Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Writing to a local file without a warning |
|---|---|
| Date: | Wed, 29 Mar 2006 00:31:03 -0600 |
http://www.aprelium.com/
Regards, - Todd
If I'm understanding you correctly, a web server would be far better solution. If the survey isn't too complicated then the code to save the answers shouldn't be either.
Ian
-----Original Message-----
From: Frank Heyne [mailto:fh@rcs.urz.tu-dresden.de] Sent: 28 March 2006 17:33
To: webappsec@securityfocus.com
Subject: Writing to a local file without a warning
Hello,
this is more about webappinsec, but anyway I hope to get a hint whether
what I need to do is possible at all. You can answer offline, if you prefer.
Question:
Is it possible to write a local file from a ht* file without the
interception of a warning or other dialog?
Task:
There is a standalone Windows machine with a html page from where people
can view information stored in local files with IE. It is nearly like a
kiosk, except the following: There is a questionnaire where people can give some feedback. This must
write the answers to local files in a write only directory with vbscript.
Problem:
All works well except that I still found no way to remove all security dialogues.
What I tried:
1. I can either put the questionnaire in a html file - than the user
sees a security warning about the unsecure ActiveX object (File SystemObject)
when he hits the submit button.
2. When I put the questionnaire in a hta file, this warning is missing,
but there is a dialog asking whether the user wants to run or save the
(local!) hta file when he clicks on the link to it.
I understand that this behavior is ok in most scenarios, but I need an exception for this machine - is this possible and how? I would prefer a quick solution over installing a local web server or
sql server, of course
Any ideas?
Frank Heyne
------------------------------------------------------------------------- This List Sponsored by: SpiDynamics
ALERT: "How A Hacker Launches A Web Application Attack!" Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world examples of recent hacking methods such as: SQL Injection, Cross Site Scripting and Parameter Manipulation
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl --------------------------------------------------------------------------
------------------------------------------------------------------------- This List Sponsored by: SpiDynamics
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [OWASP-LEADERS] Re: [Owasp-dotnet] RE: [SC-L] 4 Questions: Latest IE vulnerability, Firefox vs IE security, Uservs Admin risk profile, and browsers coded in 100% Managed Verifiable code, Stephen de Vries |
|---|---|
| Next by Date: | RE: Writing to a local file without a warning, Damhuis Anton |
| Previous by Thread: | RE: Writing to a local file without a warning, Griffiths, Ian |
| Next by Thread: | Re: Writing to a local file without a warning, Frank Heyne |
| Indexes: | [Date] [Thread] [Top] [All Lists] |