Re: Security: Preventing direct access to a PDF file

From: s_m_b (smb20002ns_at_hotmail.com)
Date: 06/23/03


Date: Mon, 23 Jun 2003 06:40:08 -0500


"CJM" <cjmwork@yahoo.co.uk> wrote in
news:uhqO6KXODHA.3016@TK2MSFTNGP10.phx.gbl:

unless I'm missing something here, don't you have the access rights to
the documents tied down to user groups?

> Since Active Directory will not be rolled out to all sites in our
> company until next year, I'm working on alternative ways to secure our
> intranet sites. (Sites are on IIS5, built in ASP, and all users use
> IE5+)
>
> By default all users can see a subset of menu option. By logging in,
> some users can see more menu options.
>
> ASP applications are protected on a page by page basis, and as such
> are secure.
>
> However, there are some 'ordinary' documents (eg PDFs or possibly
> XLS/Docs) that are kept in secure areas and are only available through
> restricted menus. However, as things stand, if a user were to know of
> the location of one of these documents, they could gain access by
> directly typing the url in the browser address bar.
>
> This is the loophole I want to close. Its not that likely that a user
> would have sufficient knowledge or know-how to exploit this weakness,
> but that's hardly the basis of a sound secure intranet!
>
> Note: The bulk of the content is maintained by key [non-technical]
> users; they usually convert the desired content to PDF format, then
> using some custom CMS functionality they add these documents to the
> DB-driven menu. This an essential feature of the site that somewhat
> restricts our options - any solution would have to either by-pass
> these guys, or be simple enough for them to do.
>
> Thanks
>
> Chris
>
>
>



Relevant Pages

  • RE: How to secure a table within a database?
    ... There are Server Roles (Login) and User Roles. ... I have secured the db by creating 2 User Groups on the server and then ... secure the tables in question I have tried two different ways to do so: ... Permissions to assign the groups that I want and don't want to use the Table ...
    (microsoft.public.sqlserver.security)
  • How to secure a table within a database?
    ... I am trying to secure 2 tables within a db. ... I have secured the db by creating 2 User Groups on the server and then ...
    (microsoft.public.sqlserver.security)
  • Re: which PC
    ... explain why Apple releases 'security bug fixes' on a fairly regular ... basis for OS X. ... You think they are doing this for entertainment? ... it *is* substantially more secure than windows. ...
    (rec.photo.digital)
  • Re: Writing Secure code
    ... > is completely secure and not exploitable. ... of the exit() function in libc. ... This type of error is the basis of all ...
    (SecProg)
  • Securing hidden tables
    ... I have an app that is secured, and I'd like to hide some ... like some user groups to use. ... first secure the application and then change the tables' ... Thanks in advance to anyone who replies. ...
    (microsoft.public.access.security)

Quantcast