lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <BF8A8B02-BD7C-11D8-B3B9-000393B95208@macflat.nl>
From: pieter at macflat.nl (Pieter Niessink)
Subject: Potential Flaw in Internet Explorer Enhanced Security Configuration

Hey,

Microsoft introduced a new piece of software in Windows Server 2003 
called Internet Explorer Enhanced Security Configuration.
Its supposed to stop content which is a potential security risk from 
loading or being run.

Since its installed by default i have it running on my server too. When 
surfing with IE it seems to do its job alright. The problem is
that if you leave your IE window open when the computer goes on 
screen-saver the content seems to load normally. Including
banners, flash objects and applets which should be blocked. This can't 
be good, especially not on a server os.

Has anyone else seen this, or is it a known problem ?

Kind Regards,

Pieter


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ