Security hole - how to get Desktop

Discussion in 'Parallels Remote Application Server' started by kaa@, Nov 18, 2008.

  1. kaa@

    kaa@ Guest

    I have created published Desktop (#1) and set restrictions by user to administrators group only, and published Application (#2) to Users.

    On user connect to farm, create shortcut on desktop for application, in properties change

    "C:\Program Files\2X\ApplicationServer Client\TSClient.exe" s!='192.168.1.5' t!='80' d!='' u!='user3' a!='#2' m!='0' o!='0'

    to

    "C:\Program Files\2X\ApplicationServer Client\TSClient.exe" s!='192.168.1.5' t!='80' d!='' u!='user3' a!='#1' m!='0' o!='0'

    and doubleclick on this icon. Voila - I logged to restricted desktop !!!

    checked on client and server build 465, build 468.

    PS if I have troubles with 2x and I posted messages here, but nobody answer, exist reason to send messages to support or not ?
     
  2. dcornwell

    dcornwell Guest

    I've tried to replicate that, but if you restrict the published desktop to only be allowed for specific users (Administrator etc), then this isn't a problem (for me at least).

    I guess this type of session config in the shortcut isn't ideal, but if you apply security at the server end, then it shouldn't be a real risk.
     
  3. kaa@

    kaa@ Guest

    I HAVE restrict desktop to only allowed (ANOTHER!!!) user. Create on desktop shortcut to published desktop for valid user, after that replace username in icon properties to not allowed user and try !

    Security weak is on server part.
     
  4. Lee

    Lee Guest

    hi kaa@

    Please send us you support files from the console, and screen shot the steps to replicate this behavior, also screen shot where you have restricted the user groups

    send this to support@2x.com refering to this forum article

    thanks
     

Share This Page