<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ricardo Parente&#039;s Blog &#187; Security</title>
	<atom:link href="http://ricardo.parente.us/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://ricardo.parente.us</link>
	<description>ColdFusion Developers Network</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:13:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Google Chrome Releases</title>
		<link>http://ricardo.parente.us/2011/08/google-chrome-releases/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-chrome-releases</link>
		<comments>http://ricardo.parente.us/2011/08/google-chrome-releases/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 13:45:17 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Google Chrome]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=6119</guid>
		<description><![CDATA[The Google Chrome team is pleased to announce the arrival of Chrome 13.0.782.107 to the Stable Channel for Windows, Mac, Linux, and Chrome Frame.  Spanning 5200+ revisions, Chrome 13 contains some exciting new features like Instant Pages prerendering technology. To find out about other new features, check out the Official Chrome Blog. Excerpted from http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html]]></description>
			<content:encoded><![CDATA[<blockquote>
<div>The Google Chrome team is pleased to announce the arrival of Chrome 13.0.782.107 to the Stable Channel for Windows, Mac, Linux, and Chrome Frame.  Spanning 5200+ revisions, Chrome 13 contains some exciting new features like <a title="http://chrome.blogspot.com/2011/06/faster-than-fast.html" href="http://chrome.blogspot.com/2011/06/faster-than-fast.html" target="_blank">Instant Pages</a> prerendering technology. To find out about other new features, check out the <a title="http://chrome.blogspot.com/2011/08/instant-pages-on-google-chrome.html" href="http://chrome.blogspot.com/2011/08/instant-pages-on-google-chrome.html" target="_blank">Official Chrome Blog</a>.</div>
</blockquote>
<p>Excerpted from <a title="http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html" href="http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html" target="_blank">http://googlechromereleases.blogspot.com/2011/08/stable-channel-update.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/08/google-chrome-releases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ColdFusion Security Hotfix &#124; APSB11-14, APSB11-15</title>
		<link>http://ricardo.parente.us/2011/07/coldfusion-security-hotfix-apsb11-14-apsb11-15/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=coldfusion-security-hotfix-apsb11-14-apsb11-15</link>
		<comments>http://ricardo.parente.us/2011/07/coldfusion-security-hotfix-apsb11-14-apsb11-15/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 17:02:38 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Hot Fix]]></category>
		<category><![CDATA[hotfix]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=6105</guid>
		<description><![CDATA[ColdFusion 9.0.1, ColdFusion 9, ColdFusion 8.0.1, and ColdFusion 8 are affected with vulnerabilities mentioned in the security bulletins APSB11-14 and APSB11-15. This TechNote provides fixes for the security issues mentioned in both the bulletins along with the installation instructions. Source: http://kb2.adobe.com/cps/907/cpsid_90784.html &#160;]]></description>
			<content:encoded><![CDATA[<p>ColdFusion 9.0.1, ColdFusion 9, ColdFusion 8.0.1, and ColdFusion 8 are affected with vulnerabilities mentioned in the security bulletins <a title="http://www.adobe.com/support/security/bulletins/apsb11-14.html" href="http://www.adobe.com/support/security/bulletins/apsb11-14.html" target="_blank">APSB11-14</a> and <a title="http://www.adobe.com/support/security/bulletins/apsb11-15.html" href="http://www.adobe.com/support/security/bulletins/apsb11-15.html" target="_blank">APSB11-15</a>. This TechNote provides fixes for the security issues mentioned in both the bulletins along with the installation instructions.</p>
<p>Source: <a title="http://kb2.adobe.com/cps/907/cpsid_90784.html" href="http://kb2.adobe.com/cps/907/cpsid_90784.html" target="_blank">http://kb2.adobe.com/cps/907/cpsid_90784.html</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/07/coldfusion-security-hotfix-apsb11-14-apsb11-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ColdFusion MeetUp: Using jQuery Mobile for your Next Web Application, with Andy Matthews</title>
		<link>http://ricardo.parente.us/2011/04/coldfusion-meetup-using-jquery-mobile-for-your-next-web-application-with-andy-matthews-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=coldfusion-meetup-using-jquery-mobile-for-your-next-web-application-with-andy-matthews-2</link>
		<comments>http://ricardo.parente.us/2011/04/coldfusion-meetup-using-jquery-mobile-for-your-next-web-application-with-andy-matthews-2/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 02:47:56 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[MeetUp]]></category>
		<category><![CDATA[Mobile OS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=5964</guid>
		<description><![CDATA[Our 6pm (US ET) talk on Thursday Apr 28 will be part two of two in the day from different speakers, but both on JQuery Mobile. Second up at 6pm will be &#8220;Using jQuery Mobile for your Next Web Application&#8221;, with Andy Matthews. At noon Ray Camden will have offered a preliminary talk (details in [...]]]></description>
			<content:encoded><![CDATA[<p>Our 6pm (US ET) talk on Thursday Apr 28 will be part two of two in the day from different speakers, but both on JQuery Mobile. Second up at 6pm will be &#8220;Using jQuery Mobile for your Next Web Application&#8221;, with Andy Matthews. At noon Ray Camden will have offered a preliminary talk (details in its separate announcement).</p>
<p>TOPIC DESCRIPTION: (provided by the speaker)</p>
<p>jQuery is everywhere. It&#8217;s a JavaScript framework, it&#8217;s an application development framework, and now it&#8217;s a mobile framework. Built around the rules of progressive enhancement jQuery Mobile is a mobile application framework for the next version of mobile optimized websites. In this session Andy will discuss background research done by the jQuery Mobile team, concepts used in the development of jQuery Mobile, and of course lots of code and demos. If you&#8217;re on the fence about whether to use jQuery Mobile, this session will answer all your questions.</p>
<p>MEETING URL: <a title="http://experts.acrobat.com/cfmeetup/" href="http://experts.acrobat.com/cfmeetup/" target="_blank">http://experts.acrobat.com/cfmeetup/</a><br />
DURATION: Approx. 1 hour<br />
Meeting will be recorded. URL will be posted after meeting at <a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">recordings.coldfusionmeetup.com</a></p>
<p><span id="more-5964"></span></p>
<p>SPEAKER: (provided by the speaker)</p>
<p>I have been working as a web and application developer for 12 years, with experience in a wide range of industries, and a skillset which includes graphic design, programming, business strategy and planning, and marketing. Throughout my career I have been privileged to work on projects which interfaced with industry giants such as Craigslist, written code that allowed Enterprise level sales teams to quickly and efficiently build presentations for their clients, and stayed current on trends in the marketplace by helping previous employers transition to newer, more effective, coding habits and standards. I have received certifications, spoken to users at conferences around the country, and developed software for the open source community.</p>
<p>WHEN: Thurs. Apr 28, 6:00pm US ET (UTC/GMT-4)</p>
<p>What time is that for you? The following link shows . Here&#8217;s that shows the time as US ET, and lets you choose your city from the list offered to see what time that is in your own timezone.</p>
<p>RECORDING: As always, the meeting will be recorded, and the recording URL will be posted after the meeting at <a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">http://recordings.coldfusionmeetup.com</a>.</p>
<p>DOWNLOADABLE RECORDINGS:<br />
In addition to the streaming recording posted immediately after the meeting, we now also post downloadable recordings (FLV, MP3, MP4, and WMV) usually within a few days after the meeting, also offered as a link from the recordings page.</p>
<p>LOGGING IN: When you login to the Connect room (the <a title="http://experts.acrobat.com/cfmeetup" href="http://experts.acrobat.com/cfmeetup" target="_blank">experts.acrobat.com/cfmeetup</a> link above) to view the meeting, PLEASE USE THE &#8220;LOGIN AS GUEST&#8221; option, and USE YOUR NAME, but do NOT attempt to use your <a title="http://meetup.com/" href="http://meetup.com/" target="_blank">meetup.com</a> username/password or any Connect account. Just sign in as a guest.</p>
<p>RSVP, but only if coming: We do appreciate folks RSVPing if they plan to come (using the link on this email or at the meetup site), though it&#8217;s not mandatory and it&#8217;s not a commitment. But there&#8217;s no need to RSVP if you can&#8217;t make it let alone explain why you can&#8217;t. With over 2,400 members, no worries. <img src='http://ricardo.parente.us/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>FEEDBACK/MEETING DISCUSSION: Members will receive an email after the meeting or can click a link on the event page to offer. Note also the meeting-specific discussion area there at the bottom, in addition to the one-chance feedback feature on the right. Feel free to engage in discussions about the meeting topic.</p>
<p>ADD THIS TO YOUR CALENDAR: Want to add this event to your own personal calendar? After logging in here, you&#8217;ll see an option at the top of the event page, just below the event title, saying, &#8220;Add to my calendar&#8221;, which offers calendar downloads for Outlook, iCal, Google, and Yahoo calendars. (Note that the calendar entry created will show the event taking 2 hours. That&#8217;s a default that <a title="http://meetup.com/" href="http://meetup.com/" target="_blank">meetup.com</a> has chosen, which I can&#8217;t change. The meetings are generally about an hour, though often go as much as 30-45 minutes longer with Q&amp;A and chat.)</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/04/coldfusion-meetup-using-jquery-mobile-for-your-next-web-application-with-andy-matthews-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ColdFusion 8 &amp; 9 Included on Oracle Security Alert CVE-2010-4476</title>
		<link>http://ricardo.parente.us/2011/03/coldfusion-8-9-included-on-oracle-security-alert-cve-2010-4476/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=coldfusion-8-9-included-on-oracle-security-alert-cve-2010-4476</link>
		<comments>http://ricardo.parente.us/2011/03/coldfusion-8-9-included-on-oracle-security-alert-cve-2010-4476/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 20:24:17 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Alert]]></category>
		<category><![CDATA[CVE-2010-4476]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=5713</guid>
		<description><![CDATA[The Oracle security Alert CVE-2010-4476 affects ColdFusion versions 9.0.1, 9.0, 8.0.1, and 8.0. Adobe recommends updating the Java (JDK/JRE) for all ColdFusion server versions as per Oracle’s Java update instructions. Information about the security vulnerability along with the fix is provided at the following link. Oracle just released a Security Alert with a fix for the [...]]]></description>
			<content:encoded><![CDATA[<p>The Oracle security Alert CVE-2010-4476 affects ColdFusion versions 9.0.1, 9.0, 8.0.1, and 8.0.</p>
<p>Adobe recommends updating the Java (JDK/JRE) for all ColdFusion  server versions as per Oracle’s Java update instructions. Information  about the security vulnerability along with the fix is provided at the  following link.</p>
<p>Oracle just released a <a title="http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html" href="http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html" target="_blank">Security Alert with a fix for the vulnerability CVE-2010-4476</a>,  which affects Oracle Java SE and Oracle Java For Business.  This  vulnerability is present in Java running on servers as well as  standalone Java desktop applications.  Its successful exploitation by a  malicious attacker can result in a complete denial of service for the  affected servers.</p>
<p>Read the full articles on <a title="http://kb2.adobe.com/cps/894/cpsid_89440.html" href="http://kb2.adobe.com/cps/894/cpsid_89440.html" target="_blank"><strong>Adobe&#8217;s</strong></a> and <a title="http://blogs.oracle.com/security/2011/02/security_alert_for_cve-2010-44.html" href="http://blogs.oracle.com/security/2011/02/security_alert_for_cve-2010-44.html" target="_blank"><strong>Oracle&#8217;s</strong></a> sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/03/coldfusion-8-9-included-on-oracle-security-alert-cve-2010-4476/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MeetUp Security: Hiding Info. from Individuals Not Authorized To See It w/ Jim Harris</title>
		<link>http://ricardo.parente.us/2011/03/security-hiding-info-from-individuals-not-authorized-to-see-it-w-jim-harris/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-hiding-info-from-individuals-not-authorized-to-see-it-w-jim-harris</link>
		<comments>http://ricardo.parente.us/2011/03/security-hiding-info-from-individuals-not-authorized-to-see-it-w-jim-harris/#comments</comments>
		<pubDate>Sun, 06 Mar 2011 00:49:36 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[MeetUp]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Seminars]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=5460</guid>
		<description><![CDATA[Our 12pm (US ET) talk on Thursday Mar 17 will be &#8220;Security: Hiding Information from Individuals Not Authorized To See It&#8221;, with Jim Harris. TOPIC DESCRIPTION: (provided by the speaker) During this session you will see how to restrict search results and hide records based on the security or authorization level of the people using your [...]]]></description>
			<content:encoded><![CDATA[<p>Our 12pm <strong>(US ET)</strong> talk on Thursday Mar 17 will be &#8220;Security: Hiding Information from Individuals Not Authorized To See It&#8221;, with Jim Harris.</p>
<p><strong>TOPIC DESCRIPTION:</strong> (provided by the speaker)</p>
<p>During this session you will see how to restrict search results and hide records based on the security or authorization level of the people using your application(s). The method is simple to implement and very user friendly.</p>
<p><span id="more-5460"></span><!--more--></p>
<p><strong>MEETING URL: <a title="http://experts.acrobat.com/cfmeetup/" href="http://experts.acrobat.com/cfmeetup/" target="_blank">http://experts.acrobat.com/cfmeetup/</a></strong><br />
DURATION: Approx. 1 hour<br />
<strong>Meeting will be recorded.</strong> URL will be posted after meeting at<a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">http://recordings.coldfusionmeetup.com</a></p>
<p><strong>SPEAKER:</strong> (provided by the speaker)</p>
<p>Jim Harris is a retired U.S. Army Signal Corps veteran who has been using ColdFusion to create dynamic web applications since the mid &#8217;80s.  He holds a Masters Degree in Computer Science from Duke University. He is currently employed by LT Online Corporation out of Long Island NY as their Vice President of Application Development. Jim&#8217;s website is <a title="http://cf-toolbox.com/" href="http://cf-toolbox.com/" target="_blank">CF-ToolBox.com</a>.</p>
<p><strong>WHEN:</strong> Thurs. Mar 17, 12:00pm <strong>US ET (UTC/GMT-5)<!--more--></strong></p>
<p><strong>What time is that for you?</strong> The following link shows <strong>[<a title="http://permatime.com/US/Eastern/2011-03-17/12:00/" href="http://permatime.com/US/Eastern/2011-03-17/12:00/" target="_blank">what the time would be for you</a>]</strong>. Here&#8217;s <strong>[<a title="http://www.timeanddate.com/worldclock/fixedtime.html?year=2011&amp;month=03&amp;day=17&amp;hour=12&amp;min=00&amp;sec=0&amp;p1=25" href="http://www.timeanddate.com/worldclock/fixedtime.html?year=2011&amp;month=03&amp;day=17&amp;hour=12&amp;min=00&amp;sec=0&amp;p1=25" target="_blank">another option</a>]</strong> that shows the time as US ET, and lets you choose your city from the list offered to see what time that is in your own timezone.</p>
<p><strong>RECORDING:</strong> As always, the meeting will be recorded, and the recording URL will be posted after the meeting at<a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">http://recordings.coldfusionmeetup.com</a>.</p>
<p><strong>PODCAST/DOWNLOADABLE RECORDINGS:</strong><br />
In addition to the streaming recording posted immediately after the meeting, we now also post downloadable recordings (FLV, MP3, and MP4) usually within a few days after the meeting, also offered as a link from the recordings page.</p>
<p><strong>LOGGING IN:</strong> When you login to the Connect room (the experts.acrobat.com/cfmeetup link above) to view the meeting, PLEASE USE THE &#8220;LOGIN AS GUEST&#8221; option, and USE YOUR NAME, but do NOT attempt to use your meetup.com username/password or any Connect account. Just sign in as a guest.</p>
<p><strong>RSVP, but only if coming:</strong> We do appreciate folks RSVPing if they plan to come (using the link on this email or at the meetup site), though it&#8217;s not mandatory and it&#8217;s not a commitment. But there&#8217;s<strong>no need to RSVP if you can&#8217;t make it</strong> let alone explain why you can&#8217;t. With over 2,400 members, no worries. <img src='http://ricardo.parente.us/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>FEEDBACK/MEETING DISCUSSION</strong>: Members will receive an email after the meeting or can click a link on the event page to offer. Note also the meeting-specific discussion area there at the bottom, in addition to the one-chance feedback feature on the right. Feel free to engage in discussions about the meeting topic.</p>
<p><strong>ADD THIS TO YOUR CALENDAR:</strong> Want to add this event to your own personal calendar? After logging in here, you&#8217;ll see an option at the top of the event page, just below the event title, saying, &#8220;Add to my calendar&#8221;, which offers calendar downloads for Outlook, iCal, Google, and Yahoo calendars.</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/03/security-hiding-info-from-individuals-not-authorized-to-see-it-w-jim-harris/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MeetUp Security: Wash Your Incoming Data using ColdFusion, with Jim Harris</title>
		<link>http://ricardo.parente.us/2011/03/security-wash-your-incoming-data-using-coldfusion-with-jim-harris/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-wash-your-incoming-data-using-coldfusion-with-jim-harris</link>
		<comments>http://ricardo.parente.us/2011/03/security-wash-your-incoming-data-using-coldfusion-with-jim-harris/#comments</comments>
		<pubDate>Sun, 06 Mar 2011 00:46:45 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[MeetUp]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Seminars]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=5458</guid>
		<description><![CDATA[Our 12pm (US ET) talk on Thursday Mar 10 will be &#8220;Security: Wash Your Incoming Data using ColdFusion&#8221;, with Jim Harris. TOPIC DESCRIPTION: (provided by the speaker) During this session you will see a code set that examines incoming data for specific commands hackers use to plant malicious code and how to strip those commands. The [...]]]></description>
			<content:encoded><![CDATA[<p>Our 12pm <strong>(US ET)</strong> talk on Thursday Mar 10 will be &#8220;Security: Wash Your Incoming Data using ColdFusion&#8221;, with Jim Harris.</p>
<p><strong>TOPIC DESCRIPTION:</strong> (provided by the speaker)</p>
<p>During this session you will see a code set that examines incoming data for specific commands hackers use to plant malicious code and how to strip those commands. The demonstration will also show you a method by which you can quickly safeguard against new hack commands without distributing new templates.</p>
<p><span id="more-5458"></span></p>
<p><strong>MEETING URL: <a title="http://experts.acrobat.com/cfmeetup/" href="http://experts.acrobat.com/cfmeetup/" target="_blank">http://experts.acrobat.com/cfmeetup/</a></strong><br />
DURATION: Approx. 1 hour<br />
<strong>Meeting will be recorded.</strong> URL will be posted after meeting at<a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">http://recordings.coldfusionmeetup.com</a></p>
<p><strong>SPEAKER:</strong> (provided by the speaker)</p>
<p>Jim Harris is a retired U.S. Army Signal Corps veteran who has been using ColdFusion to create dynamic web applications since the mid &#8217;80s.  He holds a Masters Degree in Computer Science from Duke University. He is currently employed by LT Online Corporation out of Long Island NY as their Vice President of Application Development. Jim&#8217;s website is <a title="http://cf-toolbox.com/" href="http://cf-toolbox.com/" target="_blank">CF-ToolBox.com</a>.<!--more--></p>
<p><strong>WHEN:</strong> Thurs. Mar 10, 12:00pm <strong>US ET (UTC/GMT-5)</strong></p>
<p><strong>What time is that for you?</strong> The following link shows <strong>[<a title="http://permatime.com/US/Eastern/2011-03-10/12:00/" href="http://permatime.com/US/Eastern/2011-03-10/12:00/" target="_blank">what the time would be for you</a>]</strong>. Here&#8217;s <strong>[<a title="http://www.timeanddate.com/worldclock/fixedtime.html?year=2011&amp;month=03&amp;day=10&amp;hour=12&amp;min=00&amp;sec=0&amp;p1=25" href="http://www.timeanddate.com/worldclock/fixedtime.html?year=2011&amp;month=03&amp;day=10&amp;hour=12&amp;min=00&amp;sec=0&amp;p1=25" target="_blank">another option</a>]</strong> that shows the time as US ET, and lets you choose your city from the list offered to see what time that is in your own timezone.</p>
<p><strong>RECORDING:</strong> As always, the meeting will be recorded, and the recording URL will be posted after the meeting at<a title="http://recordings.coldfusionmeetup.com/" href="http://recordings.coldfusionmeetup.com/" target="_blank">http://recordings.coldfusionmeetup.com</a>.</p>
<p><strong>PODCAST/DOWNLOADABLE RECORDINGS:</strong><br />
In addition to the streaming recording posted immediately after the meeting, we now also post downloadable recordings (FLV, MP3, and MP4) usually within a few days after the meeting, also offered as a link from the recordings page.</p>
<p><strong>LOGGING IN:</strong> When you login to the Connect room (the experts.acrobat.com/cfmeetup link above) to view the meeting, PLEASE USE THE &#8220;LOGIN AS GUEST&#8221; option, and USE YOUR NAME, but do NOT attempt to use your meetup.com username/password or any Connect account. Just sign in as a guest.</p>
<p><strong>RSVP, but only if coming:</strong> We do appreciate folks RSVPing if they plan to come (using the link on this email or at the meetup site), though it&#8217;s not mandatory and it&#8217;s not a commitment. But there&#8217;s<strong>no need to RSVP if you can&#8217;t make it</strong> let alone explain why you can&#8217;t. With over 2,400 members, no worries. <img src='http://ricardo.parente.us/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>FEEDBACK/MEETING DISCUSSION</strong>: Members will receive an email after the meeting or can click a link on the event page to offer. Note also the meeting-specific discussion area there at the bottom, in addition to the one-chance feedback feature on the right. Feel free to engage in discussions about the meeting topic.</p>
<p><strong>ADD THIS TO YOUR CALENDAR:</strong> Want to add this event to your own personal calendar? After logging in here, you&#8217;ll see an option at the top of the event page, just below the event title, saying, &#8220;Add to my calendar&#8221;, which offers calendar downloads for Outlook, iCal, Google, and Yahoo calendars.</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/03/security-wash-your-incoming-data-using-coldfusion-with-jim-harris/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Touchable &#8211; Not ColdFusion</title>
		<link>http://ricardo.parente.us/2011/01/touchable-not-coldfusion/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=touchable-not-coldfusion</link>
		<comments>http://ricardo.parente.us/2011/01/touchable-not-coldfusion/#comments</comments>
		<pubDate>Sat, 29 Jan 2011 18:29:52 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Google Earth]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Touchable]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=5056</guid>
		<description><![CDATA[Take look at this video from PBS. This is program about a touch-table. (It&#8217;s Google-Earth on steroids!!!!) About half way in the video it shows Iran&#8217;s nuclear facility and does an interesting thing. It moves the satellite pictures as a function of time in years and lets you see what has really has been happening there! And [...]]]></description>
			<content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="265" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.pbs.org/kcet/wiredscience/video/embed/231" /><param name="quality" value="high" /><embed type="application/x-shockwave-flash" width="425" height="265" src="http://www.pbs.org/kcet/wiredscience/video/embed/231" quality="high" wmode="transparent"></embed></object></p>
<p>Take look at this video from PBS. This is program about a touch-table. (It&#8217;s Google-Earth on steroids!!!!) About half way in the video it shows Iran&#8217;s nuclear facility and does an interesting thing.<br />
It moves the satellite pictures as a function of time in years and lets you see what has really has been happening there!<br />
And what they &#8220;hid&#8221; or thought they &#8220;hid&#8221; underground!</p>
<p><a title="http://www.pbs.org/kcet/wiredscience/video/231-touchtable..html" href="http://www.pbs.org/kcet/wiredscience/video/231-touchtable..html" target="_blank"><strong>Here is the link.</strong></a></p>
<p>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2011/01/touchable-not-coldfusion/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cumulative Hotfix 1 (CHF1) for ColdFusion 9.0.1</title>
		<link>http://ricardo.parente.us/2010/09/cumulative-hotfix-1-chf1-for-coldfusion-9-0-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cumulative-hotfix-1-chf1-for-coldfusion-9-0-1</link>
		<comments>http://ricardo.parente.us/2010/09/cumulative-hotfix-1-chf1-for-coldfusion-9-0-1/#comments</comments>
		<pubDate>Wed, 01 Sep 2010 13:29:35 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[hotfix]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=3297</guid>
		<description><![CDATA[For those who haven&#8217;t installed the latest hotfix for ColdFusion 9.0.1 from Adobe, here is the link: http://kb2.adobe.com/cps/862/cpsid_86263.html]]></description>
			<content:encoded><![CDATA[<p>For those who haven&#8217;t installed the latest hotfix for ColdFusion 9.0.1 from Adobe, here is the link:</p>
<p><a title="Cumulative HotFix 1 for ColdFusion 9.0.1" href="http://kb2.adobe.com/cps/862/cpsid_86263.html" target="_blank"><strong>http://kb2.adobe.com/cps/862/cpsid_86263.html</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2010/09/cumulative-hotfix-1-chf1-for-coldfusion-9-0-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe ColdFusion&#039;s Directory Traversal Disaster</title>
		<link>http://ricardo.parente.us/2010/08/adobe-coldfusions-directory-traversal-disaster/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=adobe-coldfusions-directory-traversal-disaster</link>
		<comments>http://ricardo.parente.us/2010/08/adobe-coldfusions-directory-traversal-disaster/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 13:04:00 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Directory Traversal]]></category>
		<category><![CDATA[Hot Fix]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=3076</guid>
		<description><![CDATA[The ColdFusion directory traversal vulnerability has been classified by Adobe as important rather than critical, and I agree with A.P. (Adrian P. of GnuCitizen) that this is a mistake.  Here&#8217;s why I think this is a big mistake &#8230; on top of the excellent analysis Adrian has already done (check his excellent post here) I [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>The ColdFusion directory traversal vulnerability has been classified by Adobe as <strong>important</strong> rather than critical, and I agree with A.P. (Adrian P. of GnuCitizen)  that this is a mistake.  Here&#8217;s why I think this is a big mistake &#8230; on  top of the excellent analysis Adrian has already done (<a href="http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/" target="_blank">check his excellent post here</a>) I think it&#8217;s relevent to do a little digging yourself to understand the full scope of the potential problem.</p></blockquote>
<p>This post is worth reading.</p>
<p>Here is the <a title="Adobe ColdFusion's Directory Traversal Disaster" href="http://h30507.www3.hp.com/t5/Following-the-White-Rabbit-A/Adobe-ColdFusion-s-Directory-Traversal-Disaster/ba-p/81964" target="_blank"><strong>link</strong></a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2010/08/adobe-coldfusions-directory-traversal-disaster/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Unauthenticated File Retrieval (traversal) within ColdFusion Administration Console</title>
		<link>http://ricardo.parente.us/2010/08/unauthenticated-file-retrieval-traversal-within-coldfusion-administration-console/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=unauthenticated-file-retrieval-traversal-within-coldfusion-administration-console</link>
		<comments>http://ricardo.parente.us/2010/08/unauthenticated-file-retrieval-traversal-within-coldfusion-administration-console/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 15:15:41 +0000</pubDate>
		<dc:creator>rparente</dc:creator>
				<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ricardo.parente.us/?p=3037</guid>
		<description><![CDATA[Adobe ColdFusion is a easy to use and very widely adopted Programming language, Procheckup has discovered that the ColdFusion admin console (and various programs within) are vulnerable to multiple directory traversal attacks related to a input parameter. No authentication is needed; all that is needed is that the admin console is accessible to the Internet. [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Adobe ColdFusion is a easy to use and very widely adopted Programming language, Procheckup has discovered that the ColdFusion admin console (and various programs within) are vulnerable to multiple directory traversal attacks related to a input parameter. No authentication is needed; all that is needed is that the admin console is accessible to the Internet.<br />
Notes: Tested on ColdFusion enterprise version7.0 amd version 8.01 running on Windows XP, and Windows 2003 R2 SP2 server and mapped to IIS 6.<br />
Defaults were chosen with &#8220;server contained installation&#8221; &#8220;like the earlier versions&#8221;, and all subcomponents.<br />
ColdFusion 9 provides an additional layer of filtering to prevent common attacks, preventing the below attack from working. Procheckup recommends however ColdFusion 9 users to apply the ColdFusion 9 patches as Procheckup have found the filtering can be bypassed.</p>
<p>Versions tested and found vulnerable<br />
ColdFusion MX7 7,0,0,91690 base patches<br />
ColdFusion MX8 8,0,1,195765 base patches<br />
ColdFusion MX8 8,0,1,195765 with Hotfix4</p>
<p>(http://seclists.org/fulldisclosure/2010/Aug/att-127/PR10-07-nes.txt)</p></blockquote>
<p><strong>Hotfix available for ColdFusion  (APSB10-18)</strong></p>
<p>Apply patches as described below, or restrict access to /CIDE/administrator/ by IP address or other similar controls.</p>
<p>See <a title="Adobe Patch APSB10-18" href="http://www.adobe.com/support/security/bulletins/apsb10-18.html" target="_blank"><strong>http://www.adobe.com/support/security/bulletins/apsb10-18.html</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://ricardo.parente.us/2010/08/unauthenticated-file-retrieval-traversal-within-coldfusion-administration-console/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

