[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: GEMS Connect to Data Base security crack



Apologies,
This is of course in context of the system lockout requirement imposed by
Texas cert where only the Gems application can be allowed to run and the
normal explorer shell is not active.

 -----Original Message-----
From: 	owner-bugtrack@dieboldes.com [mailto:owner-bugtrack@dieboldes.com]  On Behalf
Of jeffh@dieboldes.com
Sent:	Friday, March 22, 2002 10:49 PM
To:	bugtrack@dieboldes.com
Subject:	GEMS Connect to Data Base security crack

All versions, probably
"Load" function -> Open with -> Right mouse click on gbf -> delete gbf, etc.

This is a security breach as no password is required to delete virtually any
file on the system, along with the ability to run any application, etc.
We should limit the functionality of the Open With and Save As dialogs or at
least require the obligatory  password prior to their invocation.