Prev | Current Page 349 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"


4. After installation is completed, the ActiveX control can be invoked without
prompting the user in the future. Note that this item can be con?¬? gured. The
gold bar in Internet Explorer 6 prompts the user of uncommonly used ActiveX
controls. In IE 7, users have the option to provide granular policy about which
objects can run silently, which cannot run at all, and which can run with a
prompt??”this is called the ActiveX opt-in.
To see an example of an ActiveX object, visit labs.isecpartners.com/HackingExposed-
Web20/activex.cepted.htm. ActiveX.cepted is an ActiveX control that leverages IE. The
ActiveX control in this example is built into the operating system but the controls are
usually installed by the web application. The example control will invoke the Shell
.Explorer class ID, which opens a web browser within the browser itself (an example of
an OLE action).
The code for ActiveX.cepted is as follows:


ActiveX.cepted


ActiveX.cepted


CLASSID="CLSID:8856F961-340A-11D0-A96B-00C04FD705A2">




Notice that a browser within the web browser is displayed via the ActiveX control.


Pages:
337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361

ogłoszenia dodatki news news news news