Did you code ColdFusion in 2014

The Hybrid Group is doing a survey via Twitter called #Code2014 asking which languages you've used in 2014. They have a nice graphic there. So Tweet it out if you've done #ColdFusion #CFML to #Code2014!

Preventing SSLv3 Fallback in ColdFusion

We've all been taking steps lately to protect our computers and servers from the POODLE flaw in SSLv3. At CF Webtools we've been updating our servers in various hosting facilities to prevent the use of SSLv3. Perhaps you never think about it, but as a ColdFusion developer you make frequent use SSL via various ColdFusion tags or cfscript. For example, CFHTTP lets you access a remote server (such as a web service) with a URL via ColdFusion server and it most often uses SSL in the process.

POODLE and ColdFusion

In case you missed why this is a trending topic (and why security folks like myself and Mark Kruger, aka. ColdFusion Muse are so riled up about it), here is a quick refresher as to what POODLE is according to US-CERT From this article they describe what is affected

"All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this vulnerability using web browsers and web servers, which is one of the most likely exploitation scenarios. "
"This affects most current browsers and websites, but also includes any software that either references a vulnerable SSL/TLS library (e.g. OpenSSL) or implements the SSL/TLS protocol suite itself."

[More]