Inside: SereneScreen Fan Forum

Inside: SereneScreen Fan Forum (https://www.feldoncentral.com/forums/index.php)
-   Marine Aquarium 3 for Windows (https://www.feldoncentral.com/forums/forumdisplay.php?f=46)
-   -   Security issue (https://www.feldoncentral.com/forums/showthread.php?t=4714)

Dale 01-23-2009 12:07 PM

Quote:

Originally Posted by Jim Sachs (Post 109554)
Yeah, but it's broken on XP. Edgar has a fix, which I'll post as soon as he's done with a different bug.

\
8h (and 8i) properly go to the website, after password prompt, on XP Pro.

On Vista Ultimate 32-bit, 8i still works properly.

However note (Vista): When exiting the screensaver mode, a "black" window pops open for a moment. That seemingly occurs regardless of how I get out of the screensaver (move mouse, etc.), and regardless of whether the "password" option is turned on or off. [Not thoroughly explored, but it has happened enough times to be reported as an annoyance]

Jim Sachs 01-23-2009 12:15 PM

That's to prevent all the full-screen black flashes that everyone had been reporting a couple of months ago. By switching to windowed mode an instant before exiting, most of the drama in Vista is avoided.

Dale 01-24-2009 10:25 PM

Quote:

Originally Posted by Jim Sachs (Post 109616)
That's to prevent all the full-screen black flashes that everyone had been reporting a couple of months ago. By switching to windowed mode an instant before exiting, most of the drama in Vista is avoided.

...however, it also does that on XP, providing additional drama for XP.

I'm not sure it's worth fixing, but I did want to make sure it's known.

cjmaddy 01-25-2009 07:33 AM

https://www.feldoncentral.com/forums...18&#post108518

rps 01-26-2009 11:59 AM

Quote:

Originally Posted by Dale (Post 109533)
For the info of folks watching this thread - essentially all that script does is "http://www.serenescreen.com" (with the appropriate amount of fiddling to get the environment right).

This is clearly done in "user" context, after a correct password has been supplied.

Ok, I have to ask: how does a process in the null session get a .js to launch in another session? It doesn't seem like that should even be possible under Windows' security rules.

~Ralph S.

Shinsa 02-01-2009 01:43 PM

Remember, Microsoft says, "If someone has physical access to your computer, then it is not secure". In other words, they won't fix bugs in their OS that someone can only take advantage of by being at your machine (i.e. accessing a Win XP machines users files by booting with a Windows 2000 Professional CD).

Edgar 02-01-2009 02:11 PM

Their scripting engine called WScript has a method to impersonate the original user that ran the screensaver. Otherwise, I would have given up with the WebSite button for Vista.
What was weird is that in XP, it doesn't seem to matter that it came from a null session. I really did need the WScript but to make it work the same on all the Windows as possible, it calls the same script.


All times are GMT -6. The time now is 10:54 AM.

Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.