[2651] in WWW Security List Archive
Re: ActiveX security hole reported.
daemon@ATHENA.MIT.EDU (Elvis Mohan)
Fri Aug 16 13:30:20 1996
From: Elvis Mohan <theking@trinidad.net>
To: "'www-security@ns2.rutgers.edu'" <www-security@ns2.rutgers.edu>
Date: Fri, 16 Aug 1996 11:34:24 -0300
Errors-To: owner-www-security@ns2.rutgers.edu
Hey folks,
Having read about this "security hole".. I decided to try it out myself.
It did work... with the warnings.. but I also noticed that in MSIE3.0,
there is an option to Enable the running of ActiveX scripts and
another option to Enable ActiveX controls and plig-ins. If someone
feels that ActiveX is not secure, I strongly advise them to disable these
options. It can be prevented.
Best regards,
Elvis Mohan
emohan@trinidad.net
theking@trinidad.net