|
From: Helen B. <he...@tp...> - 2003-07-01 08:55:41
|
At 11:54 AM 1/07/2003 +0400, Dmitry Yemanov wrote: >Mike, > > > Or are you (seriously, as can be read from your post) > > suggesting that the > > local-only (embedded) server should act as mediator for > > remote connections also? > >That's how people want the embedded server to work. The current builds allow >fbembed.dll to be a client for remote servers. I haven't tested it myself, but that's actually contrary to what the doc says. Doc says it doesn't support any remote access protocol, including local loopback. Is anything else there not up to date? > > Local in-process server, aka "fbembed" is AFAIK what it tells > > you to be. If > > someone added remote capabilities to that DLL, all of a > > sudden it would have > > just those remote access capabilities - i.e. it would be a > > security problem. > >The embedded server is a big security problem by just the fact of its >existence, because the application has full access to the internal engine >structures, page cache, etc. I wonder whether Nando noticed that he didn't need to log in to get server access... Helen |