I ran into a situation tonight where I needed to reset the admin passwords for Railo, its super easy but figuring out where to do it was a little bit of a pain. Here's how you do it, read more...
Viewed 2681 times
Comments (1)
A recent presentation given at DEFCON 16 exposed a seemingly unsuspected vulnerability, common in most SSL-Secured websites. Many large and prominent sites such as GMail, Facebook, Yahoo Mail and others are exposed to this vulnerability simply because they haven't secured their cookies. The presenter dubbed the exploit, HTTPS Cookie Highjacking and loosely described it as,
"It turns out an adversary able to position themselves in between you and a website is able to inject arbitrary http-based content elements for domains that do not set the 'Encrypted Sessions Only' property of their cookies, and thus cause your client to transmit these cookies via clear text, intercept them, and impersonate you."
Just wanted to list out some recent enhancements that I've made to the site.
Photo Gallery
The most notable enhancement I made to this area was including a dynamic watermark to the images that I pull back from Flickr. I didn't do this for the copyright aspect of my photos (although its an added bonus read more...
Viewed 1417 times
Comments (0)
This months Baltimore Adobe Users Group is getting a special guest speaker, CFML committee member and CEO of Railo, Gert Franz. Railo is an Adobe Coldfusion alternative that, at some level, is free and soon will have a open source edition. If you live in and or around the Baltimore Metro you should defenitely make your way down for the meeting, there is usualy free food and drink, and always great conversation amongst Adobe professionals. read more...
Viewed 1004 times
Comments (0)
Come Monday I'll be starting the envisioning phase of a 4 month project aimed to enhance the overall user experience in one of our flagship applications. I'm definitely excited about the project not only because there will be some really cool components to build but also because the project will be run using an Agile methodology. For the past several years I've been working on high dollar(long running), complex business apps that followed the Waterfall approach. Each of these projects adhered to the phases of your standard Software Development Life Cycle (SDLC) and at times seemed to drag on in the least exciting phases.
Agile development is definitely different than your traditional waterfall based project, not only from a structure point of view (phases and such) but also in it's principles, which are;
Individuals and interactions over processes and tools