Jump to content
Claris Engage 2025 - March 25-26 Austin Texas ×

So, what's wrong with this system...


This topic is 8090 days old. Please don't post here. Open a new topic instead.

Recommended Posts

Posted

Don Wieland kindly gives out a user password system at:

http://www.dwdataconcepts.com/dwdctips.htm

Looks pretty good so far. So what are the weaknesses of this system?

What are its vulnerabilities? Why should I NOT use it?

Do others use similar approaches?

Thanks!

Posted

Don's systems seems OK, although quite simple.

I used concepts from Chris and Bob system, as well as my own knowledge and created a system which uses quite a few files, but is pretty secure and could be implemented on an enterprise-wide basis with quite a bit of variation of security.

Basically there are 3 core files: LogIn, _UserPriv, and _LauncherPriv. The LogIn file is what the user interracts with and enteres thier username and password. _UserPriv validates the users and returns thier access level. _LauncherPriv validates the access level and runs another launcher with the specific Filemaker Security level built into it.

You then need another launcher file for each Filemaker Password/Security Level.

A further Privledges file would specify specific functionality privledges for each user.

It was a little complicated to setup, but very powerful and pretty easy to manage.

Posted

I think Don's system needs work. I gained full access to the Users file with a one-step script in another file.

I imagine that this limitation could be overcome by some sort of security check within each of the Users file's scripts, i.e. prevent them from being run if called from a file that is not Menu.

  • 2 weeks later...
Posted

Okay, so you smart guys broke into Don's system easily. And thus, I took the advice and got the Moyer/Bowers book, learned their system (and why Don's failed), and basically incorporated it, with some small adaptations and fixes, into my relational template. Wanted to point to that from this thread, for those that find this thread looking for a security solution.

So, now I ask the same question, but for a different system...

What's wrong with the security system in the relational template that I just posted to the Sample Files forum?? Can you smart guys crack it (without having access to the physical files)??

Thanks!

This topic is 8090 days old. Please don't post here. Open a new topic instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.