Help Desk Software & Beyond
May 17, 2012, 06:05:46 AM *
Welcome, Guest. Please login or register.
To post messages you need to register. We apologize for inconvenience, but this is to prevent spam.
Registration is instant (no email verification) and we do not ask for any personal information.

Login with username, password and session length
News: Welcome to Help Desk Software forum!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Operators Can see ANY Ticket  (Read 205 times)
Derwood
Newbie
*

Karma: 1
Posts: 19


View Profile
« on: November 13, 2011, 07:56:42 AM »

G'day All,

I have had one of the operators of our setup of TTX demonstrate something to me that worries me a little. When logged in and by using the web address line in any browser they can look at any ticket they have access to. An example address is shown below;

http://(your web address)/ttx.cgi?cmd=ticket&sid=&key=16462&style=

by changing the TTX number, they can then view any ticket they like. Regardless of if they belong to that group and should have visibility or not.

I block groups from some of my operators for very good reasons and I am wondering if we can do something about this?

(Using TTX V3.0 and SQL, not 100% sure of the server details)

thanks
Darren

« Last Edit: November 13, 2011, 07:58:19 AM by Derwood » Logged
Sparky
Moderator
Hero Member
*****

Karma: 83
Posts: 2,228


stop pushing all those buttons


View Profile
« Reply #1 on: November 14, 2011, 11:11:27 AM »

This is how TTX has always worked.

Anybody, not just operators, can view any ticket if they have the corresponding access key.  However, somebody who is not logged in as an operator would need the full long version of the key.

Feel free to send a message to Alex at his helpdesk if you feel that your setup is not secure enough.
« Last Edit: November 14, 2011, 11:17:25 AM by Sparky » Logged

Did you update the paths in ttxcfg.cgi after moving TTX to your new location?   Undecided
To those seeking help.... please report back when you figure it out.  Cheesy
Alex
Administrator
Hero Member
*****

Karma: 22
Posts: 605



View Profile WWW
« Reply #2 on: November 14, 2011, 04:20:33 PM »

Thanks for heads up. The problem is fixed, updated files are available through SVN repositories:

version 3.01 (latest official release)

https://www.unitedwebcoders.com/fisheye/browse/TTX/release-3.01
or
https://www.unitedwebcoders.com/fisheye/browse/~raw,r=850/TTX/release-3.01/TTXTicket.pm
or
http://svn.unitedwebcoders.com:8082/svn/ttx/release-3.01/


latest development snapshot:

https://www.unitedwebcoders.com/fisheye/browse/TTX/trunk
or
http://svn.unitedwebcoders.com:8082/svn/ttx/trunk/

Logged

Follow me on: LinkedIn
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1 RC3 | SMF © 2001-2006, Lewis Media Valid XHTML 1.0! Valid CSS!
Page created in 0.023 seconds with 18 queries.