]
 • CFEclipse (15) [RSS]
 • Cloud (1) [RSS]
 • ColdFusion (1483) [RSS]
 • ColdFusion Builder (23) [RSS]
 • Data Services (43) [RSS]
 • Fish Tank (5) [RSS]
 • Flash (368) [RSS]
 • Flex (565) [RSS]
 • Home Automation (5) [RSS]
 • HTML5 (36) [RSS]
 • JavaScript (3) [RSS]
 • Jobs (133) [RSS]
 • jQuery (15) [RSS]
 • JRun (14) [RSS]
 • Labs (63) [RSS]
 • LiveCycle (37) [RSS]
 • MAX (285) [RSS]
 • Mobile (257) [RSS]
 • PhoneGap (17) [RSS]
 • Regular Expressions (19) [RSS]
 • RIA (21) [RSS]
 • SQL (45) [RSS]
 • Stuff (554) [RSS]
 • Tips (CF Studio) (80) [RSS]
 • Tips (CF) (795) [RSS]
 • Tips (Dreamweaver) (91) [RSS]
 • Tips (Flex Builder) (2) [RSS]
 • Using CF (167) [RSS]

Other BLOGs
 • Charlie Arehart
 • Lee Brimelow
 • Ray Camden
 • Christophe Coenraets
 • Sean Corfield
 • Mihai Corlan
 • Cornel Creanga
 • Mark Doherty
 • John Dowdell
 • Danny Dura
 • Enrique Duvos
 • Steven Erat
 • Kevin Hoyt
 • Serge Jespers
 • Adam Lehman
 • Duane Nickull
 • Miti Pricope
 • Andrew Shorten
 • Ryan Stewart
 • James Ward
 • Greg Wilson
 • Full As A Goog

RSS Feeds
 • Feed
 • Subscribe

Join my mailing list and find out about new books and other topics of interest.

Thoughts, ideas, tips, musings, and pontifications (not necessarily in that order) by Ben Forta ...
NOTE: This is my personal blog, and the opinions and statements voiced here are my own.

Viewing By Entry / Main
October 22, 2009

Pete Freitag Launches HackMyCF

Pete Freitag has launched HackMyCF, a site that can test your ColdFusion servers for security holes, missing hotfixes and patches, and more. You simply provide a server host name and e-mail address, and the app runs a scan and e-mails you a report. Highly recommended!

Comments
Very cool. However, is there anything done to verify that a person owns the domain that they type in? Or will this just be a tremendously valuable tool for hackers to have someone else find the vulnerabilities in a potential target site?
# Posted By Matthew Reinbold | 10/22/09 2:53 PM
Disregard that last comment - I see now that the address the report is emailed to needs to be from the same domain as the site to be checked for vulnerabilities.
# Posted By Matthew Reinbold | 10/22/09 2:57 PM
Yes but the question at the heart of the matter is how secure is Pete's Server?

*Is it on a shared server
*Who has access to the information
*How much information is collected

Looks like a great service and would consider using it / paying for it but need more information inside the Terms / Privacy.
# Posted By Nathan Kondra | 10/26/09 6:43 PM

  © Copyright 1997-2009 Ben Forta, All Rights Reserved