| Welcome, Guest |
You have to register before you can post on our site.
|
| Online Users |
There are currently 1065 online users. » 1 Member(s) | 1061 Guest(s) Applebot, Bing, Google, addykent
|
| Latest Threads |
KanBan like behaviour
Forum: IntraWeb General Discussion
Last Post: MJS@mjs.us
3 hours ago
» Replies: 4
» Views: 99
|
TIWSummernote Issue
Forum: IntraWeb General Discussion
Last Post: Alexandre Machado
09-30-2026, 07:34 PM
» Replies: 1
» Views: 51
|
Reproducible IIS crash in...
Forum: IntraWeb General Discussion
Last Post: alex.trejo@tttnet.com.mx
09-21-2026, 05:33 PM
» Replies: 1
» Views: 484
|
WebApplication.IP change ...
Forum: IntraWeb General Discussion
Last Post: alex.trejo@tttnet.com.mx
09-21-2026, 05:31 PM
» Replies: 2
» Views: 541
|
How can I get started? Do...
Forum: CrossTalk General Discussion
Last Post: taggame
09-17-2026, 03:17 AM
» Replies: 2
» Views: 4,304
|
Hook/callback to handle t...
Forum: IntraWeb General Discussion
Last Post: Lenfors
09-08-2026, 09:03 AM
» Replies: 0
» Views: 382
|
The packages IW16.xx inc...
Forum: IntraWeb General Discussion
Last Post: hsbelli
09-03-2026, 11:46 AM
» Replies: 2
» Views: 754
|
Redirection issues with F...
Forum: IntraWeb General Discussion
Last Post: magosk
08-31-2026, 10:03 AM
» Replies: 0
» Views: 441
|
Source Code
Forum: IntraWeb General Discussion
Last Post: magosk
08-31-2026, 08:11 AM
» Replies: 3
» Views: 963
|
TContenthandler requires ...
Forum: IntraWeb General Discussion
Last Post: valmeras
08-30-2026, 02:35 AM
» Replies: 0
» Views: 402
|
|
|
| OpenSSL 'ChangeCipherSpec' MiTM Potential Vulnerability |
|
Posted by: pgnair - 12-17-2020, 10:26 AM - Forum: IntraWeb General Discussion
- Replies (15)
|
 |
I am using Intraweb 14.2.1 and the OpenSSL dll libraries 1.0.2u(last modified 21/12/2019). We received below vulnerability on this quarter PT on one of the web application running as standalone. How can resolve this issue please?
[The OpenSSL service on the remote host is potentially vulnerable to aman-in-the-middle (MiTM) attack based on its response to twoconsecutive 'ChangeCipherSpec' messages during the incorrect phase ofan SSL/TLS handshake.This flaw could allow a MiTM attacker to decrypt or forge SSL messagesby telling the service to begin encrypted communications before keymaterial has been exchanged which causes predictable keys to be usedto secure future traffic.OpenSSL 1.0.1 is known to be exploitable. OpenSSL 0.9.8 and 1.0.0 arenot known to be vulnerable; however the OpenSSL team has advised thatusers of these older versions upgrade as a precaution. This checkdetects and reports all versions of OpenSSL that are potentiallyexploitable.Note that Indusface WAS has only tested for an SSL/TLS MiTM vulnerability(CVE-2014-0224). However Indusface WAS has inferred that the OpenSSL serviceon the remote host is also affected by six additional vulnerabilitiesthat were disclosed in OpenSSL's June 5th 2014 security advisory : - An error exists in the 'ssl3_read_bytes' function that permits data to be injected into other sessions or allows denial of service attacks. Note that this issue is exploitable only if SSL_MODE_RELEASE_BUFFERS is enabled. (CVE-2010-5298) - An error exists related to the implementation of the Elliptic Curve Digital Signature Algorithm (ECDSA) that allows nonce disclosure via the 'FLUSH+RELOAD' cache side-channel attack. (CVE-2014-0076) - A buffer overflow error exists related to invalid DTLS fragment handling that permits the execution of arbitrary code or allows denial of service attacks. Note that this issue only affects OpenSSL when used as a DTLS client or server. (CVE-2014-0195) - An error exists in the 'do_ssl3_write' function that permits a NULL pointer to be dereferenced which could allow denial of service attacks. Note that this issue is exploitable only if SSL_MODE_RELEASE_BUFFERS is enabled. (CVE-2014-0198) - An error exists related to DTLS handshake handling that could allow denial of service attacks. Note that this issue only affects OpenSSL when used as a DTLS client. (CVE-2014-0221) - An error exists in the 'dtls1_get_message_fragment' function related to anonymous ECDH cipher suites. This could allow denial of service attacks. Note that this issue only affects OpenSSL TLS clients. (CVE-2014-3470)OpenSSL did not release individual patches for these vulnerabilitiesinstead they were all patched under a single version release. Notethat the service will remain vulnerable after patching until theservice or host is restarted.]
|
|
|
| Update items and values of IWCombobox |
|
Posted by: KoderJan - 12-16-2020, 10:49 PM - Forum: IntraWeb General Discussion
- Replies (2)
|
 |
Hi,
How can I update the Names and Values of TIWCombobox.Items in an asynchronous event in runtime?
Background:
I have a array of records which is used to update TIWCombobox.Items asynchronously.
This combobox has 'ItemsHaveValues' enabled because I need access to the value of the items.
If I update the Items property using Combobox.Items.Add('Item 1=Value1') the combobox displays only the 'Value1'
Thanks!
|
|
|
| Intraweb and fast report |
|
Posted by: softdev85 - 12-16-2020, 06:21 PM - Forum: IntraWeb General Discussion
- Replies (3)
|
 |
hello,
I am dummy with fastreport i never use.
I have build software with intraweb that use mysql database,
he work well.
Ido some sql query, and the result are writen on screen,
but i want now build report with the result of this query in pdf
and i want also print them.
Have you just a small example for understand how work with fast report,
in intraweb software ?
thank's a lot for your help
Best regards
|
|
|
| TIWBSInput and Date type input |
|
Posted by: Comograma - 12-16-2020, 12:53 PM - Forum: IntraWeb General Discussion
- Replies (7)
|
 |
I have a TIWBSInput component to input a date and to load it from a database table field, type date.
This TIWBSInput is of type bsitDate, e.g., TIWBSinput.InputType := bsitDate.
When inputing I have no problem because I have the placeHolder on the field before input that shows me how to do it.
Where I do something like this:
MyComponentDate.Text := DateToStr(MyQuery.FieldByName('birthdayDate').AsDate);
or
MyComponentDate.Text := MyQuery.FieldByName('birthdayDate').AsString;
I get an error saying that it's an invalid date.
If my application is running as an application, that's ok but when I run it as a Windows Service, I'll get the error.
I know why this happens and that is because the regionals from the SYSTEM account, where the service is running, are different from the ones of the user account that is browsing the application on the browser.
How can I workaround this? How can I get the input pattern presented on the field?
|
|
|
| HTTPS on dll |
|
Posted by: jimmy11 - 12-11-2020, 01:44 PM - Forum: IntraWeb General Discussion
- Replies (2)
|
 |
Hi,
I am trying to enable HTTPS and disable HTTP on our application using SSLOptions on ServerController.
I have set the NonSSLRequest to nsBlock this seems to work on exe but I can't make it work if the application is compiled as dll.
I am using IntraWeb 14 and IIS as host.
Hope someone can help.
Thanks.
|
|
|
| Intraweb Renewal |
|
Posted by: Comograma - 12-10-2020, 06:51 PM - Forum: IntraWeb General Discussion
- Replies (4)
|
 |
Hi,
Anyone knows if Atozed is closed or if they went into bank rupcy?
Last friday I'd renewal my Intraweb v15 license, made the payment and until today I'm waiting to the license to be activated.
I can't use latest version of Intraweb 15.2.21 and this is bad.
I even sent a PM to Alexandre Machado, so that maybe he could help me but no response what so ever.
This is a bad job with Intraweb Sales.
|
|
|
|