Want to get rid of Google Ads, click here.
+ Reply to Thread
Results 1 to 5 of 5

Thread: Builtin debugger

  1. #1
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,271

    Default

    The debugger is available for ALL users in SC3SP3 with application level A9901! It is fixed in SP4 with A9902.



    This means that any user can open the debugger and grant himself SysAdmin capability! >=(







    [Edited by admin on 27-11-2001 at 08:44 PM GMT]

  2. #2
    Senior Member eisefr's Avatar
    Join Date
    Nov 2001
    Location
    Germany
    Posts
    538

    Default

    If you tell your users how they change the capability-words.... :smile:

    THEN its your own fault...

  3. #3
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,271

    Default

    Offcourse, that can be said about almost any of the security holes I know of. They are there but it does require knowledge to exploit it.



    I have knowledge about a few security holes



    Regards Tommy

  4. #4
    Senior Member eisefr's Avatar
    Join Date
    Nov 2001
    Location
    Germany
    Posts
    538

    Default

    Ok.. that debugger problem i seen already..

    But honestly... i didn't look for any security-problems in SC3. Cause none of my users have that knowledge to destroy something. Not even by a mistake.



    What i do of course, is i make from all important files a unload at night.. at least every 2 weeks... some important files every night. So even IF someone destroys datas or formats, links or something like that.. i have a backup from everything.



    ANd we make every night a backup from our server on tape.



    You dont think that should be enough?



    IF someone would play around with something what he is not allowed to.. i have still the option to kick him really hard :grin:

    <kidding>

  5. #5
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,271

    Default

    How much You should do is always dependant on an assesment of risk.



    For example we backup all the files every second hour. But in our sc we also register approx 22000 calls a month and approx 8000-10000 problems.



    Regards Tommy

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts