Go Back   FlashFXP Forums > > >

Bug Reports Report bugs here.

 
 
Thread Tools Display Modes
Old 10-27-2005, 06:55 PM   #1
smyr
Junior Member
FlashFXP Beta Tester
 
Join Date: Jul 2005
Posts: 7
Exclamation password security bypass!!

* FlashFXP v[3].[3.4], build [1106 ], [x]registered, [ ]unregistered, [ ]pirated
* OS [x] WinXP, [ ] Win2K, [ ] Win98, [ ] WinME, [ ] Other
* Running behind NAT/router [x] Yes & Model [Belkin F5D7230-4], [ ] No, [ ] Not sure
* Running firewall [x] Yes, Name [Belking h/w router], Ver. [ ], or [ ] No
* Running Antivirus [x] Yes, Name [Ontrack Systemsuite 6] or [ ] No
* Network [ ] xDSL, [x] CABLE, [ ] Dail-Up, [ ] Other

When setting password for Flashfxp using the "Sites/Security/Set Password" option you can *easily* bypass this if you already have a Flashfxp session opened in the background minimized to the system tray by right clicking on the Flashfxp icon and selecting "New Session. Viola, a new window pops up *without* any passwords being asked thus bypassing this vital funtion!!

This is really serious I think and has to be fixed!

Reg. Marc,
marc@smyr.net
http://www.smyr.net
smyr is offline  
Old 10-27-2005, 08:40 PM   #2
Hetfield
Senior Member
FlashFXP Scripter
 
Join Date: Nov 2002
Posts: 334
Default

Why is this serious if FlashFXP is allready started?
Hetfield is offline  
Old 11-22-2005, 06:11 PM   #3
Makc666
Member
FlashFXP Beta Tester
 
Makc666's Avatar
 
Join Date: May 2004
Location: MSK-RU
Posts: 79
Default

I think that the password must be asked not when you start FlashFXP, but when you open "Site Manager" (F4).
I think a future can be made for this, so user can select if he wants to enter password when program stars (once), or every time when he calls for "Site Manager".
Makc666 is offline  
Old 11-23-2005, 03:10 AM   #4
Linkster
Moderator
Administrator
 
Join Date: Oct 2001
Location: New Mexico, USA
Posts: 1,070
Default

if you are worried about security, I suggest you "lock" flashfxp upon minimize...ctrl+minimize. this will prevent opening the current or new sessions without the pwd
Linkster is offline  
Old 11-23-2005, 08:03 AM   #5
Makc666
Member
FlashFXP Beta Tester
 
Makc666's Avatar
 
Join Date: May 2004
Location: MSK-RU
Posts: 79
Default

Quote:
Originally Posted by Linkster
if you are worried about security, I suggest you "lock" flashfxp upon minimize...ctrl+minimize. this will prevent opening the current or new sessions without the pwd
Thanks. Found it in:
Quote:
Interface - Shortcut Keys
F9 Minimize to System Tray (Hide)
F9+Ctrl Minimize to System Tray (Hide & Lock) - Prompts for password if none set
May be add one more line to help, like:
Ctrl+Minimize with the same description as for F9+Ctrl
Makc666 is offline  
 

Tags
bypass, flashfxp, password, running, [x]

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 07:03 PM.

Parts of this site powered by vBulletin Mods & Addons from DragonByte Technologies Ltd. (Details)