Conflicting Information

I'm a Information Security Analyst and currently I'm trying to strengthen our ColdFusion hardening standards and I have an issue that I need to understand.
I'm referencing two separate Adobe documents,
First document:
ColdFusion 9 Lockdown Guide
Recommends:
Page 16 of 35.  Do not enable RDS. Click next...
Next document:
Security Advisory for ColdFusion
Release date: January 4, 2013
Last updated: January 16, 2013
Vulnerability identifier: APSA13-01
Recommends:
Setting the password for Remote Development Services (even if RDS is disabled)
Enabling password protection for RDS
Setting the Admin password and enabling password protection for Administrator
So, Adobe recommends, 1st, not to Enable RDS at all, but then recommends as a "mitigation", Enabling RDS (post installation) to setup a username and password, but the ColdFusion 9 Lockdown Guide "Do not enable RDS.". 
Maybe as a "Remediation", Adobe should just remove RDS since a) they recommend keeping it disabled and b) it's such a vulnerability?  Also, I would suggest that the recommendations from the Security Advisory (s) be incorporated into an updated ColdFusion 9 Lockdown Guide.
I'm sure this cannot be the first time they've heard this.
Don

It doesn't say to "Enable RDS", it says "Enable password protection for RDS"
You can disable the RDS by commenting out the servlet mapping in web.xml, but you should still set passwords for RDS on the chance that it ever gets enabled on the server (someone restores the wrong XMl files or something). It is best to enable separate RDS usernames and passwords for this.
You should still keep RDS disabled in production, but this is an example of defense-in-depth. Even if RDS were to become enabled, it would alteast be password protected. These documents do not contradict each other.
Disabling RDS: http://helpx.adobe.com/coldfusion/kb/disabling-enabling-coldfusion-rds-production.html
Jason

Similar Messages

  • HT4515 I want to buy an unlocked 4s from apple and use it permanently on a foreign CDMA cell service (IUSA Cell in Mexico).  I am getting conflicting information.  Thoughts?

    I want to buy an unlocked 4s from apple and use it permanently on a foreign CDMA cell service (IUSA Cell in Mexico).  I am getting conflicting information on whether this is possible.  Apple website says the phones are unlocked for GSM use only. 
    I called apple when i bought an Ipad to help decide on a GSM vs CDMA version and was told that if I went to Mexico with a CDMA version of the Ipad (2) that i would call the carrier give them some numbers and they would activate it.  When i returned I was to call Verizon and reactivate it in the US.  I ultimately got the GSM version so i never tested the theory. 
    I am now thinking of getting the 4S to use in Mexico permanently but want to use it on a CDMA carrier because it is half the cost per month.  But will this work?  Thoughts?

    There is no such thing as an unlocked CDMA iPhone. All CDMA iPhones are carrier locked and the carriers do not allow unlocking. All legitimatly unlocked iPhones are GSM only The CDMA side is completely disabled in them.
    You can only use a CDMA iPhone if the carrier you want to use offers one.

  • Conflict Resolver Sync Error - Unable to retrieve conflict information from the sync server

    So I have been using iTunes with my iPhone 3GS and now my iPhone 4 to sync with my Outlook for many years now  and it has been flawless.
    I recently bought a new iPad and started syncing it as well.
    Now as of late, after every 2 or 3 syncs, I get an error from iTunes displaying the Conflict Resolver and it says there are 42 sync conflicts.
    When I try use the Review Now button it shows up and the issues are between my iPhone and Outlook and are only related to contacts.
    As soon as I try to choose which record to resolve, the window immediately disappears without giving me a chance to finish and I get another dialog window with the error:
    Unable to retrieve conflict information from the sync server.
    Please try again the next time the conflict resolver window is presented.
    When I try to sync again it seems to be fine.  But then after I sync my iPad and theny iPhone again it shows up and it still won't let me resolve the conflicts.
    I have tried the following:
    1) Rest Sync History on all devices
    2) I have had iTunes replace all the contacts on the iPad from iTunes
    3) I have changed the conflict resolver to only notify when 50% of the data will be changed
    I have had no such luck.
    If I add a contact to Outlook or to my iPhone and then sync it seems to be syncing the new addtions correctly.  However, I cannot get this issue with this 42 conflicts resolved for some reason.  This has been going on for a month now.

    Here is the solution. 
    Rationale: You want to be able to have the dates on your items (notes, contacts) on your iphone to be the same as on outlook.  This will eliminate any sync conflicts.  You will also notice that if you modify something on the iphone and sync, you will lose the modification you made.
    Steps:
    1) In outlook, export the data (contacts, notes) to a CSV file
    2) Delete you notes/contacts in outlook
    3) Sync your iphone and select replace information on this iPhone (in iTunes)
    4) Now your contacts and notes will be empty on both your iPhone and Outlook
    5) Now import your contacts and notes from the CSV files back into outlook.  What this does is put the current date and time on every individual item
    6) Sync your iPhone to iTunes normally
    7) everything will work correctly now with no sync issues and no conflicts.
    Sherali

  • Conflicting information regarding running chkdsk on replica volumes.

    I am seeing conflicting information on using chkdsk on replica volumes.  I have a disk replica that appears to have a corrupted file that is preventing the tape backup from completing.  I have seen suggestions on TN that using chkdsk /f against
    the replica volume could fix the problem but I also see information on Technet (.bb795857.aspx) that it could also cause a loss of all recovery points.  Has anyone successfully run this against a replica volume in DPM 2012 R2 with no loss of recovery
    points?
    Thanks,

    Hi,
    Running chkdsk on the Replica can be done without with out too much concern as Shadow copy volume is still online and VSS can track changes made to the Replica and perform copy-on-write (cow) to maintain current active snapshot.
    Running chkdsk on the "recovery point" volume takes some precautions.  You need to cancel any running and all future scheduled jobs that effect the datasource whose recovery point volume you want to run chkdsk on.  This is because while chkdsk
    has taken the volume offline to have exclusive use, any writes to the replica could lead to invalidating the shadow copies.  In theory, VSS Shadow copy protection mode should prevent that, but to be safe, I would take the extra precaution.  
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. Regards, Mike J. [MSFT]
    This posting is provided "AS IS" with no warranties, and confers no rights.

  • Conflicting information over availability of BT In...

    I live in St Austell, which is one of the 6 pilot areas for FTTP and according to recent press releases it has already gone live but when I look around all I am seeing is conflicting information.
    According to the line checker at the BT Infinity page I am not in an area that is enabled yet for fibre optic and Sam Knows says St Austell won't be getting FTTC until December of 2012 but if I do the postcode check at BT Wholesale it says FTTC is already enabled... We are about 100m from the nearest cabinet and I saw BT digging up the road outside our house over a month ago.
    Currently I'm on an LLU ADSL2 connection through Xilo and the line rental is through Sky, so I don't know if that is confusing matters but I've been unable to get any kind of clear answer from BT on when we are likely to get access to a fibre optic connection and whether it will be FTTP or FTTC. It could be a week or it could be a year... Since I work from home via the internet a genuinely fast unlimited broadband connection is something I'd like to see enabled as soon as possible.
    Is there any way to cut through all this conflicting information and find out what options we will have and when?

    I noticed a person asking for help help identifying the cabinet they are connected to and when/if it's due Infinity.
    Dean a BT forum Mod replied and he mentioned "and others".
    It might be worth contacting... See Message #13 and the contact form is in #15. 
    They will probably need address/post code/phone number... anything you can think of that will help them to identify your location.
    It may take 72hrs or so to get a reply due their workload.
    Note when you use a checker  the only way to get an accurate result is by entering a telephone number.... if you have BT line.
    The Post code result is only for an area and within that area some cabs have been done and some haven't.
    Please Click On any Text in Blue as that automatically links to information.
    PC (NDEGR)

  • TS2776 error message 'cannot access conflict information sync server'

    I recently can't sync my iPhone with my Microsoft Outlook calendar.  I receive an error message 'cannot access conflict information sync server.  Try again later.'  Help!

    You are trying to use conflicting services for sync, disable all the ones that you do need. Once only one is enabled, you will be OK

  • Syncing my phone it says I have conflicts when then I get the message "Unable to retrieve conflict information from the sync server.  Please try again next treset Sync history and hasn't helped.

    When syncing my phone it says I have contact conflicts which I try to resolve and then I get the message "Unable to retrieve conflict informaiton from the sync server.  Please try again next time the conflict resolver window is presented".  I have reset the Sync History but hasn't helped.  Suggestions?

    Here is the solution. 
    Rationale: You want to be able to have the dates on your items (notes, contacts) on your iphone to be the same as on outlook.  This will eliminate any sync conflicts.  You will also notice that if you modify something on the iphone and sync, you will lose the modification you made.
    Steps:
    1) In outlook, export the data (contacts, notes) to a CSV file
    2) Delete you notes/contacts in outlook
    3) Sync your iphone and select replace information on this iPhone (in iTunes)
    4) Now your contacts and notes will be empty on both your iPhone and Outlook
    5) Now import your contacts and notes from the CSV files back into outlook.  What this does is put the current date and time on every individual item
    6) Sync your iPhone to iTunes normally
    7) everything will work correctly now with no sync issues and no conflicts.
    Sherali

  • Conflicting information about external display resolution - please help!

    I have a MacBook Pro (15-inch, Mid 2009) with the non-reflective screen, Mini Display Port and NVIDIA GeForce 9400M Graphics processor.
    According to these technical specifications (http://support.apple.com/kb/SP544), the built-in NVIDIA GeForce 9400M Graphics processor supports full native resolution on the built-in display and up to 2560 by 1600 pixels on an external display.
    Armed with this information, I just purchased a shiny, new DELL U2711 (http://accessories.us.dell.com/sna/productdetail.aspx?c=us&cs=04&l=en&s=bsd&sku= 224-8284&redirect=1) external display which has a resolution of 2560 x 1440. Unfortunately, all I can get out of it is 1920 x 1080 (This is the maximum resolution I can select in the monitors system preferences panel.)
    So Apple tells me this graphics card supports 2560 x 1600, but I also contacted NVIDIA directly who told me that this particular card's maximum resolution is 1920 x 1080.
    Somebody has to be wrong. Is this monitor supported? Am I doing something wrong? Do I need to send this monitor back and buy a smaller display?
    Any advice would be greatly appreciated.
    O

    Well - seeing as nobody could provide any help on this, I'll post the answer in case anybody else has the same problem.
    It turns out that the monitor's resolution IS supported by the NVIDIA GeForce 9400M, so the information NVIDIA gave me was wrong.
    The issue was the adaptor.
    A regular Mini Display > DVI adaptor can only handle a resolution of 1920 x 1080. Turns out I needed a Mini Display > DUAL LINK DVI Adapter, which is a combination of USB and DVI which provides the required resolution of 2560 x 1600.
    http://store.apple.com/us/product/MB571Z/A
    Hope this is helpful to somebody.

  • Document Security settings - conflicting information

    A PDF has been created in a process where Security is applied by itext sharp; and all values should be set to Allowed.
    When I check File > Properties > Security Tab (in adober reader 8 ) I can see:
    1) At the bottom a 'Document Restrictions Summary' section, but not all my values are "Allowed". So possibly something isn't right with the itext sharp process. However what is more confusing and the purpose of this post is that I can also see....
    2) At the top the Document Security section and a Show Details button. Selecting this brings up the Document Security dialog with another list of settings - some of which are a contradiction of those shown in the Summary list (point 1 above) e.g. Document Assembly is Not Allowed in 1) above, but is shown as Allowed in the separate Document Security dialog?????
    I can't find any information on the difference between these two sections and which Value is correct.
    I'm not sure if this is the correct forum, I've also posted this in the adobe reader group.
    Any help appreciated.
    ej.

    >When I check ...in adober reader 8
    >1) At the bottom a 'Document Restrictions Summary' section, but not all my values are "Allowed".
    This is normal in Reader, because its functions are limited. It's
    confusing, but it says "disabled" for things it can't do as well as
    those things which are forbidden. To actually confirm the settings use
    Acrobat instead.
    Aandi Inston

  • Adobe Reader 8 - Document Security - conflicting information

    A PDF has been created in a process where Security is applied by itext sharp; and all values should be set to Allowed.
    When I check File > Properties > Security Tab (in adober reader 8) I can see:
    1) At the bottom a 'Document Restrictions Summary' section, but not all my values are "Allowed". So possibly something isn't right with the itext sharp process. However what is more confusing and the purpose of this post is that I can also see....
    2) At the top the Document Security section and a Show Details button. Selecting this brings up the Document Security dialog with another list of settings - some of which are a contradiction of those shown in the Summary list (point 1 above) e.g. Document Assembly is Not Allowed in 1) above, but is shown as Allowed in the separate Document Security dialog?????
    I can't find any information on the difference between these two sections and which Value is correct.
    Any help appreciated.
    ej.

    I just need to clarify this.
    So if I see the Document Assembly not allowed in the Reader, and if I can assemble the document in the Acrobat, what does it mean?
    I am submitting a government grant application, and they specify saying we have to submit the document with a setting that allow document assembly, commenting, editing, etc.  This is to allow reviewers to be able to comment on and assemble applications.
    Should I be worried when I see in Reader that Document Assembly is Not Allowed?  Or is this OK, as far as Document Assembly is allowed in Acrobat?
    Thank you,

  • Conflicting information about files that should not be included in version control

    Hi All,
    We are using RoboHelp HTML v9 from the Tech Comms Suite v3.5.
    We are two authors who added our help project files into Perforce version control using the instructions provided on the Adobe site. All was going well until I returned from Maternity Leave. Now, we seem to be getting some file conflicts and 'strange behaviour'.
    I searched for answers and found the following submissions offering conflicting advice about the .hhp file:
    http://adobe.hosted.jivesoftware.com/message/3880352
    http://forums.adobe.com/message/3853685#3853685
    The .hhp file is one of the files causing us troubles. Should this file be under source control? What is the best way for us to remove it from source control, or would it be better for us to remove the whole project from source control and re-add it through RoboHelp once more to ensure whatever it is that happened on my return is eliminated?
    Thank you all for your help.
    Regards
    LillibetUK

    If you are getting conflicts then these need to be sorted out regardless of whether they should be inside your source control application. I use source control and can tell you that the HHP file should be source controlled. Open it up in Notepad and you'll find all sort of project related data including a list of all the topics in your project. It can also be useful to recover from a corrupted project. For this reason alone I'd always include it in source control.

  • Conflicting information from support pages about firmware update error

    I recently opened my Macbook to see a firmware update. I followed the instructions to install it, however when I went to shut down to complete the process, I got an error: +"unexpected error occurred (0); unable to upgrade firmware"+
    After several tries, some digging through the support articles yielded this information:
    +Firmware updates for Intel-based Macs require a GUID partition scheme+
    +Firmware updates will not install on an Intel-based Mac if the computer is using a non-standard partition scheme, such as an fdisk scheme. You may see an "unexpected error occurred (0); unable to upgrade firmware" error message, or your computer may start normally (after a single beep if the power button is held) when attempting to install the firmware update.+
    So I followed the instructions to determine which partition scheme I had. It was "applepartitionscheme". I read further to see how to correct this, assuming I should to make sure I had the latest updates on my computer. After seeing that it required backing up data, and potentially my install disc, I decided to put my Service Plan money to work, and have Apple Support walk me through it, as I am still a rather novice Apple customer.
    I admit I was frustrated that the man on the phone did not seem to understand that I already had a grasp on my problem, and that I bypassed a lot of the diagnostic steps already. I realize that tech support has to follow some step by step manual when talking to a customer, but sometimes I hate being patronized. (Yes, my monitor is on, yes I am connected to the internet. I am not stupid.) I explained I recently had the hard drive replaced. He walked me through "Repairing Permissions" using my install disc. This did not fix the issue. He explained that the update was probably not needed. It wasn't compatible with my computer, and that the techs who put my new drive in probably installed any updates I needed at Apple Care.
    But, am I just really not educated enough in this? Wouldn't my computer say then if it had the most current update? When I check my version it reads : MB....B02, 1.13f3 but when I check under the list of latest update for Macbook it reads, MB...B07, 1.4f12. Is my new hard drive is indeed updated, but my "About This Mac" still thinks it has an older version? Am I going to have this problem with every update?
    I find it hard to believe that after reading this highlighted tech support article:
    +An Intel-based Mac's hard disk must be formatted with the GUID partition scheme to apply a firmware update. Intel-based Macs are shipped this way from the factory. If you have reformatted your hard drive, you should check which scheme your hard disk is currently using before applying a firmware update.+
    that I don't need to fix this incompatibility. Can anyone help with this?

    fatoots wrote:
    ... This did not fix the issue. He explained that the update was probably not needed. It wasn't compatible with my computer, and that the techs who put my new drive in probably installed any updates I needed at Apple Care.
    At that point say you are not satisfied and you would like to A: talk to his supervisor
    or B: escalate the problem.
    Trust what "System Profiler" tells you, not what "Software Update" tells you.
    You DO need to resolve this update.
    * backup your data
    * repartition the HD using GUID
    * reinstall MacOS
    * install all updates
    * restore your data

  • How do I know how much space I have free on my internal SSD - conflicting information

    I upgraded the hard drive in my early 2011 macbook pro to a 512 GB SSD.
    When I go into 'get info' in Finder it was  152 GB free (out of 512 GB)
    However,  when I run two third party utilities it tells me instead that I have  100 GB free.
    First    "Daisy Disk" - a great utility - scans the SSD  and comes back with  99.9 GB free.
    Then 'Cocktail'  another top utility tells me I have used 80% of my SSD  - also implying  100 GB free.
    Can anyone throw any light on this?
    PS One more thing,  a few days ago  'get info' in Finder was showing  just 120 GB free, so I had a clear out of unwanted files and cleared out 30 GB of junk , hence the 152 GB free now (according to 'get info').    Even before the clear out, the 3rd party utilities were showing 100 GB free and that's what they're still showing now.  Any ideas welcome.
    Regards
    Danbo

    Apps that scan all your folders and total up file sizes cannot give accurate pictures of total disk space used, because they cannot look inside certain folders that you don't have access to. Some of those folders will be system folders, others will be folders belonging to other user accounts. The "Get Info" numbers in the Finder are correct.

  • Read_pos and read_encoder return conflicting information

    I am doing a test that requires my motor to move to 3 positions multiple times during the test. It is a stepper motor running closed loop with an encoder. When I use read_pos to verify the movement, it reports that I hit the same location every time. However, read_encoder returns different values each time. The resolution of the stepper is 51200 steps/rev and the encoder is 10000 counts/rev. Why does the encoder report different positions without the step postion being different? Thanks
    Chuck Cottle
    Advanced Inspection and Measurement

    How much difference is there when reading the encoder counts? If it is just a few counts (or just one count) I would agree that this is due to a microstepping problem.
    Unfortunately not all microsteps are created equal. I.e., if you tell the motor driver just to advance one microstep, and then advance one more, the actual displacmenet may be somewhat different for each microstep (but the motor will reach exactly the same position if the number of microsteps equals one full step). So if the 7344 detects a (minor) following error it will issue a calculated number of microsteps to correct this following error - but probably will not reach the desired position exactly since the calculation assumes that each microstep pulse will cause the same dr
    ive displacement.
    Also, I have heard of problems when the ratio encoder counts to steps per rev. is NOT an even number, rounding errors may occur.
    There is an excellent on-line essay about stepping motors, including possible microstepping problems, by a certain Mr Jones. Just do google search for 'jones on stepping motors'.

  • What's going on? conflicting information....

    I have a first gen Nano, and the iPod software on it is v5.1, which iTunes tells me is up-to-date. In fact, the check for update button is greyed out, so that seems to confirm that.
    I currently use iTunes 7.1.1.5 and keep getting prompts to upgrade to v6, which I really don't want to if I can avoid it. I know can't purchase some songs from iTunes now, as I require this later version.I always have problems when i upgrade versions - are there any known problems with this version on first gen nanos?
    anyway, my main problem now is that the songs that I can still purchase with my 'old' version of iTunes can't be transferred to my iPod - I get a message that says 'some items of the itunes library were not copied to the ipod as the ipod software is too old. Go to the summary tab and update....etc etc'
    so what do I do? One part tells me my ipod software is up-to-date and there is no update avail, the other tells me it's too old and to update? huh?
    thanks in advance to anyone who can explain this to me.

    Ok, so I tried again this morning and now the songs transfer without problem to the ipod - no error message at all. Hmmmm.
    I'm now thinking about upgrading to the latest version of iTunes, but still a little wary as I've had problems with iTunes upgrades previously and having to restore my nano as a consequence.

Maybe you are looking for

  • Preview (and Skim) crashing with certain pdfs.

    I get pdf copies of my Visa bill and preview regularly crashes when I try to view them. Note that this happens some months, and not others. I have downloaded and tried Skim with the same result. Sometimes Safari crashes at the same time. Here is the

  • My Samsung monitor won't show image with G5??

    HAD a 2004 G5 with the ADC (or ACD?) card and Apple Display and everything worked fine when using a VGA to DVI connector and connected my small Samsung monitor. I could do dual monitor. Now I sold the G5 and bought a late 2005 model with the normal D

  • Can I somehow open a Logic Express 7 project in Logic Express 8?

    Can I somehow open a LE7 project in LE8?

  • Pulling Files From Time Machine Backup?

    I want to do clean install of Snow Leopard on my Macbook Pro because it's becoming overly cluttered with files that have been over the years first put on my Powerbook then my Macbook and then this computer. Currently everything is backed up to a hard

  • Tell me why layout

    Hi friend, I how how to use layouts. But i feel it is difficult to design a form with layouts. instead of that i can create a form with null layout and i can drag and drop the components using any visual tool. I think in java they have many classes f