FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > General Site Owner Support (All may read/respond) > Places To Go Sites To See!
User Name
Password  Lost PW

Reply
 
Thread Tools Search this Thread Display Modes
Old 04-18-2002, 05:07 PM   Postid: 66258
lepton
Site Owner
 
lepton's Avatar

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Jan 2002
Posts: 149
Another Big MS Browser Hole Found

Quote:
Internet Explorer users who click their browser's back button open the Windows operating system to a malicious hack attack.

When users hit the back button on Explorer's toolbar, the browser's security settings for the "Internet" zone can be bypassed, and the browser will automatically execute malicious code embedded into a site's URL.
From Wired News

lepton is offline   Reply With Quote
Old 04-18-2002, 06:29 PM   Postid: 66260
kitchin
Site Owner

Forum Notability:
1163 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Jan 2001
Location: Virginia
Posts: 2,992
If this article is accurate, Micorsoft's response is inadequate. Basically, don't use the back button on untrusted sites.
Quote:
The problem is caused by what can politely be described as a design flaw in Explorer. When a Web page fails to load, Explorer displays a standard error message. This message is set to operate in the "Local Computer Zone" security setting, which by default allows scripting to run automatically.

Any code inserted in the original URL is handled as if it comes from the same security zone as the last URL viewed. So a URL containing malicious JavaScript that might be blocked by default if a user visits the site directly, will be automatically triggered when the user presses the back button.

... [discoverer] Sandblad suggested the usual fix for browser woes; disable active scripting.
I guess "Local Computer Zone" means "Local Intranet" in Internet Options? In the typical home setup, no network other than an internet connection, why not just set security at the same level for all four icons (Win98, IE 5):
-Internet
-Local Intranet
-Trusted Sites
-Restricted Sites
OK, maybe higher on the last one! But the first three could be set high, or medium + script blocking, right?

Wouldn't that work for most people? Who needs local active scripts? I guess that's just what Sandblad is saying.
kitchin is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:10 AM.


Running on vBulletin®
Copyright © 2000 - 2013, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2013 FutureQuest, Inc.
FutureQuest, Inc.