Disable the createObject() function and <cfobject> tag. At least the Java form of them, if the sandbox controls are that granular.
This is exactly why many hosting providers do not allow the use of those tags, so that users can not access the underlining CF java objects like service factory.
Thanks Ian, however I already am aware of disabling CFOBJECT and CreateObject but wanted to know more if their was any way to disable access to the ServiceFactory object alone without doing the latter.
Something more granular maybe such as possibly altering some of the NEO*.XML files to shut off access to the ADMIN API only.
None of which I have ever heard.
I can't imagine anything in the neo*.xml files that would apply.
If anything like that could even be considered, I think it would have to be accomplished somewhere between the OS and Java layers.
I think the only workaround is to employ "Sanbox Security".
By doing so, I believe that access to the CFIDE/AdminApi is possible ONLY if you setup folder access to that directory.
Thanks for the help.