Not signed in (Sign In)
    • CommentAuthorAnonymous
    • CommentTimeNov 4th 2009 edited
     
    You should email the person and say whether the suggestion is considered before you wipe it off your discussion forum. I posted a security hole in your software that other users should be aware of and you delete it and all references to it.

    Please address the issue or I can make a website that exposes this problem and makes it VERY public. At least here it is contained to your current user base.

    If this gets deleted without notification/justification, expect a public website calling out the security flaws (especially this one).

    The security problem is that Application Exceptions just work by name. So if any program is put into Application Exceptions, all you have to do is:

    - Copy and paste a browser program (like firefox.exe or chrome.exe).

    - Rename the program as the name of the application in Application Exceptions.

    - Run the newly named file, which gives full unfiltered access to the internet.

    Your software should handle file signatures and not just allow exceptions by name.
    • CommentAuthorAnonymous
    • CommentTimeNov 4th 2009 edited
     
    Amen! There was something fishy about it and I have not recieved any email notifications from Net Nanny software for several weeks. I was not sure what the problem was. Everything checked out. Now this post about renaming files is the problem. Kids getting smarter everyday to defeat technology. I expect ContentWatch to stay two steps ahead of those kids.
    • CommentAuthorAnonymous
    • CommentTimeNov 7th 2009 edited
     
    I'm glad this wasn't deleted. Hopefully it will be fixed or hidden from the users as an option.
    • CommentAuthormike808
    • CommentTimeNov 20th 2009 edited
     
    An easier fix would be to store the entire program path, not just the basic filename of the program.

    And there are ways to lock down program areas with access control lists (ACLs) and NTFS, but it's not easy to do with Windows XP Home (check out XCACLS and XCACLSgui).
    • CommentAuthorWPhillips Forum Administrator ~
    • CommentTimeNov 23rd 2009 edited
     
    "The application exceptions list, which is never displayed to anyone except the Net Nanny administrator, is more of a temporary fix for compatibility issues. As compatibility issues are reported we recommend adding them to the exceptions list and begin working with our development team to resolve the underlying issues. Then, once the root cause is fixed, you should be able to remove the “.exe” from the list.

    We’ve always worked closely with our customers to resolve issues and enhance Net Nanny and I definitely appreciate you contributing to the forum and bringing your concerns to us. For things that may contribute to circumventing Net Nanny it would probably be best to contact me directly. You can do so anytime by email or call during our office hours."
    • CommentAuthorAnonymous
    • CommentTimeFeb 11th 2010 edited
     
    Looks like this was fixed in the latest release of Net Nanny 6.5. It wasn't really an issue because only Administrators can view or add files to the exceptions list.

A ContentWatch Product

© 2001-2009 ContentWatch, Inc., All rights reserved.

Follow Us on TwitterFollow Us on Facebook100 Percent SecureSSL SecurityBetter Business Bureau Online Reliability