Jump to content
WnSoft Forums

run application action security


tom95521

Recommended Posts

Thanks everyone.

I hope the additional programming doesn't take away from the cool stuff being developed already. I think as a group we can help make great software even better. Now to get back to playing with the program....

tom95521

Link to comment
Share on other sites

Hi, Tom,

Thanks for the information - I didn't know that it was now possible now to add command line parameters to a run external file command. However, this is still not a serious problem since, as Granot said, the authors of PTE shows are identified and known, and if they were to insert malicious coding we would know who they are, so they are not likely to do this. Theoretically it is possible, but not likely to happen.

However, I agree with you that now that the "cat is out of the bag" we need to protect ourselves, and Igor's suggestion sounds like a reasonable one to me.

Another precautionary measure would be for PTE to be designed such that there was a warning message whenever a "run external application" command was used in a show. Most shows, particularly those on Beechbrook or those shows entered into competitions, would never have occasion to display this message, unless there was a problem. These shows do not usually use the "external application" feature as they are stand-alone shows, so the provision of such a message would not be a distraction to them as no one would ever see it. :)

Link to comment
Share on other sites

Igor,

As always, you have responded quickly to the needs of the PTE community. Your suggestion to prohibit ‘potentially dangerous commands‘ from running sounds like an excellent solution to the risk factors pointed out to us by Tom.

As many have mentioned, the ‘risk’ of malicious code being used, within the PTE user group, is probably zero, but it is much better to be safe than sorry.

Your quick thinking and prompt action will undoubtedly put many minds at ease.

Thank you Igor ~ and thank you Tom for bringing this topic to our attention.

bjc

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...