Vestibule/history/README.md

4.6 KiB
Raw Permalink Blame History

History — the 2001 VB6 original

This directory is the source code of the kiosk browser Jeremy Anderson wrote in Visual Basic 6 in December 2001, at age eighteen, while on co-op from school for his first employer — a Boston-area MSP and programming company that serviced medical offices. It solved one problem: patients waiting in a lobby would misuse the computer, so the computer needed to become a single-purpose, escape-proof browser.

It ran in that lobby for years. Twenty-five years later it became Vestibule. Nothing in Vestibule's build, runtime, or packaging depends on this directory — it is a non-shipping historic artifact, kept for provenance.

What is here

Three snapshots of the same project, in the directory arrangement they arrived in:

Directory What it is Date
vb6-2001/original/ The earliest iteration. The unlock code is read from C:\windows\system\smt.txt; a first-run setup screen lets the operator set it. Dec 11–17, 2001
vb6-2001/ (top level) The lobby build. The unlock code is hardcoded in the form source; home page www.msn.com. The f-suffixed files are a later development line with the browser-disable step commented out for testing. Dec 12–18, 2001
vb6-2001/Final/ The shipped build: the IEXPLORE.EXE step is active again, wrapped in an error-53 retry loop for machines where the file was already gone. Includes frmBrowserfFloppy.frm, a self-demo variant that navigates to a:\description.html with a blank unlock code, and frmMain.frm ("Reloader"), a leftover test stub. Dec 18, 2001 – Jan 3, 2002

description.html is the 2001-era readme, typos intact.

How it worked

  • A maximized, chromeless VB6 form hosting the Internet Explorer COM control (SHDOCVW.DLL), ControlBox = False, WindowState = 2.
  • SystemParametersInfo(97, True) — the undocumented Win9x screensaver flag — disabled Ctrl+Alt+Del, Alt+Tab, and the Windows key.
  • SetWindowPos with HWND_TOPMOST kept the window on top.
  • The menu hid by default and appeared when the mouse touched the top edge of the screen (picAddress_MouseMove, Y <= 10 twips) — the gesture Vestibule still ships.
  • On startup it renamed IEXPLORE.EXE to IEXPLORE.bak and deleted the original: an escaped user found no browser to escape to. On unlock it copied the file back.
  • The unlock delay was a GoTo counting loop burning the CPU for half a second. The lock screen used Comic Sans.

It refused to run on NT, 2000, or XP — the screensaver trick does nothing on NT-family kernels, and the About box says so.

The "System Security 1.5" strings

The lock screen and About box carry the name and description of a sibling application — a standalone system-lockdown tool the author wrote alongside this one. The browser reused that app's lock-screen UI wholesale, branding included. The SmtSysMan variable names and the smt.txt unlock-code file belong to that lineage as well. The strings are left in place: they are what the shipped binary displayed.

Scrub log (2026-08-24)

The code is preserved byte-for-byte except for the following, applied so the artifact carries no employer, school, or client identifiers:

Change Where
Employer-branded project filenames renamed to the neutral LobbyBrowser*; project name and output executable inside each project file renamed to match; SourceSafe section headers follow the filenames all .vbp, .vbw, MSSCCPRJ.SCC
Company version string (the school's initials) → empty every .vbp
Hardcoded unlock code (the employer's initials) → "REDACTED" frmBrowser.frm, frmBrowserf.frm, Final/frmBrowserf.frm
Employer name in the 2001 readme → "my co-op employer, a Boston-area MSP and programming company" description.html
The floppy self-demo form's filename (which named a school) → frmBrowserfFloppy.frm Final/

Three files were excluded and are not in this tree:

  • The compiled .exe — it embeds the original project name, the school company string, and the unlock code in its version resource; a binary cannot be scrubbed without a rebuild, and the artifact is the source.
  • IEXPLORE.bak — a copy of Microsoft's Internet Explorer executable captured by the rename step. It is Microsoft's binary, not authored code, and does not ship here.
  • test.txt — an empty scratch file.

Viewing it

The .frm/.bas/.vbp files are plain text and read fine anywhere. Opening the project requires the Visual Basic 6 IDE, and running the result requires Windows 95, 98, 98 SE, or ME — by design, it does nothing on NT-family kernels, which includes every Windows since.