Flasher Archive

[Previous] [Next] - [Index] [Thread Index] - [Previous in Thread] [Next in Thread]


Subject: AW: FLASH: Detect options
From: Malte
Date: Thu, 28 Jan 1999 15:20:45 GMT

> If you are using I.E. - just load flash as an ActiveX
> control - in the
> object part of the web page assign a value to "codebase" - it
> should be the
> URL and version number of the flash ActiveX control -
> compressed as a cab
> file. The control will automatically load if the user does
> not already have
> that version of that ActiveX control or have their security
> setting set to
> not receive ActiveX controls.

If any active-x control gets loaded automatically - wow. Free access to your
machine for everybody.

> I would suggest using ActiveX controls rather than plugins on
> I.E. machines.
> The ActiveX control provides the same functionality as the
> plugin but rather
> than being tied just to the browser, it is tied to the
> operating system.

Fine. You realized why ActiveX is dangerous.

> Bottom line, with ActiveX controls your really providing a
> plugin for the
> operating system not just the browser. And the user doesn't
> have to go
> through the frustration of downloading and installing a plugin.

I'd prefer a plugin which works on both my IE and Netscape, has to to
downloaded only once and installation is just a doubleclick. What's so
frustrating about it? I think security is an important topic. ActiveX is
unsecure. I added a article I recently found:

The German media reported that computer hackers could transfer
funds electronically without needing a PIN by inserting an
unauthorized funds transfer into a German Quicken datafile when a user
downloaded an ActiveX application from a website. They implied that
the next time that the user connected online to send instructions, the
unauthorized transactions would be sent as well.

Althout Intuit stated their Quicken is secure and no illegal transactions
happened yet it's clear that accessing the whole system *is* a risk.

Malte K�hrer
--
www.koehrer.de



------------------------------------------------------------------------
To UNSUBSCRIBE send: unsubscribe flasher in the body of an
email to list-manageratshocker [dot] com. Problems to: owneratshocker [dot] com
N.B. Email address must be the same as the one you used to subscribe.
For info on digest mode send: info flasher to list-manageratshocker [dot] com


[Previous] [Next] - [Index] [Thread Index] - [Next in Thread] [Previous in Thread]