Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: 'cross site scripting' CERT advisory and MS

Re: 'cross site scripting' CERT advisory and MS

From: Alexander Schreiber <Alexander.Schreiber_at_INFORMATIK.TU-CHEMNITZ.DE>
Date: Fri, 18 Feb 2000 13:46:41 +0100

On Thu, 17 Feb 2000 flynngn_at_JMU.EDU wrote:

> David LeBlanc wrote:
> >
> > What I recommend specifically for using Outlook (probably also applies to
> > other mail readers using IE as a HTML viewer) is:
> > 1) Set it to run in the Restricted Sites zone
> > 2) Edit the Restricted Sites zone into what I call maximum paranoia mode -
> > turn EVERYTHING off. IIRC, cookies are off to begin with, but this gets
> > them turned off for sure.
>
> Wouldn't it be better to set the Internet zone for high security and
> then set the browser to use the Internet zone? The restricted zone requires
> entering the list of untrusted systems while the Internet zone says

Sorry - but having to specify the list of _untrusted_ systems for a
restricted zone sounds broken to me - this means that by default you trust
everybody, unless specified otherwise. I think the other way around (i.e.
giving a list of _trusted_ systems) is the correct way to go. Or am I
horribly mistaken here ?

Regards,
       Alex.

--
------------------------------------------------------------------------------
 EMail : als@thangorodrim.de              | WWW : http://www.thangorodrim.de/
 If privacy is outlawed, only outlaws will have | Ceterum censeo Parva Mollia
 privacy. (Philip Zimmerman, author of PGP)     | esse delendam.
Received on Feb 18 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos