Click to search on your search term.

Securing ColdFusion Servers on Windows

This one-day seminar covers building secure ColdFusion application servers on the Windows platform, and keeping them secure. You'll learn how to secure the Windows OS, IIS and CF Server, find and eliminate security holes in your application code, and maintain security on your servers. See how attacks work, and how you can defend against them.

Duration: 1 days

Price: 495.00
GSA Price: 473.81
Online Price: 545.00

Course Prerequisites

There are no course prerequisites.

Course Objectives

Course Outline

Unit 1 ? Course Overview

This unit, following the Allaire precedent, provides a general description of the course. It includes an overview of the security ?process?, and the layering approach to security. It ends with a description of the lab materials.

Unit 2 ? The Threat

This unit describes ? and demonstrates - the array of potential attacks and their severity.

  • Purposes of attacks
  • Types of attacks
    • Denial of service
    • Impersonation
    • Buffer overflows
  • Targets of attacks
    • Operating system
    • IIS
    • CGI applications (CF)
    • Databases
    • Other network devices
  • Attack patterns and processes
    • Information gathering
    • Exploits
    • ?Island-hopping?
    .

Unit 3 ? Networking and Security Overview

This unit discusses the larger network infrastructure that will surround the web server, and examines different ways the server may be configured to work within that infrastructure.

  • Public vs private access
  • Security vs convenience
  • Microsoft Networking
  • DMZs and bastion hosts

Unit 4 ? A Layered Approach to Security

This unit describes in detail the general concepts to securing resources.

  • Multiple redundant layers
  • Minimizing privileges to the least possible
  • Removing unnecessary options

Unit 5? Securing the Operating System

  • Overview of Windows NT security
  • Server installation checklist
  • Building a bastion host

Unit 6 ? Securing IIS

  • IIS installation checklist

Unit 7 ? Securing CF Applications

  • CF Server configuration
    • Changing the service account
    • Disabling RDS
    • Securing the CF Administrator
  • Filtering input within applications
  • Code auditing

Unit 8 ? Maintaining Security

  • Auditing and monitoring
  • Remote console access
  • Applying patches and updates
  • Monitoring security issues ? public resources
  • Dealing with a successful attack

Fig Leaf has provided training in the following cities:

Alexandria VA Arlington VA Atlanta Austin Baltimore Boston
Charoltte Chicago Columbus Dallas Denver Des Moines
Detroit Edmonton El Paso Houston Indianapolis Jacksonville
Las Vegas Los Angeles Memphis Miami Milwaukee Minneapolis
New Haven New York Ottowa Philadelphia Phoenix Raleigh / Durham
Reston Sacramento San Antonio San Diego San Francisco San Jose
Seattle Springfield State College PA Tallahassee Toronto Washington DC
Click here to request us to schedule a class in your area