[WEB4LIB] IKiosk Security Lapse

Dale E. Goodell goodeld at wou.edu
Fri Oct 30 12:03:16 EST 1998


I am also running v3.31 of WinSelect Kiosk/Policy.  I have just 
tested this, and saw the same thing.  I am very interested in this 
thread, and would like to keep the discussion going on-list.  
 
> I've been using Winselect Policy / Kiosk 3.3.1 on our public Internet
> PC's to good effect for some
> time now.  However, our ever-curious teenagers have (unwittingly)
> brought the following security lapse to my attention:  if you reboot the
> PC, when Windows 95 (or 98) starts up again you can click repeatedly
> with the mouse where the "Start" button
> eventually shows up.  This easily brings up the Task Manager.  From
> there you can choose "Run Applications."  A default box comes up.  If
> you ignore this box and  choose "Browse," a new box comes up. You cannot
> enter a pathname into this browse box, which is as it should be, since
> access to the hard drive has been turned off. But if instead of choosing
> the "Browse" option, you stick with the first, default box which
> appears, you CAN enter a pathname, e.g. "c:\command.com."  And into DOS
> we go.
 


==================================================================
Dale E. Goodell
User Support Analyst
Western Oregon University Library
Monmouth, OR 97361

Internet:   goodeld at fsa.wou.edu
Voice:      503/838-8891
Fax:        503/838-8399


More information about the Web4lib mailing list