Jump to content
Claris Engage 2025 - March 25-26 Austin Texas ×

This topic is 4707 days old. Please don't post here. Open a new topic instead.

Recommended Posts

Posted

In some articles Steven Blackwell tell us the risk of using an opening script to perform some security in our databases, but what is best solution in other to perform the same procedure:

1. Using a startup layout without data, buttons or other things. This is showed in ISO Magazine. So if any user tries to cancel the open script it goes to nowhere.

2. Create a privilege just to see the startup layout and a button in startup layout to do all magic, change the user privilege to other and make the activation.

Posted

The vulnerability here is that it's a fairly trivial exercise to bypass the opening script and open the file. Obviously someone doing this must have some sort of credentials to open the file.

So if any user tries to cancel the open script it goes to nowhere.

Canceling the script isn't the threat vector here. So that really has no bearing on the situation. It's that the script never even runs if it's bypassed unless other steps have been taken.

Steven

  • 2 weeks later...

This topic is 4707 days old. Please don't post here. Open a new topic instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.