Yes, of course, you can consider that this kind of feature as a security hole. However, this action is destinated to give the access to some private HTML pages to a limited number of people inside my organisation (internal network).
A more satisfactory way to do this action is to use a table with the user name, to ask to the user to introduce its userid each time he accesses the pages and to compare the userdid with those present in the table. This can be aesy done with Coldfusion e.g.
However, I think that this way is too heavy for two pages html and for 5 users. More over, the access to these pages can be simply verify using a referer redirecting any people to a index page to verify if he has the right to view the pages in the case where an user goes directly to these pages.
These were the reasons why I tought to this "simple" access control.
In other hand, I understand also that the extraction of such userid could represent also a security hole for NT4.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.