Security notes
The following are notes for ensuring a more secure environment and
to explain possible security holes in KevPT.
- When changing KevPT system (FileMaker) passwords, be sure to
change the password in all of the .fp5 files (including the
KevPT.fp5 file)
- Do not give the default user password (the one currently set
to "user") "Export Records" privileges. If you do, they will be
able to use tools such as AppleScript to extract passwords or
unauthorized record data from KevPT.
- In order to serve the web portion, it must have Export
Privileges. There is a FileMaker password "webserver" that has
Export Privileges. This password should be changed as soon as
possible. Keep in mind, because the webserver password has export
privileges, a user at that machine can export any data using
AppleScript or another method.
- Be sure to log out after using KevPT. While the standalone and
FileMaker clients automatically log out after quitting FileMaker
or KevPT. It is possible for a savvy web user to gain access using
the same web browser as a previous user. If the user logged out
(i.e. quit the web browser), then it is not possible to gain
access without the password.
- Be careful when giving and removing administrative privileges.
If you remove administrative privileges from every user, it can be
difficult to get them back.