SmartCode Solutions Web Forum




Author Message
 Posted Wednesday, November 15, 2006
Forum Member

Forum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum Member

Group: Forum Members
Last Login: Thursday, February 15, 2007
Posts: 25, Visits: 25
I really like that VNC is wrapped up inside of an ActiveX control (although it would be cooler if it was a managed .NET assembly instead).  Anyway, my fear is that once this activeX control is installed on a machine it could be used by any piece of software on the system to take control of the computer.  We need some way to keep any arbitrary program from using it, like a software key or something (I'm not sure what the answer is).  What if this control becomes popular? Imagine what would happen if spyware apps looked for the existence of the s-code vnc control and exploited it.  or worse yet, copied a licensed version and distributed it with their own spyware?!  There needs to be some sort of safeguard, but I have no idea what that should be.
Post #1241
Add to Twitter Add to Facebook
 Posted Thursday, November 16, 2006
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Administrators
Last Login: Friday, May 18, 2012
Posts: 1,624, Visits: 3,043
This is a good question and unfortunately I think there is no answer to it. Some serial number protection wouldn’t be much help; we all know that any software can be cracked and such protection could be easily worked around. And the case with the ActiveX is pretty much the same as with the native VNC binaries, they also can be used by a spyware, etc. The binaries are currently detected by Windows Defender as a possible thread, so I guess if ServerX would become popular he would have the similar fate. This might be a good thing, since if a spyware would try to install the ActiveX, a user will be notified about it.

http://www.s-code.com/App_Themes/Default/images/blue_line.gif
We are looking for investors and business partners. Please contact us for more details

Kindest Regards,
SmartCode Solutions Support
Post #1243
Add to Twitter Add to Facebook
 Posted Thursday, November 16, 2006
Forum Member

Forum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum Member

Group: Forum Members
Last Login: Thursday, February 15, 2007
Posts: 25, Visits: 25
I agree that there is no easy fix.  I'm worried about incurring liability if a customer's machine gets hacked because we placed this on there.  I wish I could compile it so that it would only connect to a list of hosts predefined in the binary.  I understand a hacker could modify it, but that would require a high level sophistication and a simple script kiddie would'nt be able to pull it off.
Post #1244
Add to Twitter Add to Facebook
 Posted Thursday, November 16, 2006
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Administrators
Last Login: Friday, May 18, 2012
Posts: 1,624, Visits: 3,043
We could compile a version, which would accept connections from predefined IP's. But again this wouldn’t be bullet proof. Besides we would charge some small fee for such customization Smile What’s really can protect an old user is a firewall, if it’s configured properly than a customer should be safe.

http://www.s-code.com/App_Themes/Default/images/blue_line.gif
We are looking for investors and business partners. Please contact us for more details

Kindest Regards,
SmartCode Solutions Support
Post #1247
Add to Twitter Add to Facebook


Similar Topics

Expand / Collapse

Reading This Topic

Expand / Collapse