Microsoft Content Management Server - Resource Manager Exposed To Public??

This is Interesting: Free IT Magazines  
Home > Archive > Microsoft Content Management Server > September 2006 > Resource Manager Exposed To Public??





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Resource Manager Exposed To Public??
Ninerfan

2006-09-22, 7:22 pm

Hi all,

A user on our implementation of MS CMS 2002 book marked the following type
of URL. This takes him directly into our resource gallery via the Resource
Manager web tool. No password or login required. I realize it's highly
unlikely that someone would ever guess such a URL but is this normal? Is
there anyway to restrict access to the gallery from outside probes like this?

I've changed some of the string because obviously I don't want to invite
people into our gallery but you get the idea.

http://server/project/CMS/WebAuthor...F8-D808522AB499}&wbc_gallery={B95A0224-963D-4F1F-A254-23C14985499A}&TimeStamp=632942638493545689

Thanks for any info.
Stefan [MSFT]

2006-09-25, 1:22 pm

Hi Ninerfan,

the user will only see the page if he has permissions to it.
Or if guest account is enabled.
But then he will not be able to do anything beside seeing the items which
are guest enabled - so the items he is allowed to see anyway.

Cheers,
Stefan

--
This posting is provided "AS IS" with no warranties, and confers no rights


"Ninerfan" <Ninerfan@discussions.microsoft.com> wrote in message
news:DADE13E0-04F5-4D40-AEBF-54FE3DD7EBCD@microsoft.com...
> Hi all,
>
> A user on our implementation of MS CMS 2002 book marked the following type
> of URL. This takes him directly into our resource gallery via the Resource
> Manager web tool. No password or login required. I realize it's highly
> unlikely that someone would ever guess such a URL but is this normal? Is
> there anyway to restrict access to the gallery from outside probes like
> this?
>
> I've changed some of the string because obviously I don't want to invite
> people into our gallery but you get the idea.
>
> http://server/project/CMS/WebAuthor...F8-D808522AB499}&wbc_gallery={B95A0224-963D-4F1F-A254-23C14985499A}&TimeStamp=632942638493545689
>
> Thanks for any info.



Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com