Showing posts with label IntraLearn. Show all posts
Showing posts with label IntraLearn. Show all posts

Saturday, January 14, 2023

Design for the User, Not the Developer

One of my past jobs was at a company that provided legally mandated continuing education courses to securities and insurance reps. Each client's compliance officers needed on-demand reports of student progress and annual reports of compliance status. Knowing these reports were going to be used rarely, but needed to be easy to use when they WERE needed, I worked with several of our clients to build a handful of canned reports that would meet their needs. Some massaging was needed every few years, but the clients were happy. It took them all of five minutes to get the reports that contained the data they needed in the format they needed.

Then came a new bungee boss to run IT. He decided to replace my simple reporting program with a complicated one that involved several steps to add the data you needed. It exposed literally every piece of student information in the system in a complex series of drop-down menus to generate the reports.

The clients HATED it. One of our bigger clients refused to use it because it allowed them to report on how many times a rep had taken the exam before passing. They said they couldn't accept the liability of being able to, in the example they gave, find out a rep needed 45 attempts to pass the ethics exam. They wanted a pass/fail. They didn't even want to know the actual score.

The bungee boss was FURIOUS clients kept demanding my interface instead of his.

"They just need to learn how to use it!" Bungee Boss cried.

"They only use it once a year," I tried to explain. "And they're not IT people."

In the end he just deleted my interface from the system and replaced it with his. The company lost quite a few clients the following year. Bungee Boss convinced the company owner that the reporting changes were not the cause, even though many of the clients who'd left had been part of multi-hour support calls to get the reports they needed.


Wednesday, April 13, 2005

"Encrption.txt (sic)" in the wild

Regular readers (Do I even HAVE any of those? I doubt it.) Will remember this post about an amusing file found in the IntraLearn LMS.

Here are a couple examples of "Encrption.txt (sic)" in the wild. To check for it on your IntraLearn install, just add /cgi-bin/Encrption.txt to the end of the URL itself, deleting /home/ or other information at the end of the URL.

Why does this file matter? Because it consists of the IntraLearn corporation admitting that it distributes software for which it has lost the source code, and as a result, has no way to know what's really in the files they distribute. Seems the perfect place for someone to have put a back door or logic bomb, doesn't it?

The sad thing is, the code isn't compiled, it's encrypted using the cfencrypt utility that comes with Cold Fusion. A quick web search for cfdecrypt would lead them to a command line utility that would allow them to recover the source code of the offending files.

That's right folks, a quick Google is too complicated for IntraLearn developers.

Please note, an absence of the warning about the files does not mean your version of IntraLearn is magically running code for which IntraLearn has the source.

SiteIntraLearn SiteLink to file
UMass Roxbury http://roxburycc.umassonline.net/home/ View the sample
Enbanet Powered Boston University Site http://216.234.48.127/home/ View the sample

Saturday, August 28, 2004

Extending and enhancing IntraLearn

In my last job, I spent six years working with the IntraLearn Learning Management System. I used it literally from it's alpha and beta days right up until August of 2004. In that six year time span, I extended its capabilities to an impressive degree, allowing it to do things that even the developers insisted the product could not do.

In all modesty, I know more about IntraLearn than most the people who work on its code base.

So I've added a new category to my BLOG. Starting with this entry, I will offer a series of articles on how to extend IntraLearn and it's capabilities, how to allow it to scale beyond it's initial specifications and how to stabilize it.

At last count, the IntraLearn infrastructure I designed was able to handle close to 200,000 students with minimal difficulty, using a good deal of custom code.

You may wonder what could possibly motivate me to just give away all my expertise on IntraLearn. The answer is simple, I have no interest in working with it again, so keeping all my data to myself for future use as a contractor is not a consideration. In the end, IntraLearn has some substantial limitations that will forever keep it on the low end, ruling it out of real enterprise use. There are fundamental flaws in the software, and I want people to have the tools necessary to move beyond those flaws. I fully expect the most useful of my planned essays to be the ones detailing how to move student and course data out of IntraLearn and into a different system.

When I'm finished, if you wish to leave IntraLearn, this site will give you all the tools and information necessary to make it happen.

If you must use IntraLearn, this site will enable you to get the most out of the product, allowing you to use it in situations and student populations that not even the authors of the product thought could be done.

Wednesday, July 21, 2004

IntraLearn "Encrption.txt (sic)"

IntraLearn users:

You have been f***ed.

Any doubt?

Below is the text of Encrption.txt, which can be found in the cgi-bin directory of any IntraLearn port. (May have been removed in post 3.5 installs)
---------------------Encrption.txt----------------------------
Two files namely

reports/create_order.cfm
reports/repogen1.cfm

has been encrypted prior to version 2.3 and the source code is not available for the same. When encryting Intralearn, make sure to remove these two files before running cfencode.

Syntax for cfencode

cfencode directorypath/*.cfm /r /v "1"
---------------------Encrption.txt----------------------------


You see, Cold Fusion lets you encrypt your CFM files so your users can't view the source code. This prevents your clients from making unauthorized changes to the product.

IntraLearn lost the source code part of their product, then left the above text file stating as much on their distribution CDs.

The funny thing is (Aside from the fact that they can't spell "encryption") is that the cfdecrypt utility was around a couple years before IntraLearn hit version 2.6. They never bothered to do a google search.

A quick note to anyone looking for cfdecrypt. As of this writing, the first hit is for a web interface to the utility. There is a compiled, command line Windows binary available.

I wish I'd noticed the file ages ago. I could have e-mailed them the decrypted files back when they would have been useful.

Let your mind wander over the implications of a company losing source code to files they continue to distribute. Feel free to take into account the detail that their QA didn't catch the fact that they left an admission of this error in their distribution files.

Let's all hope the last person to work on those files wasn't building any back doors.

Fortunately, the back doors I found after decrypting their source no longer functioned. I don't know if they explicitly removed them, or if other changes to the code happened to break them.

And if you're from IntraLearn, don't worry, I'm not going to post the user names and passwords you hard coded into your "product."