Re: Another Scripting Hole In Microsoft IE Exposes Local Files

From: Ken Hagan (K.Hagan@thermoteknix.co.uk)
Date: 01/04/02

  • Next message: Alun Jones: "Re: Another Scripting Hole In Microsoft IE Exposes Local Files"

    From: "Ken Hagan" <K.Hagan@thermoteknix.co.uk>
    Date: Fri, 4 Jan 2002 10:13:56 -0000
    
    

    "Wolfgang Schelongowski" <spamtrap@xivic.prima.de> wrote...
    >
    > Both Javscript and ActiveX are known to be insecure by (lack of) design
    > for *all* platforms, where they can be executed. It's been known for
    > years that they are security risks.

    For ActiveX this is uncontroversial, since native code is executed.

    However, most of scripting problems I see with IE seem to result from
    the *extent* of the scripting object model. For example, IE seems to
    let you do via scripting pretty much anything that you can do at the
    command prompt.

    Surely a browser that restricted scripts to performing calculations
    and reading or re-writing the web pages that they were embedded in
    would be fairly safe, no?

    Such a system would not be very different from a properly sandboxed
    Java host, and I've yet to hear anyone argue that the JVM is
    "insecure by lack of design for all platforms".



    Relevant Pages

    • Re: linksmanager
      ... Did you design your site or did you pay someone to design it? ... and learned html in the process. ... scripting to help clients that don't have server side scripting. ... is to perhaps don't make the background image repeat itself. ...
      (alt.internet.search-engines)
    • Re: Random Number
      ... scripting language. ... My own very first contact with TCL in a production environment, ... and/or the design as a whole (being just another ... components in the testbench that didn't have that complete isolation. ...
      (comp.lang.tcl)
    • max-width web page design
      ... want a maximum width for your web page in IE using div's, scripting ... is superior to the use of div's when you need a max width ... benefit of your intended design. ... theoretical browser behavior, but to get the specific behavior ...
      (comp.infosystems.www.authoring.html)
    • Re: Python vs. Lisp -- please explain
      ... |> Early Tcl and JavaScript are scripting languages, Python is not. ... Which shows that by this definition scripting language is not a ... So I set out to design my own." ...
      (comp.lang.python)
    • Re: Reading Registry keys with VBscript
      ... > VBScript on other platforms (win98 and later)? ... I'm missing part ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
      (microsoft.public.scripting.vbscript)

  • Quantcast