<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Hosting Forum - Hostek.com</title>
		<link>http://forum.hostek.com/</link>
		<description>Discussions related to ColdFusion Hosting, Linux Hosting  and Windows Hosting, including ASP and .NET Hosting</description>
		<language>en</language>
		<lastBuildDate>Wed, 08 Sep 2010 07:14:18 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forum.hostek.com/images/misc/rss.png</url>
			<title>Hosting Forum - Hostek.com</title>
			<link>http://forum.hostek.com/</link>
		</image>
		<item>
			<title>CFSCHEDULE Task Stopped Working at Midnight</title>
			<link>http://forum.hostek.com/showthread.php?369-CFSCHEDULE-Task-Stopped-Working-at-Midnight&amp;goto=newpost</link>
			<pubDate>Sun, 05 Sep 2010 09:31:35 GMT</pubDate>
			<description>Just curious if anyone has had a similar problem or knows a quick fix to the problem I have having with a scheduled task stopping at the stroke of...</description>
			<content:encoded><![CDATA[<div>Just curious if anyone has had a similar problem or knows a quick fix to the problem I have having with a scheduled task stopping at the stroke of midnight the next day.<br />
<br />
In my code i have the following<br />
<br />
<b>&lt;cfschedule <br />
action=&quot;update&quot; <br />
task=&quot;AutomatedMessage&quot; <br />
interval=&quot;1800&quot; <br />
url=&quot;URL&quot; <br />
startdate=&quot;9/4/10&quot; <br />
starttime=&quot;10:00 am&quot;<br />
 operation=&quot;httprequest&quot;&gt;</b><br />
<br />
The code worked flawlessly all day until midnight hit and I got the last automated message. It sends me an email every 30 min with some simple information, so this is how I was able to determine that it stopped. Just wanted to see if there had been any similar results or a solution out there.<br />
<br />
Thanks guys!</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?7-ColdFusion-Hosting-Related">ColdFusion Hosting Related</category>
			<dc:creator>wyseguy79</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?369-CFSCHEDULE-Task-Stopped-Working-at-Midnight</guid>
		</item>
		<item>
			<title>WCP - Enhancement List</title>
			<link>http://forum.hostek.com/showthread.php?367-WCP-Enhancement-List&amp;goto=newpost</link>
			<pubDate>Mon, 30 Aug 2010 18:12:18 GMT</pubDate>
			<description>Click here for a demo (https://wcp.hostek.com/demo) of our WCP if you are not familiar with it. 
 
Here is a list of enhancements that we are working...</description>
			<content:encoded><![CDATA[<div>Click here for a <a rel="nofollow" href="https://wcp.hostek.com/demo" target="_blank">demo</a> of our WCP if you are not familiar with it.<br />
<br />
Here is a list of enhancements that we are working on.  The enhancements will be completed in this order, subject to change at any time :)<br />
<ul><li>File Manager (<b>COMPLETED Aug 30, 2010</b>)</li>
<li>Resellers - ClientExec billing integration (<b>COMPLETED Aug 31, 2010</b>)</li>
<li>MIME Types (<b>COMPLETED Sep 2, 2010</b>)</li>
<li>Default documents (ie, which page loads first like index.php) (<b>COMPLETED Sep 3, 2010</b>)</li>
<li>Virtual Directories</li>
<li>Application Pack for Mura</li>
<li>ASP.NET Permissions</li>
<li>More Site Information, ie, IP, versions, etc.</li>
<li>Rename domain</li>
<li>SSL Certs</li>
<li>SubDomain - option to &quot;inherit&quot; domain's Virtual Directories</li>
<li>FoxPro Driver DSN</li>
<li>Allow creation of DSN while setting up database for MS SQL (MySQL already completed)</li>
<li>Resellers - own holding (coming soon) page</li>
<li>Resellers - ability to suspend a site</li>
<li>Enable / Disable IIS compression</li>
<li>allow enabling/disabling of php, perl, asp</li>
<li>more to come...</li>
</ul></div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?39-WCP-Windows-Control-Panel">WCP - Windows Control Panel</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?367-WCP-Enhancement-List</guid>
		</item>
		<item>
			<title>Very slow message processing</title>
			<link>http://forum.hostek.com/showthread.php?366-Very-slow-message-processing&amp;goto=newpost</link>
			<pubDate>Mon, 30 Aug 2010 16:33:37 GMT</pubDate>
			<description>I have noticed that my email through hostek is very slow. For example, I just registered for the forums, and the confirmation message took 30 minutes...</description>
			<content:encoded><![CDATA[<div>I have noticed that my email through hostek is very slow. For example, I just registered for the forums, and the confirmation message took 30 minutes to arrive. At other times, I am sent emails through 2 different accounts. From the other account, the message arrives almost immediately. Through my hostek account, the message may take 15-20 minutes.<br />
<br />
Is this experience common? I have had this domain for a couple of years, and it has been this way from the beginning.<br />
<br />
Thankis,<br />
<br />
Don</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?21-Email-Related">Email Related</category>
			<dc:creator>drdwilcox</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?366-Very-slow-message-processing</guid>
		</item>
		<item>
			<title>ASP.net forms</title>
			<link>http://forum.hostek.com/showthread.php?365-ASP-net-forms&amp;goto=newpost</link>
			<pubDate>Fri, 27 Aug 2010 21:04:20 GMT</pubDate>
			<description><![CDATA[I'm just starting to use expression web and need to know where I can find out how to do the following 
 
I need to create a asp.net form that works...]]></description>
			<content:encoded><![CDATA[<div>I'm just starting to use expression web and need to know where I can find out how to do the following<br />
<br />
I need to create a asp.net form that works with Expression Web where the users will submit an inquiry.  What server information do I need for this form?<br />
<br />
After I do that; I'd like to create a form where my users can login and submit announcements and they would automatically get published to their web page.  i'm guessing I might need to synchrononize some type of database with this.<br />
<br />
I'd like to create a forum where users will submit a form and it will publish to the forum.  I'm guessing all this can be done using asp.net but a little lost where to start and where do I find any necessary server information I might need to configure these forms.</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?5-Windows-Hosting-Related">Windows Hosting Related</category>
			<dc:creator>lutherandj</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?365-ASP-net-forms</guid>
		</item>
		<item>
			<title>Do you support Silverlight SDK 4?</title>
			<link>http://forum.hostek.com/showthread.php?364-Do-you-support-Silverlight-SDK-4&amp;goto=newpost</link>
			<pubDate>Thu, 26 Aug 2010 19:41:24 GMT</pubDate>
			<description><![CDATA[Yes.  For using the Silverlight SDK 4, you would simply need to include the "System.Web.Silverlight.dll" within the /bin folder when you upload your...]]></description>
			<content:encoded><![CDATA[<div>Yes.  For using the Silverlight SDK 4, you would simply need to include the &quot;System.Web.Silverlight.dll&quot; within the /bin folder when you upload your Silverlight application.</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?5-Windows-Hosting-Related">Windows Hosting Related</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?364-Do-you-support-Silverlight-SDK-4</guid>
		</item>
		<item>
			<title>Do you support WCF RIA Service 1.0?</title>
			<link>http://forum.hostek.com/showthread.php?363-Do-you-support-WCF-RIA-Service-1-0&amp;goto=newpost</link>
			<pubDate>Thu, 26 Aug 2010 19:39:42 GMT</pubDate>
			<description>Yes, we do support WCF RIA Service 1.0. 
 
This may not be installed on all servers, so if this is not working for you, contact support with your...</description>
			<content:encoded><![CDATA[<div>Yes, we do support WCF RIA Service 1.0.<br />
<br />
This may not be installed on all servers, so if this is not working for you, contact support with your domain name and request the WCF RIA Service be installed on the server for you.</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?5-Windows-Hosting-Related">Windows Hosting Related</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?363-Do-you-support-WCF-RIA-Service-1-0</guid>
		</item>
		<item>
			<title>Smartermail 7</title>
			<link>http://forum.hostek.com/showthread.php?362-Smartermail-7&amp;goto=newpost</link>
			<pubDate>Thu, 26 Aug 2010 07:20:27 GMT</pubDate>
			<description><![CDATA[What are Hostek's plans on upgrading Smartermail to version 7?]]></description>
			<content:encoded><![CDATA[<div>What are Hostek's plans on upgrading Smartermail to version 7?</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?21-Email-Related">Email Related</category>
			<dc:creator>Lagaffe</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?362-Smartermail-7</guid>
		</item>
		<item>
			<title>Mura - Permission denied for creating Java object: coldfusion.server.ServiceFactory</title>
			<link>http://forum.hostek.com/showthread.php?360-Mura-Permission-denied-for-creating-Java-object-coldfusion-server-ServiceFactory&amp;goto=newpost</link>
			<pubDate>Mon, 23 Aug 2010 17:01:10 GMT</pubDate>
			<description>If you are using *Mura* and you get this error, *Permission denied for creating Java object: coldfusion.server.ServiceFactory*, you are likely using...</description>
			<content:encoded><![CDATA[<div>If you are using <b>Mura</b> and you get this error, <b>Permission denied for creating Java object: coldfusion.server.ServiceFactory</b>, you are likely using an outdated version of Mura and also are probably on a ColdFusion 9 server.  There is a quick fix though, which I'll explain below.<br />
<br />
Find the file named CFMLVersion.cfc which may be at \wwwroot\requirements\transfer\com\factory<br />
<br />
Edit that file and find the line that has:<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">if(server.coldfusion.productversion.startsWith(&quot;8&quot;))</code><hr />
</div> And change that to:<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">if(server.coldfusion.productversion.startsWith(&quot;8&quot;) OR server.coldfusion.productversion.startsWith(&quot;9&quot;))</code><hr />
</div> Save the file and it should now work.<br />
<b><br />
NOTE:  Since this is likely running an outdated version of Mura, I would strongly suggest installing the latest version, as there has been changes to the framework which makes it load faster too.</b></div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?7-ColdFusion-Hosting-Related">ColdFusion Hosting Related</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?360-Mura-Permission-denied-for-creating-Java-object-coldfusion-server-ServiceFactory</guid>
		</item>
		<item>
			<title>Common items found in PCI report... and solutions</title>
			<link>http://forum.hostek.com/showthread.php?358-Common-items-found-in-PCI-report-and-solutions&amp;goto=newpost</link>
			<pubDate>Thu, 19 Aug 2010 22:05:43 GMT</pubDate>
			<description>To make this information readable, I will put just the heading info in here, and not the full details. 
 
Microsoft IIS ISM.DLL HTR Request Remote...</description>
			<content:encoded><![CDATA[<div>To make this information readable, I will put just the heading info in here, and not the full details.<br />
<br />
Microsoft IIS ISM.DLL HTR Request Remote Overflow<br />
This is related to mappings for .HTR, .STM, and .IDC files.  By default, we don't have .htr mapped for security.  Contact <a rel="nofollow" href="http://support.hostek.com" target="_blank">support</a> to have mappings for .stm and .idc removed if you are not using these extensions.  The use of .stm is rare and the use of .idc is almost unheard of.  We will be removing the .idc mapping from the servers shortly by default.<br />
<br />
IIS Authorization Method Disclosed<br />
07/01/08<br />
CVE 2002-0419<br />
IIS is vulnerable to information gathering as to which form of authentication is being<br />
used due to the results of attempted connections with incorrect user ids and passwords.<br />
**Contact <a rel="nofollow" href="http://support.hostek.com" target="_blank">support</a> with your domain name and request All Authentication options to be unchecked for your domain.<br />
<br />
FTP Server Remote Buffer Overflow<br />
10/13/09 CVE 2009-2521 CVE 2009-3023 Two vulnerabilities exist in the FTP Service in Microsoft Internet Information Services (IIS) 5.0, Microsoft Internet Information Services (IIS) 5.1, Microsoft Internet Information Services (IIS) 6.0, and Microsoft Internet Information Services (IIS) 7.0. On IIS 7.0, only FTP Service 6.0 is affected. The vulnerabilities could allow remote code execution on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.<br />
**False Positive.  This is related to patch KB 975254 which is installed.<br />
<br />
File change notification privilege elevation<br />
02/14/08 CVE 2008-0074 IIS is vulnerable in the way that it handles file change notifications in the FTPRoot, NNTPFile\Root, and WWWRoot folders. A local attacker would have to be able to create or modify a file in one of these directories. A remote attacker would have to be able to upload a script to an affected IIS server, and be able to run the script. This uploaded script would need write access to the FTPRoot, NNTPFile\Root, or WWWRoot folders. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of local system. Unpatched versions of IIS are vulnerable on: Windows 2000 with IIS web server, FTP or NNTP services enabled; Windows XP with IIS web server or FTP services enabled; Windows Server 2003 with FTP or NNTP services enabled; and Vista with FTP service enabled.<br />
**False Positive.  Related to KB 975254 referenced above. <br />
<br />
<br />
FTP Services - 110086 - TCP 21 - WU-FTPD QUOTE PASV Forced Core Dump Information Disclosure<br />
The suggested solution is:  Upgrade your FTP server to the latest version.<br />
This is a false positive, as we do have the FTP server upgraded to the latest version on all of the servers.  One scanner wanted more detail, so I will include that here:<br />
&quot;OS: Depending on the server, it will be either Windows Server 2008 SP2  or Windows Server 2003 SP2, with all current security updates.  The version of FTP is IIS 7.5 for Windows 2008 or IIS 6.0 for Windows 2003 SP2.  We do not run WU-FTPD on any of our servers, which is referenced by Threat 110086&quot;.<br />
<br />
<br />
Web Services - 131657 - TCP 80 - Web Server Uses Non Random Session IDs<br />
Generally related to ColdFusion sites.  The solution can be found <a rel="nofollow" href="http://www.bennadel.com/blog/785-Ask-Ben-Hiding-Encrypting-ColdFusion-CFID-And-CFTOKEN-Values.htm" target="_blank">here</a>.<br />
<br />
ASP Upload Command Execution<br />
07/12/06 CVE 2006-0026 IIS 5.0, 5.1, and 6.0 are affected by a buffer overflow when processing ASP files. A remote attacker could execute arbitrary commands by uploading a specially crafted ASP file onto the web server, and then causing IIS to process it. An attacker would need to have valid login credentials in order to exploit this vulnerability unless the web server has been configured to allow anonymous uploads to the web site.<br />
**False Positive:  This is related to patch KB 917537 and also is not applicable to Windows Server 2003 <br />
<br />
Web Services - 500033 - TCP 443 - Possible Vulnerabilities in IIS 5<br />
This is a false positive, as we do not run IIS 5 on any of our servers.  Your PCI scanning company should be able to determine this and not report this to you.<br />
<br />
<br />
Multiple Vulnerabilities in IIS 4.0 - 5.1<br />
This is a false positive, as we do not run IIS 4 nor IIS5 on any of our servers.  Your PCI scanning company should be able to determine this and not report this to you.<br />
<br />
<br />
Cross-Site Scripting<br />
This is something you need to fix in your code.  Basically you need to sanitize your form input when using it after the form is submitted.  You need to remove any of the following characters minimally:<br />
% ( ) = &lt; &gt; <br />
<br />
Here is a sample of how to do this, based on ASP.  I would suggest placing this function in an include page:<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">Function CleanFormInput(aField)<br />
&nbsp; aTempField = Replace(aField, &quot;&lt;&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;&gt;&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;%&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;=&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;(&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;)&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;'&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;|&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;;&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;-&quot;, &quot;&quot;)<br />
&nbsp; aTempField = Replace(aTempField, &quot;&quot;&quot;&quot;, &quot;&quot;)<br />
&nbsp; CleanFormInput = aTempField<br />
End Function</code><hr />
</div> Then in your code where you are processing the input you could do something like (after including the include file mentioned above):<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">aCleanVar = CleanFormInput(Request(&quot;myFormField&quot;))</code><hr />
</div> Details: A cookie without the HTTPOnly attribute could be<br />
susceptible to theft by cross-site scripting attacks.<br />
** See this <a rel="nofollow" href="http://www.owasp.org/index.php/HTTPOnly#Mitigating_the_Most_Common_XSS_attack_using_HttpOnly" target="_blank">link</a> for the fix to this issue.</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?38-PCI-Compliance-Information-IIS-Servers">PCI Compliance Information - IIS Servers</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?358-Common-items-found-in-PCI-report-and-solutions</guid>
		</item>
		<item>
			<title>CF Admin vulnerability fix - ColdFusion Servers only</title>
			<link>http://forum.hostek.com/showthread.php?357-CF-Admin-vulnerability-fix-ColdFusion-Servers-only&amp;goto=newpost</link>
			<pubDate>Thu, 19 Aug 2010 19:08:38 GMT</pubDate>
			<description>To our dedicated customers that are using ColdFusion.  If you are not using ColdFusion, you can ignore this notice. 
 
NOTE:  I know some of you also...</description>
			<content:encoded><![CDATA[<div>To our dedicated customers that are using ColdFusion.  If you are not using ColdFusion, you can ignore this notice.<br />
<br />
NOTE:  I know some of you also have ColdFusion shared hosting accounts with us also, and yes, we have already taken care of all of our shared hosting servers.<br />
<br />
There is security vulnerability related to CF Admin when accessible publicly.  There is a<a rel="nofollow" href="http://kb2.adobe.com/cps/857/cpsid_85766.html" target="_blank"> patch that Adobe released</a>, which you can install to fix this, however, a possible better solution is outlined below, as that will prevent this and other future issues related.<br />
<br />
Here is how you should have the /CFIDE mapping handled if not done so already.<br />
<br />
A normal install has the /CFIDE folder at:<br />
c:\inetpub\wwwroot\CFIDE<br />
<br />
This location is needed, however, it should not be your default /CFIDE mapping for domains added to the server.<br />
We suggest copying the /scripts and /classes folder from this location and placing them at:<br />
d:\home\CFIDE<br />
<br />
Then make sure that everyone has only read/execute permissions on the d:\home\CFIDE folder.<br />
<br />
In your IIS, make sure any sites using a virtual CFIDE folder is changed to use the d:\home\CFIDE folder and NOT the c:\inetpub\wwwroot\CFIDE folder.<br />
<br />
Now, in IIS, edit the Host Headers for the WWW item that is used for your CF Admin and remove 127.0.0.1 from the list, assuming that entry is there.  Then add an IIS item named CFAdmin pointed to the same directory as the IIS item that you currently use for the CFAdmin access, and set it to use 127.0.0.1 and port 80.  Next, create a Virtual Directory for this CFAdmin iis item and name it CFIDE and set it to the c:\inetpub\wwwroot\CFIDE folder.<br />
<br />
Now, you can access CF Admin from the server via the <a rel="nofollow" href="http://127.0.0.1" target="_blank">http://127.0.0.1</a> address, removing the CF Admin access from the public.<br />
<br />
Remember, in the future when you need to create any virtual /CFIDE folders, to use the new d:\home\CFIDE folder.</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?25-VPS-and-Dedicated-Server-Related">VPS and Dedicated Server Related</category>
			<dc:creator>Brian</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?357-CF-Admin-vulnerability-fix-ColdFusion-Servers-only</guid>
		</item>
		<item>
			<title>Migrating WebMail to SmarterMail</title>
			<link>http://forum.hostek.com/showthread.php?356-Migrating-WebMail-to-SmarterMail&amp;goto=newpost</link>
			<pubDate>Wed, 18 Aug 2010 04:14:47 GMT</pubDate>
			<description>I am in the process of moving two websites from a different provider to Hostek. One is a regular html site and the other is a Coldfusion 9 site. The...</description>
			<content:encoded><![CDATA[<div>I am in the process of moving two websites from a different provider to Hostek. One is a regular html site and the other is a Coldfusion 9 site. The sticking point right now is how to move the emails from a WebMail account to SmarterMail Enterprise 4.3 which is what is currently running on my Coldfusion site. <br />
<br />
So, two questions...<br />
<br />
1. My current site (a Coldfusion 9 Silver account) on Hostek is running SmarterMail 4.3, not version 6.x. How would I move WebMail over?<br />
<br />
2. If I set up a new Windows Bronze account for my client , would I get SmarterMail 6.x? <br />
<br />
Thanks,<br />
Doug</div>

 ]]></content:encoded>
			<category domain="http://forum.hostek.com/forumdisplay.php?21-Email-Related">Email Related</category>
			<dc:creator>Doug</dc:creator>
			<guid isPermaLink="true">http://forum.hostek.com/showthread.php?356-Migrating-WebMail-to-SmarterMail</guid>
		</item>
	</channel>
</rss>
