Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Web Companion Security

Featured Replies

Specifically what kind of vulnerability did they find? Was it Mac or Windows?

What version FMP and is the progam patched to the latest level?

The web security admin

A security sweep of our NT server with Filmaker

Pro 5 unlimited on it showed we were vulberable to hackers. The web companion allowed averlaying of long HTTP GET requests. And it could overright the stack. This allows hackers to execute their code on our machine.

  • Author

Ok, but remember Web Companion isn't a "typical" or "normal" web server: it's designed solely as an interface to FMP. So even if there is a vulnerability, web companion might not understand or process the code anyway.

I'd be more worried about shared databases without passwords etc.

quote:

Originally posted by jimpres:

A security sweep of our NT server with Filmaker

Pro 5 unlimited on it showed we were vulberable to hackers. The web companion allowed averlaying of long HTTP GET requests. And it could overright the stack. This allows hackers to execute their code on our machine.

Suggestion: run WebCompanion on separate machine and serve the Web trough main NT IIS with WebConnector. That way al the security is provided by IIS machine.

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.