
61
Setting
Default
Recommendation
Description
Missing Template
Handler
Blank or
/CFIDE/administra
tor/templates/miss
ing_template_erro
r.cfm
Specified
The missing template handler HTML
should be equivalent to the 404 error
handler specified on your web
server.
The default missing template
handler allows a potential attacker to
get a rough idea of the ColdFusion
version in use.
Site-wide Error
Handler
Blank or
/CFIDE/administra
tor/templates/secu
re_profile_error.cf
m
Specified
The default site-wide error handler
may expose information about the
cause of exceptions. Specify a
custom siite-wide error handler that
discloses the same generic
message to the user for all
exceptions. Be sure to log the actual
exception.
Maximum number
of POST request
parameters
100
100 or lower
Set this to the maximum number of
form fields you have on any given
page. Allowing too many form fields
may allow for a DOS attack known
as HashDOS.
Summary of Contents for 38043740 - ColdFusion Standard - Mac
Page 5: ...5 ...
Page 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Page 26: ...26 ...
Page 33: ...33 ...
Page 38: ...38 ...