bennadel / Securing-ColdFusion-Scheduled-Tasks

Securing ColdFusion Scheduled Tasks In A Dockerized Container

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Securing ColdFusion Scheduled Tasks In A Dockerized Container

by Ben Nadel

This is an experiment to see various way in which we can secure a ColdFusion scheduled task. This way, we can be sure that the scheduled task is not being initiated via a public request from a potentially malicious actor. This demo uses a Lucee CFML / nginx image from Lucee CFML's official docker images.

CAUTION: I am neither a security expert nor a Docker expert!!

Security techniques:

  • Lock down to an internal IP address (localhost).
  • Lock down to an internal port (Tomcat).
  • Lock down with an invocation password (ENV variable).

About

Securing ColdFusion Scheduled Tasks In A Dockerized Container


Languages

Language:ColdFusion 98.9%Language:Dockerfile 1.1%