Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Can FM Server get infected??

Featured Replies

I feel I must know this: can FM Server be infected with a virus from a client FM machine?

We do not have an e-mail client on the server, but it is obviously on the network. So if a client gets infected with something like a Goner virus, could it potentially get to our server??

Thanks and keep protected

If your FM Server is a dedicated machine and there are no shared drives/volumes, there is no way FMS can be infected by a virus via the FileMaker host connection.

It is possible an email virus file could end up on a drive of the machine, but if it does not have email software on it like Outlook or Lotus Notes, there is no way it can 'spread' an email virus.

That is not to say that an FMS cannot be infected by other types of viruses like a worm. If the server is administered with some sort of remote admin software like Timbuktu, SMS, or PC Anywhere there might be a chance that a virus could infect the machine.

Actually, something like a Word macro virus--remember those--can indeed infect files hosted on FileMaker Server. And this can occur cross-platform. Do NOT run virus checking software on the CPU running FIleMAker SServer, but you can have it installed to be run manually on command on CLOSED files only.

HTH

Old Advance Man

  • Author

dykstrl,

Our machine is indeed dedicated, but I have Remote Server Administration plug-in enabled, so that I can send messages to users and such. Would you recomend disabling it?

This is not third party tool, but comes with FM Server 5.0.

I hardly ever use it, and the infection possibility concerns me.

  • Author

Actually, something like a Word macro virus--remember those--can indeed infect files hosted on FileMaker Server. And this can occur cross-platform. Do NOT run virus checking software on the CPU running FIleMAker SServer, but you can have it installed to be run manually on command on CLOSED files only.

HTH

Old Advance Man

Dear Old Man, not sure if I understand. You recommend not running anything like Norton AntiVirus on the Server machine? I do have it installed there, but it's not updated since the machine isn't connected to the Internet. Why do you suggest not having it?

What do you mean by "Word macro virus"? Sorry for the ignorance.

The Remote Server Administration uses the ordinary FileMaker connection directly from the administrator (client) and FMS.

I think OAM is right about the Word Macro viruses - I didn't think about those - especially the more sophisticated ones that call ActiveX commands.

At the same time, we have been running quite a few FM Servers for years (since FM server cames out) on both platforms and have not had a single virus problem with any of them - and only the NT boxes have anti-virus software installed, but is not running. We even have a FM Server on a Mac connected outside our firewall (wide open) and it has not been touched in the 3 years it has been there.

It's OK to have an antivirus program running on the CPU running FileMAker Server. Just do nmot let it automatically scan, especially open FIleMAker Pro files. It can be made to scan on command, but quit or stop the FM Server app/service first.

I do not believe that sending a message with the Remote Admin toll could propagate a virus. But I will make an inquiry.

Old Advance Man

  • 5 months later...
  • Author

Not to scratch the old itch, but I'm still not sure how to keep the FMS from being infected with Macro viruses.

Additionally, what's the best way to protect individual clients from hacks? (clients must be connected to the internet)

Thanks

RE: Not to scratch the old itch, but I'm still not sure how to keep the FMS from being infected with Macro viruses.

Macro virus need host application e. g. Word, Excel etc. In theory it is possible to create some VB or AppleScript virus that will affect FileMaker. But not simple Macro designed to run within MS Word.

Probably the big difference is whether the server is a Mac or PC. I've seen exactly 3 Mac viruses in 17 years of supporting the platform (never on FileMaker Server), and one was the Word macro virus. I've seen two PC viruses in the last week (but not on FM Server, NT 4.0). If files are not shared on the FM server, there is almost no path for the virus to move to the server.

-bd

  • Author

Thank you for your replies, they're reassuring. I also assume, that if the client is connected to internet on Port 80 there's no danger to FMP files hosted on the FMS server? Please say it is so...

PS Anatoli, I miss Prague in May, and Staropramen is an excellent beer!

Prague is quite nice in May/June smile.gif

I am moving to LA in end of June smile.gif You can get the Pilsner Urquell on tap in most cities around the world, just try it! It is a bit more bitter, but excellent quality.

The HTML files can get infected with things like Nimda I guess.

More problematic is absolute nonexistent security for hosted database. Any hacker equipped by browser can get all data from any database.

We developed our own security filter to protect our clients.

  • Author

Thanks, I'll try it.

Let me get this straight, are you saying that if a clent FMP opens a db hosted on FMS server, hackers can steel or modify the data?

Do they hack the network flow of data, or take control of the client machine? What if you're sitting behind the firewall?

Uhh..that's scary

RE: that if the client is connected to Internet on Port 80 there's no danger to FMP files hosted on the FMS server? Please say it is so...

In this scenario I assumed you are talking about port 80 served by WebCompanion and clients using browsers.

If it is not available on web, just on local network and/or behind good firewall then it depends on security of such firewall.

On web anybody can get to db for full listings of all records.

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.