[THIN] Re: Preventing users from using Save AS in Nfuse 1.7

  • From: Frank Monroe <Frank.Monroe@xxxxxxxxxxx>
  • To: "'thin@xxxxxxxxxxxxx'" <thin@xxxxxxxxxxxxx>
  • Date: Thu, 2 Jan 2003 11:56:33 -0500

I'm not worried about the security because ticketing takes care of that.  I
am trying to fix user behavior of trying to take shortcuts to get to the
server.  When they do this, they override the load balancing and fault
tolerance.

-----Original Message-----
From: Ron Oglesby [mailto:roglesby@xxxxxxxxxxxx]
Sent: Thursday, January 02, 2003 11:07 AM
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: Preventing users from using Save AS in Nfuse 1.7



I had one of my guys copy the code from Columbia and stuff it into the
Nfuse 1.7 pages for a client. I might be able to get the code for you
but it could take a bit.

The reason we don't worry about this to much with 1.7 is most
implementations use the CSG. And with this and 1.7 deleting the ICA file
after use saving it isn't such a big deal.=20

The other reason is that even with it disabled. You can hold down the
left mouse button then right click (or shift right click I forget now)
and still get the ica file. So it really wasn't a good security feature.

Ron

Ron Oglesby
Senior Technical Architect
=20
RapidApp
Office 312.372.7188
Mobile 312.961.2380
email roglesby@xxxxxxxxxxxx
=20

-----Original Message-----
From: Alexander Danilychev [mailto:teknica@xxxxxxxxxxx]=20
Sent: Thursday, January 02, 2003 9:50 AM
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: Preventing users from using Save AS in Nfuse 1.7


Well, it is not very useful.

If you use ticketing (and you should) shortcut will expire on first=20
execution or over short time.

Preventing people from right clicking the browser is done mostly via
Java=20
script, so if you have old Columbia pages - copy Java script from there.

The issue is with the user ability to bypass Java script (or VB Script).
The only solid solution is to implement custom Browser which has right
click=20
disabled. If you are interested I can post a download from my old
project -=20
you can actually completely lock user from getting away from where you
want=20
them to go + no right clicks (done within exe, no script)

On another hand, Admin tools for Internet Explorer can lock things very
well=20
this days.

ALEX







>From: "Ron Oglesby" <roglesby@xxxxxxxxxxxx>
>Reply-To: thin@xxxxxxxxxxxxx
>To: <thin@xxxxxxxxxxxxx>
>Subject: [THIN] Re: Preventing users from using Save AS in Nfuse 1.7
>Date: Thu, 2 Jan 2003 08:27:01 -0600
>
>
>You mean the Right click save as to save the ICA file?
>
>Ron Oglesby
>Senior Technical Architect
>=3D20
>RapidApp
>Office 312.372.7188
>Mobile 312.961.2380
>email roglesby@xxxxxxxxxxxx
>=3D20
>
>-----Original Message-----
>From: Frank Monroe [mailto:Frank.Monroe@xxxxxxxxxxx]=3D20
>Sent: Thursday, January 02, 2003 7:45 AM
>To: thin@xxxxxxxxxxxxx
>Subject: [THIN] Preventing users from using Save AS in Nfuse 1.7
>
>
>With Project Columbia  it was possible to prevent users from using
"Save
>As"
>or "Copy Shortcut" to save the launch.asp file.  Does anyone know how
to
>do
>the same under Nfuse 1.7?
>***********************************************=3D20
>This Weeks Sponsor: 99point9.com
>The 99Point9.com Online Tech Support=3D20
>Helpdesk is the one-stop solution for all=3D20
>your server-based computing needs.=3D20
>http://www.99point9.com
>************************************************
>For Archives, to Unsubscribe, Subscribe or=3D20
>set Digest or Vacation mode use the below link.
>
>http://thethin.net/citrixlist.cfm
>***********************************************
>This Weeks Sponsor: 99point9.com
>The 99Point9.com Online Tech Support
>Helpdesk is the one-stop solution for all
>your server-based computing needs.
>http://www.99point9.com
>************************************************
>For Archives, to Unsubscribe, Subscribe or
>set Digest or Vacation mode use the below link.
>
>http://thethin.net/citrixlist.cfm


_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE*=20
http://join.msn.com/?page=3Dfeatures/virus

***********************************************=20
This Weeks Sponsor: 99point9.com
The 99Point9.com Online Tech Support=20
Helpdesk is the one-stop solution for all=20
your server-based computing needs.=20
http://www.99point9.com
************************************************
For Archives, to Unsubscribe, Subscribe or=20
set Digest or Vacation mode use the below link.

http://thethin.net/citrixlist.cfm
*********************************************** 
This Weeks Sponsor: 99point9.com
The 99Point9.com Online Tech Support 
Helpdesk is the one-stop solution for all 
your server-based computing needs. 
http://www.99point9.com
************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link.

http://thethin.net/citrixlist.cfm
*********************************************** 
This Weeks Sponsor: 99point9.com
The 99Point9.com Online Tech Support 
Helpdesk is the one-stop solution for all 
your server-based computing needs. 
http://www.99point9.com
************************************************
For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link.

http://thethin.net/citrixlist.cfm

Other related posts: