Skip to content

Instantly share code, notes, and snippets.

@JamoCA
Created May 1, 2014 19:01
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 2 You must be signed in to fork a gist
  • Save JamoCA/664fd2a3661fc7d75ab1 to your computer and use it in GitHub Desktop.
Save JamoCA/664fd2a3661fc7d75ab1 to your computer and use it in GitHub Desktop.
Block access to ColdFusion web application based on bogus, pre-existing cookies that aren't used.
<cfscript>
BadCookieList = [
"ASP.NET_SessionID",
"ISFIRSTVISIT",
"PHPSESSID",
"REMEMBERCOUNTRY",
"RESOURCEINFO",
"SESSIONS",
"SS_MID",
"USERINFO",
"WEB",
"WebPersCookie",
"bb_lastactivity",
"bb_lastvisit",
"bb_sessionhash",
"negotiation",
"osCsid",
"ss_lastvisit",
"siteCookie"];
for (i=1;i LTE ArrayLen(BadCookieList); i=i+1) {
if (StructKeyExists(Cookie, BadCookieList[i])){
pc = getpagecontext().getresponse();
pc.getresponse().setstatus(503, 'Service Unavailable');
abort;
}
}
</cfscript>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment