Re: Minor IE vulnerability: about: URLs

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Julian Hall <jules@acris.co.uk> wrote:

> Another approach would be to write your own version of the 
> about: protocol module, and point the server to your
> implementation DLL.

Aye, that would work. But after wandering aimlessly in the registry I've
stumbled upon a quicker workaround.

Go to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\ProtocolDefaults and add a DWORD, name 'about', value
'4'. This puts about: URLs in the Restricted Sites Zone. Hurrah!

-- 
Andrew Clover
Technical Consultant
1VALUE.com AG

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux