CF10 and File Extensions Request Filtering


there organizations disa/dod require when using iis 7/7.5/8 set request filtering -> file name extensions -> edit features settings -> allow unlisted file name extensions disabled.  forces add every single file extension type needed allow entry in file names extensions section them run.  wanted make post because it's easy miss 1 of items required result in system not functioning expected.  there several obvious ones without them allowed cfide not load @ all.  if miss .js item run issues.  system continuously inform password invalid when not.  unlike of others lack of .js not show visually except menu items pre-colapsed , can't login via username/password making have bypass security.

 

here list of items needed cfide running under locked down scenario.

 

  • . (just period itself, required allow default documents load)
  • .cfc
  • .cfm
  • .dll
  • .gif
  • .jpg
  • .js

interesting tip. sharing.

 

 

 

/charlie



More discussions in ColdFusion Server Administration


adobe

Comments

Popular posts from this blog

How to set the order of FAQs instead of alphabetical

Thread: Get UK Keyboard working

how do I change the e-mail address for my merchant account