![]() |
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. |
|
|
Thread Tools | Search this Thread | Display Modes |
#1
|
|||
|
|||
![]()
I've written an application that monitors Internet activity on
machines running Windows 2000 (SP4) and IE6. I thought it was working well but have discovered a nasty security flaw. If users go directly to a Windows Explorer window (for example, by double clicking MY COMPUTER) they can type a web address into the address bar and this will bring up the page in the Explorer window, making it equivalent to Internet Explorer. The big problem is that this doesn't show up as such - the window title is just the web page title, MINUS the "Microsoft Internet Explorer". Even worse, IEXPLORE.EXE doesn't then show up in the process list. The end result is that Internet Explorer is running, but undetectably. I missed this problem initially because Microsoft seems to have fixed it in Windows XP with IE7. Any ideas how I can get round this in W2K/IE6? In essence, what I need to do is to prevent users from accessing web pages via Explorer.exe. Failing that, I would have to detect that the user was accessing a web page via Windows Explorer rather than Internet Explorer. I have tried to find details of DDE commands in Windows Explorer, to let me query the address in the address bar. If I could see that this started with "http:" or its variants I should be able to just close the window. I drew a blank with this - no-one seems to list DDE commands any more. Removing Windows Explorer title bars or MY COMPUTER doesn't seem to be an option, as users would then be unable to get to their documents. The PCs with the problem run Windows 2000 SP4 with IE6. I program in Borland Delphi (Version 5) but didn't feel this was a Delphi specific query. I would be very grateful for any suggestions, as upgrading all our machines to XP/Vista will take a long time. |
Ads |
#2
|
|||
|
|||
![]()
For Internet Explorer questions not pertaining to Outlook Express, please
post to one of the following: IE6 Specific Newsgroup: news://msnews.microsoft.com/microsof...er.ie6.browser IE General newsgroup, (For IE6 and IE7): news://msnews.microsoft.com/microsof...plorer.general -- Bruce Hagen MS-MVP Outlook Express Imperial Beach, CA wrote in message ups.com... I've written an application that monitors Internet activity on machines running Windows 2000 (SP4) and IE6. I thought it was working well but have discovered a nasty security flaw. If users go directly to a Windows Explorer window (for example, by double clicking MY COMPUTER) they can type a web address into the address bar and this will bring up the page in the Explorer window, making it equivalent to Internet Explorer. The big problem is that this doesn't show up as such - the window title is just the web page title, MINUS the "Microsoft Internet Explorer". Even worse, IEXPLORE.EXE doesn't then show up in the process list. The end result is that Internet Explorer is running, but undetectably. I missed this problem initially because Microsoft seems to have fixed it in Windows XP with IE7. Any ideas how I can get round this in W2K/IE6? In essence, what I need to do is to prevent users from accessing web pages via Explorer.exe. Failing that, I would have to detect that the user was accessing a web page via Windows Explorer rather than Internet Explorer. I have tried to find details of DDE commands in Windows Explorer, to let me query the address in the address bar. If I could see that this started with "http:" or its variants I should be able to just close the window. I drew a blank with this - no-one seems to list DDE commands any more. Removing Windows Explorer title bars or MY COMPUTER doesn't seem to be an option, as users would then be unable to get to their documents. The PCs with the problem run Windows 2000 SP4 with IE6. I program in Borland Delphi (Version 5) but didn't feel this was a Delphi specific query. I would be very grateful for any suggestions, as upgrading all our machines to XP/Vista will take a long time. |
Thread Tools | Search this Thread |
Display Modes | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Home page in Internet Explorer 7 | Katherine | Outlook Express | 2 | November 12th 06 03:59 PM |
how to access the values in one page to other | safs | Outlook - Using Contacts | 1 | September 13th 06 10:21 AM |
How do I access my boss's calendar from my outlook page? | WonkaWonkaBurningLove | Outlook - Calandaring | 1 | August 7th 06 11:56 AM |
Earthlink is online,but I cannot access Internet Explorer | Phil Ott | Outlook Express | 0 | April 30th 06 08:11 PM |
Denied Outlook "Send" access via Explorer when DSL Yahoo service | Ken Steen-Olsen steen-olsen@sbcglobal | Outlook - Installation | 0 | January 11th 06 11:17 PM |