PDA

View Full Version : password security bypass!!


smyr
10-27-2005, 06:55 PM
* FlashFXP v[3].[3.4], build [1106 ], [x]registered, [ ]unregistered, [ ]pirated
* OS [x] WinXP, [ ] Win2K, [ ] Win98, [ ] WinME, [ ] Other
* Running behind NAT/router [x] Yes & Model [Belkin F5D7230-4], [ ] No, [ ] Not sure
* Running firewall [x] Yes, Name [Belking h/w router], Ver. [ ], or [ ] No
* Running Antivirus [x] Yes, Name [Ontrack Systemsuite 6] or [ ] No
* Network [ ] xDSL, [x] CABLE, [ ] Dail-Up, [ ] Other

When setting password for Flashfxp using the "Sites/Security/Set Password" option you can *easily* bypass this if you already have a Flashfxp session opened in the background minimized to the system tray by right clicking on the Flashfxp icon and selecting "New Session. Viola, a new window pops up *without* any passwords being asked thus bypassing this vital funtion!!

This is really serious I think and has to be fixed!

Reg. Marc,
marc@smyr.net
http://www.smyr.net

Hetfield
10-27-2005, 08:40 PM
Why is this serious if FlashFXP is allready started?

Makc666
11-22-2005, 06:11 PM
I think that the password must be asked not when you start FlashFXP, but when you open "Site Manager" (F4).
I think a future can be made for this, so user can select if he wants to enter password when program stars (once), or every time when he calls for "Site Manager".

Linkster
11-23-2005, 03:10 AM
if you are worried about security, I suggest you "lock" flashfxp upon minimize...ctrl+minimize. this will prevent opening the current or new sessions without the pwd

Makc666
11-23-2005, 08:03 AM
if you are worried about security, I suggest you "lock" flashfxp upon minimize...ctrl+minimize. this will prevent opening the current or new sessions without the pwd

Thanks. Found it in:
Interface - Shortcut Keys
F9 Minimize to System Tray (Hide)
F9+Ctrl Minimize to System Tray (Hide & Lock) - Prompts for password if none set

May be add one more line to help, like:
Ctrl+Minimize with the same description as for F9+Ctrl