When connecting to Citrix sites, Support advised me to send username/password using a macro, so we set up all our customer's using this method.
I just had a staff member that double-clicked on the client in RDMS and then moved the cursor in to Notepad and RDMS ran the macro in Notepad, displaying the username and password to the user, so security is now compromised.
RDMS should only run macro's within the RDMS application - this is a massive problem.
Hi,
Unfortunately this is not simple to detect where we are. The macro is indeed the less secure method we have and it used only when we can't have a direct access like what we have with RDP.
What do you mean to execute only in DVLS. Is it a web site that you open or an external application?
Regards
David Hervieux
I can't possibly use a macro if doing so allows my users to view confidential security information such as passwords. If Support had identified this as a potential program I never would have used it.
It is a website:
Have you tried to use the autofill web site instead of the macro or the web browser extension?
Regards
David Hervieux
Hello,
Just to keep our community informed, we have added a warning message in the property window where we define the macros. We've also added a large warning in the documentation.
As to the Citrix Receiver web page, we have found the proper combination of control names to use to get it to work. Since there was extensive javascript present in the page, the solution to have the credentials submitted automatically was to use our [ENTER] command in place of the submit control name.
Maurice
Confirmed.
Maurice was fantastic in quickly resolving our issues via remote access, as he was when we were deciding which product to purchase which was a major reason we ended up going with Devolutions.
Much appreciated.