Previous Issue Current Issue Main page Next Issue
Fusion Authority Fusion Authority
The House of Fusion Technical Magazine
Issue: 39

September 4, 2000
September 10, 2000
This is an opt-in magazine. To join, leave or change subscription mode, please visit the signup page. All content of this magazine is copyright Fusion Authority, Inc. It may not be reproduced without permission.

Specials
Late issues
 
Community
Allaire Looking for Killer Apps
Michael Dinowitz to Speak on Monday at Software Summit 2000
Allaire Certified Professional Program Now a Go!
Allaire DevCenter News, August Issue, Comes Out
JRun Beta Now Available in Japanese for Windows/Linux
 
News
Special Savings on ColdFusion Server Upgrades with Two-Year Subscription!
Allaire Corp. Ranks in Top 10 of New England's Fastest- Growing Technology Companies
Dialog Server From ActionPoint Integrates with HomeSite
SurfKitchen to Unveil Wired and Wireless Portal Service That Uses JRun
Eprise Announces Support for UDDI, Makes ColdFusion Integration Agent Available
Metaserver Offers Software-Based e-Business Integration
Ektron Releases Latest Version of eWebEditPro
Rival Camps Form In App Server Market
Imation Media Manager Gets New ColdFusion-Based Interface
 
Tech and Tags
What's new in the Tag Gallery
WebReview's Fun with ColdFusion Series Continues
Defusion Muses: To Lock, or Not to Lock
CFUN-2k: Shlomy Gantz Makes Presentation on Flash Available
Web based Custom Tag Wizard
 
Techniques
Introduction to JavaScript
Allaire Case Study: Youth Hostels of Australia
Allaire Case Study: oneworld alliance
ColdFusion Caching: Super Bowl Champs' Secret Weapon
 
Security
Allaire Security Bulletin (ASB00-24): Microsoft (MS00-060): Patch Available for IIS Cross-Site Scripting Vulnerabilities
Allaire Security Bulletin (ASB00-25): Microsoft (MS00- 063): Patch Available for Invalid URL Vulnerability
Spotting Intrusions: A Real-Life Scenario
CNet News Reports Unix, Linux Computers Vulnerable to Damaging New Attacks
 
Knowledge Base
Shared Memory Changes in Service Pack 1 (Solaris)
MDAC on Windows 2000 SP1
Using X.509 Certificate Authentication with ColdFusion
 
Stock
Other stock news
Weekly Numbers
 

Specials

Late issues

Due to work being done on the Fusebox book, both this issue of Fusion Authority and the next one are late. This did have a positive effect in allowing us to have most of the news here and all of the stock information in the next issue. With the fluctuation of the stock in the last few weeks, a single issue dedicated to two weeks of stock information should prove useful to people. We apologise for the inconvenience.

[Top]


Community

Allaire Looking for Killer Apps

Have you written a really cool, well-coded ColdFusion application? If so, send it over to Allaire and they'll highlight your work in their Devcenter! E-mail a brief description (less than 500 words) of your Web application along with your contact information to David Golden at dgolden@allaire.com.

[Top]

Michael Dinowitz to Speak on Monday at Software Summit 2000

Attendees of the New York Software Summit 2000 will get a chance to hear Michael Dinowitz, publisher of this magazine and well-known ColdFusion Guru, speak on "Web Building Blocks: A Strategy for Robust Web Development." The conference will be held at the Brooklyn Marriott (333 Adams Street, Brooklyn, NY) this coming Monday. Michael will be speaking at the second workshop, scheduled from 11:45 am to 1:00 pm.

Information on the New York Software Summit 2000 can be found at http://www.nysoftwaresummit.org/intro.htm. Information on Michael's specific track can be found at http://www.nysoftwaresummit.org/web.htm.

[Top]

Allaire Certified Professional Program Now a Go!

Allaire's official certification program is out of the beta stage and available to all developers. Allaire suggests the following prerequisites before you take the certification exam:

The exam consists of approximately 61 multiple-choice questions, in a secured, proctored environment. People who preregister to test at the Allaire conference receive a discount!

For more information, see http://www.vue.com/allaire/.

[Top]

Allaire DevCenter News, August Issue, Comes Out

Some highlights of this issue are: News about the Allaire Certified Professional Program, news of Allaire's request for killer apps (see news items above), and technical articles.

Allaire DevCenter News (August)

[Top]

JRun Beta Now Available in Japanese for Windows/Linux

Allaire has released the latest beta of JRun for Windows/Linux, in Japanese:

Allaire Beta Download Site

[Top]


News

Special Savings on ColdFusion Server Upgrades with Two-Year Subscription!

A limited time offer from Allaire: When you purchase a two-year subscription with your ColdFusion Server 4.5 upgrade, you'll automatically save 20% of the upgrade list price!

Allaire Special Offer Page

[Top]

Allaire Corp. Ranks in Top 10 of New England's Fastest- Growing Technology Companies

BOSTON, Sep 13, 2000 (BUSINESS WIRE) -- The professional services firm of Deloitte & Touche and the law firm of Hale and Dorr LLP, in association with Mass High Tech, the Journal of New England Technology, have announced the ranking of the 2000 New England Technology Fast 50 and Rising Stars. This annual program ranks the region's fastest-growing technology companies on the basis of five-year and three-year revenue growth, respectively. Allaire Corp. ranked among the top ten Rising Stars honored in the New England program, each of which posted three-year revenue gains in excess of 2,000%.

Powerize Alert: BusinessWire

Powerize Alert: PR Newswire via COMTEX

ZDNet Tech Infobase Article

[Top]

Dialog Server From ActionPoint Integrates with HomeSite

SAN JOSE, Calif., Sep 13, 2000 /PRNewswire via COMTEX/ -- ActionPoint, Inc., a leading provider of e-commerce interaction management software, has announced the first customer shipment of ActionPoint Dialog Server(TM), an XML-based software product that makes it easy for e-businesses to rapidly deploy intelligent, personalized Web interfaces, turning every Web experience into a live interaction that happens in real time. The server integrates with Allaire's HomeSite.

ActionPoint Launches Dialog Server (Powerize Alert)

ActionPoint Launches Dialog Server (ZDNet Tech Infobase)

ActionPoint Launches Dialog Server (Northern Light News Alert)

[Top]

SurfKitchen to Unveil Wired and Wireless Portal Service That Uses JRun

ZURICH, Switzerland and NEW YORK, Sep 12, 2000 (BUSINESS WIRE) -- SurfKitchen Inc. will use PCIA GlobalXChange Chicago, Sep 27-29, 2000 as the launch site for SurfKit(TM) v2.0, a comprehensive solution for wired and wireless portals. SurfKit's unique technology addresses all major issues that portal operators face when providing applications for the Wireless and changing Internet market, relying heavily on Allaire's JRun.

SurfKitchen to Unveil SurfKit v2.0--the Wired and Wireless Portal Service at PCIA GlobalXchange in Chicago (Powerize Alert)

SurfKitchen to Unveil SurfKit v2.0 (ZDNet Tech Infobase--Article Only for Pay)

Northern Light News Alert

[Top]

Eprise Announces Support for UDDI, Makes ColdFusion Integration Agent Available

FRAMINGHAM, Mass., Sep 11, 2000 (BUSINESS WIRE) -- Eprise Corporation, a leading provider of advanced content management software for dynamic Web sites, has announced its support for the Universal Description, Discovery and Integration (UDDI) Initiative, reinforcing the company's dedication to providing completely open Web content management solutions that promote business-to-business Internet commerce. Eprise(R) is the first content management company to join the initiative and plans to implement the UDDI specifications to ease business- to-business Internet commerce integration roadblocks by providing a common mechanism to publish Web services on the Internet. There is a ColdFusion integration agent available.

Eprise Announces Support for UDDI (Powerize Alert)

Eprise Announces Support for UDDI (Northern Light News Alert)

[Top]

Metaserver Offers Software-Based e-Business Integration

Metaserver, Inc., (New Haven, CT) recently introduced Metaserver 2.5, the newest version of its software-driven application designed to help organizations migrate traditional business operations, processes, and technology from the enterprise to the Internet while maintaining their existing infrastructure. Metaserver takes business processes and automates them using the Web. Among the main target areas are the insurance, financial, manufacturing, retail distribution and utilities industries. ColdFusion Server is completely supported.

Metaserver Offers Software-based e-Business Integration (ZDNet Tech Infobase (MIDRANGE Systems 08/14/00))

[Top]

Ektron Releases Latest Version of eWebEditPro

Ektron, Inc., an Allaire Partner, has announced the availability of the latest version of eWebEditPro, a browser-based, WYSIWYG Web-content creation, editing, and publishing tool designed specifically for dynamic Web sites. This newest release of eWebEditPro features new Netscape compliance, international-language support, an intuitive installation wizard, and sample code that make it even easier for corporate IT departments and Webmasters to control site parameters and distribute Web content authoring throughout the organization.

eWebEditPro Product Page

Ektron Releases Latest Version of eWebEditPro (ZDNet Tech Infobase)

[Top]

Rival Camps Form In App Server Market

In the 9/3/00 edition of Inter@ctive Week, John T. Mulqueen looks at the battle shaping up between open standards and proprietary de facto standards in the e-commerce applications server market.

Rival Camps Form In App Server Market (ZDNet Tech Infobase (Inter@ctive Week, 9/3/00))

[Top]

Imation Media Manager Gets New ColdFusion-Based Interface

Seybold has released a report on Publishing Systems, by Patricia Evans, which discusses Media Manager's new Web interface. Based on Allaire's ColdFusion, the new interface will be able to customize the asset databases they offer, because the Imation interface source code will be accessible and documented. In addition, applications can be more scalable and security should be better.

ColdFusion for Imation Media Manager (ZDNet Tech Infobase (Seybold Report on Publishing Systems, 8/21/00))

[Top]



Tech and Tags

What's new in the Tag Gallery

Speed DB
Generates documentation and code for developing and distributing stored procedures in a team environment.
prophit
Pixel style font with multiple styles - fading, cell, dot and standard.
RSESSION
RSESSION is an outside-the-box ColdFusion state management framework. It is a nearly drop-in replacement for server-specific Session variables in your applications, and can be added in just minutes. It is designed to work in a clustered environment where loss of state during failover is not acceptable. This code turns does NOT need Application or Session scoped variables and consequently does NOT use CFLOCK anywhere, ever.
Sunrise/Sunset calculator
Calculates Sunrise and Sunset for a given Location on a given Date.
CF_BBS
CF_BBS is a turnkey message board/bulletin board system (BBS) application. It is implemented as a custom tag and is easily added to any website using only a single line of code, yet it contains many powerful features.
Orchestra by Crossdraw
Orchestra by Crossdraw is an easy-to-use, non-technical, self-contained group communication and collaboration web application that gets teams and committees managing and sharing information on-line.
CF_Custom Tag Wizard
Build your own custom tags and tag editors quickly with this web-driven replacement for HomeSite or ColdFusion Studio's Custom Tag Wizard.
Active Survey Engine 2.1 - Enterprise
Survey Engine 2.1 - Enterprise. Generic HTML form processing engine. Build web forms and collect data with advanced GUI interface. Get REAL TIME reports with built in collection of reports. Run surveys, polls, collect data without HTML knowledge.
EmailCheck
This app checks a email address to see if it is valid. If it is not valid, it submits an error message. Then it returns errorlevel and errorresponse.
cf_gbook (unencrypted)
This is a one page, database-driven guest book app that can quickly be included into existing websites. Input form is at the top of the page and messages load underneath, newest to oldest. Tag is unencrypted and free to use.
CF_EmailVerify 2.5
Determines if an Email Address is properly formatted by checking: - For at least 6 characters in the email (a@a.co) - That the User portion of the email has at least 1 character - That the Domain portion of the email contains at least 2 parts - That the Last Domain Element of the email contains between 2 and 5 characters - That there is only 1 @ symbol, which must be within the email address - That there is at least 1 period, which must be within the email address - That CompuServe users did not forget to replace the comma with a period - For No Spaces within the email address - For all non-AlphaNumeric characters within the email address
Log Manager
Streamline big log files created by CF server or the like to speed up server response. Best to schedule it. Very simple to install and use.
iiFramework
iiFramework is an add-on to ColdFusion that will make every ColdFusion developer 30 to 60% more productive. Build CF applications that are MORE manageable, scalabe and secure than possible with ColdFusion out of the box.
eggCart
eggCart is a perfect addition to a Internet Service Provider's web hosting service or for the Internet startup company that requires a shopping cart application to power their e-commerce website.
ResizeIngredient
Even though we don't like to admit it, the number one resource on the Web is recipes. Now, with the aid of this tag, recalculate ingredient portions to the best measure. Instead of seeing "48 tsp" in your recipe application, you'll see "1c". Supports english/metric conversion, long and short name output, auto pluralization of measures, and other stuff.
Alphanumeric random generator
Generates a random alphanumeric string with user-specified length. It may consist of numbers and letters (uppercase and lowercase). This tag can be used for password generation, table keys, cookies, etc.
Appointment Calendar (SIBER)
SIBER APPOINTMENT is a stylish outlook type on-line appointment calendar booking system. It has a user friendly interface displaying the year,months,days of the month and hours in the day on a single page. It enables users to add/edit and view appointments.
CF_GetMap
This ColdFusion Custom Tag generates a URL that can be used to retrieve a dynamically generated map from the www.mapblast.com web site. It uses an address and a zip code or postal code to retreive a longitude and latitude in order to build a URL for MapBlast!.
CF_DirMan
This tag allows you to manipulate directories and their contents very simply. There are four available actions: Move, Delete, Copy and List. Returns a report with the following values: Process Status, Size of directory and sub contents in MB and bytes, Number of levels, Number of sub directories, Total number of files, and a graph of the file structure. This is a very useful tag; however, it can be dangerous because it does work! Directories can be deleted or moved. You want to make sure the parameters that you pass to the tag are what you intend the tag to perform.
FuseObject Hybrid Database Admin VTM
Studio wizard to create admin pages for a single database table. It works, but will be improved considerably in short order. Interested in what improvements can be made, although I have a bunch I know in my head.
FuseTalk 1.4
FuseTalk is a powerful, fully scalable and customizable forums package that allows people within companies to interact in a common discussion area. fuseTalk offers users extensive customization features to meet your personal preferences. To keep administration time to a minimum, fuseTalk's administration module allows the administrator to set up the forum to virtually run by itself. This completely database-driven application ensures stability, speed, and ease of use for your discussion environment.

[Top]

WebReview's Fun with ColdFusion Series Continues

Building a Personal Information Manager (PIM) with ColdFusion

John Paul Ashenfelter continues his series with a hands-on run through of a simple application, building a PIM, starting from scratch with installation and configuration. Easy reading, and good practice in CF!

WebReview: Fun with ColdFusion, Part 2

[Top]

Defusion Muses: To Lock, or Not to Lock

John Cummings takes a look at <CFLock> and shared scope variable calls. It is accepted practice for developers to lock variables when there is a danger of the variable being overwritten, but whether or not to lock variables that will only be read has given many a developer pause. Cummings explores this issue in this new offering from Defusion.com.

To Lock, or Not to Lock

[Top]

CFUN-2k: Shlomy Gantz Makes Presentation on Flash Available

One of the highlights of CFun-2k was Shlomy Gantz' presentation about the latest developments in Flash. He has kindly made the presentation available on-line:

CF Fun 2000: Shlomy Gantz on Flash

[Top]

Web based Custom Tag Wizard

This was supposed to be listed in "What's new in the Tag Gallery," but it's just too cool to be buried there. It solves one of the biggest problems about custom tags that's ever existed: how to write the Studio user interface. This site provides a really great interface to a Custom Tag Wizard that will create a tag wizard for use inside of Studio. All you have to do is tell the wizard the attributes and values your custom tag expects and it will build a context editor in the Virtual Tool Markup Language used by ColdFusion Studio's tag editor. Tell the wizard how your tag works and optionally provide it with the logic for your tag and it will integrate the help file into the custom built tag editor and create a template for your new custom tag. When you click finish, the wizard will email your custom file to the email address you provided in first screen.

This gets my vote for one of the best tools for the community in a long time. Thank you, Bryan LaPlante, for writing this tag! My only wish would be for it to be available to people locally rather than through the net. Other than that, it's close to perfect.

Custom Tag Wizard

[Top]


Techniques

Introduction to JavaScript

Allaire's own Robert Crooks gives us a guide to JavaScript, available also in .pdf format. The primer is divided into two parts, "JavaScript Fundamentals" and "Functions, Events, and Complex Data Structures". Crooks touches on such things as JavaScript's relation to HTTP, advantages and disadvantages of JavaScript, syntax, variables, objects and much more. The guide also includes several exercises interspersed with the explanatory chapters. A worthwhile resource.

Introduction to JavaScript

[Top]

Allaire Case Study: Youth Hostels of Australia

An online booking facility has generated $200,000 in accommodation bookings, 80% of which is new business for Australian Youth Hostels, from travelers all over the world. These amazing statistics took place in its first three months of operation on the award-winning Youth Hostels of Australia (YHA) web site, which is ColdFusion-based.

Youth Hostels of Australia (YHA)

[Top]

Allaire Case Study: oneworld alliance

Australian Internet design and development company Red Square has created a unique fully managed Web site served out of Australia and housed on the first ColdFusion 4.01 Enterprise cluster in the southern hemisphere for seven of the world's leading airlines - the oneworld alliance.

Oneworld Alliance

[Top]

ColdFusion Caching: Super Bowl Champs' Secret Weapon

The St. Louis Rams proved as web-savvy as they were football heros when they captured the Lombardi Trophy in Super Bowl XXXIV. Much like the Rams' blazing foot speed, Web sites must also be quick to be a player in today's hyper-competitive Internet marketplace. If users must wait two minutes for a JPEG to download, they will likely give up and try somewhere else. Here's how the St. Louis Rams kept up with the demands of SuperBowl fans.

ColdFusion Caching, Super Bowl Champs' Secret Weapon

[Top]


Security

Allaire Security Bulletin (ASB00-24): Microsoft (MS00-060): Patch Available for IIS Cross-Site Scripting Vulnerabilities

Microsoft has released a patch that eliminates security vulnerabilities in Microsoft(r) Internet Information Server. The vulnerabilities could allow a malicious web site operator to misuse another web site as a means of attacking users. This is not an issue with ColdFusion Server, but it is an issue that can affect ColdFusion users, as described in the Issue section. Allaire recommends that customers follow the instructions posted on the Microsoft web site to address this issue.

Here’s more information on the topic:

Allaire Security Bulleting ASB00-24

[Top]

Allaire Security Bulletin (ASB00-25): Microsoft (MS00- 063): Patch Available for Invalid URL Vulnerability

Microsoft has released a patch that eliminates a security vulnerability in Microsoft(r) Internet Information Server (IIS). The vulnerability could enable a malicious user to prevent a web server from providing useful service. This is not a problem with the ColdFusion Server, but it is an issue that can affect ColdFusion users, as described in the Issue section. Allaire recommends that customers follow the instructions posted on the Microsoft Web site to address this issue.

For more info:

Allaire Security Bulletin ASB00-25

[Top]

Spotting Intrusions: A Real-Life Scenario

SecurityFocus offers an insightful look into a real-life security situation: "[H]ow do you know for sure if your security has been compromised? This article will teach you some techniques you can use to detect intrusions as they are happening and give you a leading edge in protecting yourself."

Spotting Intrusions: A Real-Life Scenario

[Top]

CNet News Reports Unix, Linux Computers Vulnerable to Damaging New Attacks

It was bound to happen sooner or later ... According to CNet News, security experts have uncovered a new class of vulnerabilities in Unix and Linux systems that let attackers take full control of computers.

Unix, Linux Computers Vulnerable to Damaging New Attacks (CNET)

[Top]


Knowledge Base

Shared Memory Changes in Service Pack 1 (Solaris)

The shared memory segment that cfstat/cfserver now use is created by cfserver. This means it is owned by the Coldfusion user.

Shared Memory Changes in Service Pack 1 (Solaris)

[Top]

MDAC on Windows 2000 SP1

On Win2000 SP1, executing a SQL statement with concatenation will cause the CFAS to hang. The reason? A reintroduced Microsoft bug in the MDAC that's installed with Win2000 SP1. This showed up when customers ran MSAccess on Win2000 SP1, but Allaire doesn't know if the bug is limited to MSAccess. Here's more information, and a workaround:

MDAC on Windows 2000 SP1

[Top]

Using X.509 Certificate Authentication with ColdFusion

ColdFusion Server 4.0.1 and higher supports X.509 client certificate authentication. This means that ColdFusion can now work with an SSL- enabled Web server such as Netscape Enterprise 3.5.1 or IIS 4.0 to request client authentication in the form of an X.509 certificate. The ColdFusion Application Server will extract the client information from the X.509 certificate and authenticate it against a user directory such as a Windows NT domain or an LDAP server. Here's how:

Using X.509 Certificate Authenticaion with ColdFusion

[Top]


Stock

Other stock news

All stock news for September 1 to September 22 will be located in the next issue. This is due to the extreme swing in the Allaire stock price that took place during this time and the amount of news that exists about it.

[Top]

Weekly Numbers

Date Open High Low Close Volume
8-Sep-00 28.4375 28.50 24.5625 25 3,024,900
7-Sep-00 30.0312 30.50 25.75 27.4375 3,432,500
6-Sep-00 32.2188 32.3125 30.75 31.1719 460,300
5-Sep-00 32.8125 33.125 29.50 32 1,751,900

[Top]

All articles are for informational purposes only and do not constitute a suggestion to buy, sell, or in any way trade in any stock or securities.



This is an opt-in magazine. To join, leave or change subscription mode, please visit the signup page. All content of this magazine is copyright Fusion Authority, Inc. It may not be reproduced without permission.