Support Request: USB Drive not Disabled

Reproduction

1. Launch SiteKiosk
2. Plug in a USB thumb-drive
3. "Anti Sabotage Mode" window appears and the mouse cursor is contained within it
4. However, the operating system still launches a window to read the USB drive
5. Note that the operating system window has focus, not the SiteKiosk Anti-sabotage mode window.
6. You can use the keyboard to navigate the USB drive, execute files or even browse to the C: drive.

Description

When plugging in a USB drive while SiteKiosk is running, Anti-Sabotage Mode kicks in but does not prevent the user from executing files on the USB drive. The user is prevented from using the mouse to access commands on the USB window, but the keyboard still works. This is because the focus is on the operating system USB window and not the SiteKiosk window. Thus, any keystrokes are executed against the OS window. A savvy user can use this security hole to execute programs on the USB drive.

This is fully reproducible on our end.

Answer: (2)

Re: USB Drive not Disabled 5/23/2007 6:41 PM
Hello,

as this issue isn't reproducible on my test system (with your SiteKiosk configuration) did you set the System-Security-Manager to protected before?

Normally the "Autostart" options for the drives are disabled and there shouldn't come up the Explorer window. (Like on my test system)

Are there any special files on this USB stick?

Another option would be to disallow the Explorer Window also for the SiteKiosk user via settings in the "Windows and Dialogs" management.
-->CabinetWClass

Regards,
Michael Olbrich
Re: USB Drive not Disabled 5/24/2007 1:39 AM
You are right. The start mode was not secured. Properly configuring the System Security Manager fixed the problem.

Thanks!
My Account
Login
Language (Tickets):