<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5.0.d security issue with internet download manager in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282300#M235430</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;if you don't want tools like IDM to be able to offer download to those types of restricted users, you must completely remove any potential URL reference to the actual document download from the page. This also includes disabling the PDF / document previewer which internally "downloads" fragments of the document for display and uses an URL reference that would allow full download. IDM very likely picks up this URL and provides the download option based up on that.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jan 2016 09:07:36 GMT</pubDate>
    <dc:creator>afaust</dc:creator>
    <dc:date>2016-01-28T09:07:36Z</dc:date>
    <item>
      <title>5.0.d security issue with internet download manager</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282299#M235429</link>
      <description>Hello every body,I made an alfresco 5.0.d new installation in windows server 2012 R2, i revoked the download action for site consumers, but for those who have IDM (internet download Manager installed in their browser), the browser promt for download the pdf file even if there is no download button.C</description>
      <pubDate>Wed, 27 Jan 2016 17:09:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282299#M235429</guid>
      <dc:creator>samirastucia</dc:creator>
      <dc:date>2016-01-27T17:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: 5.0.d security issue with internet download manager</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282300#M235430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;if you don't want tools like IDM to be able to offer download to those types of restricted users, you must completely remove any potential URL reference to the actual document download from the page. This also includes disabling the PDF / document previewer which internally "downloads" fragments of the document for display and uses an URL reference that would allow full download. IDM very likely picks up this URL and provides the download option based up on that.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 09:07:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282300#M235430</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-28T09:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: 5.0.d security issue with internet download manager</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282301#M235431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thank you Axel for your reply,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What if we use a SWF previwer instead of the pdfjs ?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 15:41:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282301#M235431</guid>
      <dc:creator>samirastucia</dc:creator>
      <dc:date>2016-01-28T15:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5.0.d security issue with internet download manager</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282302#M235432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The SWF previewer would likely still result in IDM providing a download option, but the downloaded file will be a reduced quality rendition of the original document.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Technically, as long as you expose any previewer capability, IDM is likely to provide something to download. Even if that is only a rendition, the URL provided can be manipulated by users to still download the original document. Everything you are doing to restrict the ability of download is only UI focussed. Technically, if a user has READ access to a document inside Alfresco and is somehow able to piece together the URL to it, they can download it (the URLs aren't that complex either).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 16:54:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/5-0-d-security-issue-with-internet-download-manager/m-p/282302#M235432</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-28T16:54:58Z</dc:date>
    </item>
  </channel>
</rss>

