Forum Home
Press F1
 
Thread ID: 16326 2002-03-05 10:24:00 Simple HTML Can Hack Your Windows Guest (0) Press F1
Post ID Timestamp Content User
37986 2002-03-05 10:24:00 Hackers can run anything on your Windows with command written in HTML, an Israeli security researcher said. The trick works on Internet Explorer and Outlook even if active scripting and ActiveX are disabled. A demonstration script is available.

It starts the calculator out of an HTML file. MS said they will patch the hole, but a workaround proposed by Axel Pettinger and Garland Hopkins is apparently working. The registry patch is available on the source, although the workaround will cause IE to launch a security warning that can not be turned off.

Full story: <www.theregister.co.uk
Guest (0)
1