31
HFS ~ HTTP File Server / Re: Warning: HFS v2.x has a severe vulnerability
« Last post by LeoNeeson on January 09, 2025, 12:58:25 AM »Could you check my versions, if it vulnerable or not? As I'm not really understand your answers per my fixes.I've sent you a private message because I can't run x64 apps.
You can use 1Fichier to upload files if that's easier for you.
Until then, I can't review your version; I'm sorry...

I really don't understand, why you afraid only 'exec' macros. With "save" macros it's possible to do the same (if write 'bat' or 'lnk' file). With 'add folder' - it's possible to add home folder of active user, and maybe download something private.I completely agree with you (and I was already aware of all that).
it is always possible to use version 2.2f which makes it possible to distribute content as one looks at a film,We can have the best of both worlds if we do this:
(Ideas) The best way to achieve good security would be:
• Make the default template not use or require any macros at all.
• Make the entire macro system behave exactly like user permissions.
• Have a config panel to let HFS admin choose which macros are enabled.
Even then, nobody could guarantee 100% permanent security forever...

Making all those changes will take a lot of work, time, and testing.
(but it will provide all the features without compromising security)
Recent Posts



