
Crestron TPMC-8L Isys i/O™ 8.4” Touchpanel Media Center
Security Infrastructure
Since the TPMC-8L does not use a traditional hard drive but rather an image that
gets restored every time the touchpanel is rebooted, any virus infection is cleared
immediately after a reboot. However, using the currently available tools and
techniques, Crestron has provided an infrastructure that protects against possible
virus infections.
1. Executables/Scripts brought in on external media
The implementation of the TPMC-8L has restrictions on starting any application
or script. The only applications that can be started are those allowed by Crestron
and these can only be started from the Crestron project.
2. Downloaded Program/Script
The browser is customized in such a way that files cannot be downloaded. The
only files the browser can open are the files it has plug-ins for, such as PDF, etc.
The user cannot change the options, as this dialog box has been disabled.
3. Browser Hijack and Browser vulnerability
Crestron has patched all currently known hijacks and vulnerabilities. Future
updates can be downloaded from the Crestron website.
4. Email Viruses
There is no e-mail client installed on the TPMC-8L, so email-based viruses
cannot be executed.
5. Viruses that attack web/FTP servers
The TPMC-8L does not run a web or FTP server and is therefore not listening to
port 21 or 80. The only ports the system listens to are the ports registered to
Crestron.
6. Virus from other machines on the network
Since drives on the TPMC-8L can be shared on the network, it is possible that a
virus can write itself to files/folders on these shares. Our recommendation
therefore is to share as "Read-Only," so that viruses cannot attach themselves to
files on the TPMC-8L.
7. ActiveX and Java
The TPMC-8L has ActiveX disabled and has no Java Virtual Machine installed.
These applets cannot run on the TPMC-8L.
NOTE: While browsing the Internet with the TPMC-8L, clicking on a link may
cause a message box titled "Restrictions" to appear that contains the text "This
operation has been cancelled due to restrictions in effect on this computer. Please
contact your system administrator." If this message appears, checking Enable Popup
Windows in the “Embedded Apps” section of the setup menu may correct this error.
Other restrictions may also cause this error, so this may not prevent all occurrences.
NOTE: Security settings and restrictions can be changed via the Embed Apps
button on the setup menu. Refer to “Embed Apps (Embedded Applications)” which
starts on page 18 for details.
Operations & Installation Guide – DOC. 6594B Isys i/O™ 8.4” Touchpanel Media Center: TPMC-8L • 55
Commentaires sur ces manuels