Prev | Current Page 417 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"


Automatic Website Checking Off checks a local list of approved URLs that is stored in a
file on a user??™s computer. If a user visits a site that is not in the approved URL file, the
browser will warn the user and then ask her to opt-in to automatic checking process. If a
user selects Automatic Website Checking On, the browser will send each URL visited by
the user to Microsoft??™s phishing database. Microsoft??™s phishing database will then verify
whether the URL is on a list of known phishing URLs. If a user visits a web site that is
not on Microsoft??™s phishing database, the request will be blocked.
In some situations, a user may browse to a web site that seems like a phishing URL,
but it may not be on a known phishing database or on the approved list. In such situations,
when a web site holds the characteristics of a phishing web site but is not reported and
confirmed, IE 7 will send a warning message to the user, informing her about the
potentially hazardous destination.
Protected Mode
Protected Mode takes on a security principal called the least privilege model, in which
applications and services run with only the lowest set of rights they need. IE 7 follows
this principle by running the browser with very restricted access to the rest of the system.


Pages:
405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429
news news news news news