rejetto forum

Testing build #185

rejetto · 42 · 31124

0 Members and 1 Guest are viewing this topic.

Offline tsaukpaetra

  • Occasional poster
  • *
    • Posts: 3
    • View Profile
In regards to the "run as Administrator problem":
Programs that are run as administrator cannot receive inter-process messages (like if you drag+drop files) from a program of a different session.

What I mean by this is that because you are running Hfs as an administrator, other programs are not allowed to interact with it (for security purposes).
The thought-line was that since a program running as an Administrator has TOTAL access to the computer, and malicious program could be written to take control of that application (worst case scenario of course) and use it do cause harm to the computer. For an example, if a worm was written to watch for programs that have the ability to display the standard windows' "Open File Dialog" box, it could send it's location into the FileName field, send an "Enter" and !Boom! it is running as an Administrator can can do /anything/.
Worst case scenario, right?

But anyways, this is most noticeable for accounts that are Standard level. It might not apply to accounts already Administrators.


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13510
    • View Profile
indeed i use an admin account (and also UAC disabled)


Greek

  • Guest
it does apply to admin accounts. thank you tsaukpaetra :)

rejetto, you work as a programmer or programming is a hobby of yours?

thank you for this great little application! ;)

PS: why you don't have the sp1 installed?


Offline slayer

  • Occasional poster
  • *
    • Posts: 7
    • View Profile
Access violation at address 004AB7E6 in module 'hfs.exe'. Read of address 00000182
HFS 2.3 beta (185)
----------------------------------------------------------------
System   : Windows Vista Professional, Version: 6.0, Build: 1770, ""
Processor: Intel,               Intel(R) Pentium(R) 4 CPU 3.20GHz, 3280 MHz MMX
Display  : 1280x1024 pixels, 32 bpp
----------------------------------------------------------------
----------------------------------------------------------------
Product Versions


Access violation at address 00528762 in module 'hfs.exe'. Read of address 00000098
HFS 2.3 beta (185)
----------------------------------------------------------------
System   : Windows Vista Professional, Version: 6.0, Build: 1770, ""
Processor: Intel,               Intel(R) Pentium(R) 4 CPU 3.20GHz, 3280 MHz MMX
Display  : 1280x1024 pixels, 32 bpp
----------------------------------------------------------------
----------------------------------------------------------------
Product Versions

hfs.exe: Build: 0 09.04.2008 10:29:14
__hfs.exe: Build: 0 07.03.2008 13:21:56


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13510
    • View Profile

jerome

  • Guest
hello,

the function "rename" a user account loose all the preregistered data access list,
it is like create a new account from the begining.

it should be useful to enable this,
and also create a new function = copy a user account Login+pass+Data access list to create a new one ( ex: login name(+*) or "copy of" login name) using the same data list and the same pass, and paste a new login name on it. (when login rename will work)

to enable a nominative login, using a common pass and the same file list, in a few clic.

because if you have a long list of files, and you need many user personal login ( to identify dynamic IP ), it is very long to make it.


thank you to think about it for future build.


Offline ailef

  • Occasional poster
  • *
    • Posts: 24
    • View Profile
hello, i tested this tool on this HFS beta and here is the report, i had 10 vulnerabilities on 340 plugins, i think it's a good result.
maybe u'll find those results interesting to improve HFS.
http://ailef.neuf.fr/atk41.html

i put a log and pass to the root folder of HFS do the tests.
i tested it on xp pro sp3.


Offline cmatte

  • Occasional poster
  • *
    • Posts: 31
    • View Profile
    • ErMeglio WebSite
hello, i tested this tool on this HFS beta and here is the report, i had 10 vulnerabilities on 340 plugins, i think it's a good result.
maybe u'll find those results interesting to improve HFS.
http://ailef.neuf.fr/atk41.html

i put a log and pass to the root folder of HFS do the tests.
i tested it on xp pro sp3.
I did a test inserting very long login/pass characters and even closing/opening hfs again didn't help!
I'm stuck to a "414 - The request has exceeded the max length allowed" error :'(
What to do?

--update--
Allright!
Pheraps ff 3 kept sending the same data! I simply closed/opened it again and it worked!
« Last Edit: May 03, 2008, 12:22:50 PM by cmatte »


Offline PolarFox

  • Occasional poster
  • *
    • Posts: 23
  • Glory to Russia!
    • View Profile
    • http://j100.ru
Exception on fingerprint if a file not found (e.g. file has been [re]moved).

rejetto, maybe need include all file operation in "try-catch" block?
And of course i'm sorry for my English :)


Offline TCube

  • Tireless poster
  • ****
    • Posts: 440
    • View Profile
"Min Disk Space" sets all uploads to failure when HFS is on a USB card [checked 185/184]
TCube
Make it idiot-proof and I will make a better idiot


jerome

  • Guest
hello the rejetto HFS testing company.

i have found a little problem to submit from a custom template.
some nice flash button's are not working in HFS in allowScriptAccess=sameDomain mode.

"target_seft" and "target_parent" are blocked, only "target_blank" works on a HTML page hosted on HFS.

Only allowScriptAccess=Always enable these target to work.

you can see an example page hosted by HFS
82.239.5.248/PageTestButtonSameDomain.html

the same page hosted on my FTP server
jerome.sevestre.free.fr/PageTestButtonSameDomain.html

is it normal ? ;D
A++


Offline jerome

  • Occasional poster
  • *
    • Posts: 36
    • View Profile
hello again, sorry to wrong alert you.
it don't comes  from HFS specifically because i have the same problem if i open the HTML file from my desktop.

it look like a wrong code in the flash button animation elements i use from a template demo,
i have tested other one's from amara menu builder and the target_self is working without any ScriptAccess notification in the code.
it is only a flash joke reacting on active X control. you can sleep quiet.
the wrong code is in my buttons, i will watch it with a decompiler.



7of9

  • Guest
Bug, Very large folder Not showing up once logged in. I have a huge (20GB MP3) folder i share with my friends and the main folder will not show up once they login to the server with the latest beta. Was working b4 just fine. Running on Vista x64 w SP1.


Offline jessiepp

  • Occasional poster
  • *
    • Posts: 2
    • View Profile
hello to all i am a new user on this forum will there be a ver of this program for mac ever?


Offline traxxus

  • Occasional poster
  • *
    • Posts: 62
    • View Profile
Hi jessiepp

HFS on mac is only possible with an windows emulator on mac... sry. To other users: correct me if the information was wrong.
traxxus.dyndns.org:100