
• Kept running into ColdFusion on pentests
• Last “pentester” talk on ColdFusion was 2006 at EUSec
– http://eusecwest.com/esw06/esw06-davis.pdf
• Chris Eng’s “Deconstructing ColdFusion” renewed my
interest
– https://media.blackhat.com/bh-us-
10/whitepapers/Eng_Creighton/BlackHat-USA-2010-Eng-
Creighton-Deconstructing-ColdFusion-wp.pdf
– https://media.blackhat.com/bh-us-
10/presentations/Eng_Creighton/BlackHat-USA-2010-Eng-
Creighton-Deconstructing-ColdFusion-slides.pdf
• People in the ColdFusion world take a high level view of
security and didn’t want to give up the details on f**king
ColdFusion up…had to figure it out myself
Why This Talk?
Comentarios a estos manuales