Solved

Question about CFencrypt

Posted on 2013-05-29
3
300 Views
Last Modified: 2013-05-29
I understand that cfencrypt will encrypt data and then write it to the database and also descrypt it when necessary. Can someone tell me if the data transfer between the web server and the database server is encrypted with this cfencrypt method?

Thank you.
0
Comment
Question by:earwig75
  • 2
3 Comments
 
LVL 52

Expert Comment

by:_agx_
Comment Utility
EDIT:

What do you mean by "CFEncrypt"?  There is no such thing in the built in tags and functions.


Can someone tell me if the data transfer between the web server and the database server is encrypted ...?

When you enter a username and password for a datasource, CF encrypts the password before storing it the config files.  But standard communication though a jdbc datasource is not encrypted.
0
 

Author Comment

by:earwig75
Comment Utility
So if I use Encrypt/Decrypt with ColdFusion it will not be encrypted between the web server and the database? Thanks again.
0
 
LVL 52

Accepted Solution

by:
_agx_ earned 500 total points
Comment Utility
You can encrypt individual values before sending them to the database, and they will be sent in encrypted form.  Everything else is sent in plain text.

For example, here "value1" will be sent encrypted. But value2 will be sent in plain text ie "orange".

               <cfset value1  = encrypt( "apple", .....etc ...)>
               <cfset value2 = "orange">

               <cfquery ....>
                    INSERT INTO Table (....)
                   VALUES (
                             <cfqueryparam value="#value1#" ...>
                             , <cfqueryparam value="#value2#" ...>
                    )
              </cfquery>
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

Today, I was working on some optimization and spam-stopping techniques when I encountered Ben Nadel's post to reduce spam feature using Math (http://www.bennadel.com/blog/197-How-I-Stop-Spammers-On-My-ColdFusion-Blog.htm). While this method is not o…
Hi, Even though I have created this Tutorial on My personal Blog, Some people might not able to find my website, So here i am posting it again Today, from the topic it is very clear that i will be showing you here the very basic usage of how we …
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now