0
Not a bug

ScreenConnect.ClientSetup still accessible after logout

damien 2 years ago updated by Eric Davis 2 years ago 1

Hi, we use Connectwise for a while now but never took time to check security issues. Sometimes we connect to hosts on a random computer. When i logout from the page, i notice that if i launch the ScreenConnect.ClientSetup.exe previously downloaded, i can still have access to the remote computer. It's quite dangerous. Can we auto delete the setup?

Thanks.

ConnectWise Control Version:
19.4
Server Affected:
Host Client Affected:
Guest Client Affected:

Answer

Answer
Not a bug

This is the expected behavior, and not a bug.


Regarding your concerns, Control has a number of settings that might address them. These can be found in the web.config file: Access Token Expire Seconds, Input Idle Disconnect Time Seconds, and Session Expire Seconds. As the names suggest, these are timeouts that will let you control the lifetime of sessions.

You can edit these in the configuration file, but I recommend using the Advanced Configuration Editor instead: https://docs.connectwise.com/ConnectWise_Control_Documentation/Supported_extensions/Administration/Advanced_Configuration_Editor


Additionally, if you wish to disable access to a session, you can always end the session from the Host page.

If these don't suit your needs, you can upvote a similar feature request here: https://control.product.connectwise.com/communities/1/topics/70-automatic-uninstall-of-client

Answer
Not a bug

This is the expected behavior, and not a bug.


Regarding your concerns, Control has a number of settings that might address them. These can be found in the web.config file: Access Token Expire Seconds, Input Idle Disconnect Time Seconds, and Session Expire Seconds. As the names suggest, these are timeouts that will let you control the lifetime of sessions.

You can edit these in the configuration file, but I recommend using the Advanced Configuration Editor instead: https://docs.connectwise.com/ConnectWise_Control_Documentation/Supported_extensions/Administration/Advanced_Configuration_Editor


Additionally, if you wish to disable access to a session, you can always end the session from the Host page.

If these don't suit your needs, you can upvote a similar feature request here: https://control.product.connectwise.com/communities/1/topics/70-automatic-uninstall-of-client

Commenting disabled