March 8, 200124 yr Specifically what kind of vulnerability did they find? Was it Mac or Windows? What version FMP and is the progam patched to the latest level?
March 8, 200124 yr A security sweep of our NT server with Filmaker Pro 5 unlimited on it showed we were vulberable to hackers. The web companion allowed averlaying of long HTTP GET requests. And it could overright the stack. This allows hackers to execute their code on our machine.
March 10, 200124 yr Author Ok, but remember Web Companion isn't a "typical" or "normal" web server: it's designed solely as an interface to FMP. So even if there is a vulnerability, web companion might not understand or process the code anyway. I'd be more worried about shared databases without passwords etc.
March 11, 200124 yr quote: Originally posted by jimpres: A security sweep of our NT server with Filmaker Pro 5 unlimited on it showed we were vulberable to hackers. The web companion allowed averlaying of long HTTP GET requests. And it could overright the stack. This allows hackers to execute their code on our machine. Suggestion: run WebCompanion on separate machine and serve the Web trough main NT IIS with WebConnector. That way al the security is provided by IIS machine.
Create an account or sign in to comment