OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Andrew Clover (anddoxdesk.com)
Date: Fri May 17 2002 - 04:27:37 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Thor Larholm <Thorjubii.dk> wrote:

    > The above is merely misinformation on their parts. The Restricted Sites Zone
    > tries to disable scripting ( a requisite for the dialogArguments
    > vulnerability ), but many vulnerabilities allow you to circumvent this
    > setting

    Even non-vulnerabilities allow it. For example a <meta http-equiv="refresh">
    can redirect to a page not within the Restricted Sites zone, and a
    <frame> or <iframe> can include content from a non-restricted site.

    It is also possible to create an about:<script>...</script> URL, which
    injects scripts into the Internet zone. Such URLs cannot be put in the
    Restricted Sites zone using the normal IE Security tab. Microsoft have
    refused to remove this undocumented behaviour.

    So essentially the Restricted Sites feature offers zero security protection
    by design. Users should not rely on it to enforce stricter settings than
    present in the Internet Zone.

    -- 
    Andrew Clover
    mailto:anddoxdesk.com
    http://and.doxdesk.com/