WebApp Sec mailing list archives

RE: Publishing Web Based Application via ICA protocol


From: "Evans, Arian" <Arian.Evans () fishnetsecurity com>
Date: Mon, 18 Jul 2005 11:08:48 -0500



2) I do dynamically render all the documents. In addition I also using
anti-leeching methods to prevent traversal, and/or direct linking.

Another option is rendering via an ActiveX control (that could
be responsible for caching, cleanup, etc. Could in fact render
xls unsure about word in the browser w/out office.

An app I tested a year or two ago used third-party COTS ActiveX
controls for this purpose...can't remember who made them. I did
some moderate testing of the controls themselves but most of the
folks I was working with didn't want to touch them due to the
verbiage in the copywrite/use notice.

-ae







The information transmitted in this e-mail is intended only for the addressee and may contain confidential and/or 
privileged material. 
Any interception, review, retransmission, dissemination, or other use of, or taking of any action upon this information 
by persons or entities
other than the intended recipient is prohibited by law and may subject them to criminal or civil liability. If you 
received this communication 
in error, please contact us immediately at 816.421.6611, and delete the communication from any computer or network 
system.



Current thread: