Bugtraq mailing list archives

Re: IE 5.0 allows executing programs


From: jjohanss () BU EDU (Jesper M. Johansson)
Date: Sat, 28 Aug 1999 10:44:32 -0400


Actually, the setting that goes right to the heart of this one is "Script
ActiveX Controls Marked Safe For Scripting".  Default for "Internet Zone"
is Enable.  It is probably safest to set it to either disable or prompt.

On some sites, you'll find that you may want this to function, and I'd
consider adding them to the "trusted sites" zone.

I don't know that you want it as a trusted site, but I realized yesterday
that Windows Update needs to be able to "Script ActiveX Controls Marked Safe
For Scripting." Thus, if you want to be able to use Windows Update, you must
set this to either enable or prompt.

Jesper


Current thread: