Re: Service Pack 2, file:///C:/index.htm Javascript blocked disabled

From: Code-Curious Mom (none_at_NG.invalid)
Date: 10/25/04


Date: Mon, 25 Oct 2004 10:47:31 -0400

Although this SP2 issue also occurs with Java, Java and Javascript are not
related despite the similar sounding names.

I had a similar situtation with local HTML files used as custom start
pages. I'm using the 'Mark
of the Web' method which you can find at

http://msdn.microsoft.com/security/productinfo/XPSP2/securebrowsing/lockdown_devimp.aspx

It doesn't specify where in the HTML file it should go, but I had a file
that actually was saved from the web, and
there it was located at the top just before <HTML>. Just be sure there are
no spaces after the
 -->
(end of comment mark)
 and <HTML>. Not sure why this has to be, but it won't work if there is a
space there. So something like:

<!-- saved from url=(0028)http://www.InternetZone.net/ -->

at the top of your file immediately before <HTML> should fix it. You can
change InternetZone.net to a real web address if
desired, it doesn't matter. The 28 is the number of characters in the web
address following, if you change the address, you'll have to modify the
character count too.
(Before I found this method, I had tried renaming the file to *.hta, but
that lets off the menu and toolbar, which I didn't like at all.)

To totally disable this security feature (which I don't recommend--not all
javascript or other active content is safe):
right click IE|Properties|Advanced| scroll down to 'Security', check 'Allow
active content to run in files on my Computer', click 'OK'.

More info see these threads:
http://groups.google.com/groups?hl=en&lr=&threadm=OYIKnezpEHA.2684%40TK2MSFTNGP11.phx.gbl&rnum=4&prev=/groups%3Fq%3Djavascript%26hl%3Den%26lr%3D%26group%3Dmicrosoft.public.windowsxp.general%26sa%3DG%26scoring%3Dd

http://groups.google.com/groups?hl=en&lr=&threadm=NPdl5jCU1HQBFwv9%40squeaky.demon.co.uk&rnum=1&prev=/groups%3Fsafe%3Dimages%26as_ugroup%3Dmicrosoft.public.windowsxp.general%26as_usubject%3Djavascript%2520mouseovers%26as_scoring%3Dd%26lr%3D%26hl%3Den

>> I just installed Service Pack 2 for Windows XP.
>>
>> I have my Internet Explorer home page set to file:///C:/index.htm
>>
>> Unfortunately, I cannot seem to get the JavaScript on that page
>> enabled all the time (e.g., <FORM><SELECT><OPTION>, and goto a new web
>> page).
>>
>> Yes, I can click on "Allow Blocked Content" every time I load the
>> page, but I would like to tell Internet Explorer that this file is OK,
>> trust it, run JavaScript on it all the time.
>>
>> I also went into Tools, Internet Options, Security, Custom Level and
>> enabled everything (except pop-up blocker) and Javascript still does
>> not work automatically from my local home page.
>>
>> I also tried to add it to trusted sies, but the URL must begin with
>> "https:"
>>
>> What can I do to enable Javascript automatically, (i.e., at all times)
>> for a local file such as file:///C:/index.htm?
>>
>> Thanks
>
>



Relevant Pages

  • Re: Connect to Web interface to process data
    ... >>> I would like to use Java to connect to a Web page. ... > http://bioinfo.cis.nctu.edu.tw/service/gprm/) it seems to be Javascript, ... to an otherwise fully functional HTML form element. ...
    (comp.lang.java.programmer)
  • Re: Javascript
    ... Java and Javascript are two different things. ... Applets are downloaded as separate files to your browser alongside an HTML ... |> opened up a browser window and brought it to google now a browser window ...
    (microsoft.public.security)
  • Security holes in Hotmail, Yahoo, and other webmails
    ... Most webmails services and applications have huge security holes on the ... execution of malicious javascript and HTML code ... some parts of the user's mailbox, without use of javascript. ... Cross-site scripting vulnerabilities on the yahoo.com domain was reported ...
    (Vuln-Dev)
  • Re: HTML4.01 STRICT and hyperlinks with target
    ... new window *in HTML* instead of in JavaScript. ... have a link open a new window in HTML instead of in JavaScript. ... I know this is not a great reason, but I think it is reason ...
    (comp.infosystems.www.authoring.html)
  • [Full-disclosure] [RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in E
    ... RedTeam Pentesting discovered that the IceWarp ... WebMail Server is prone to Cross Site Scripting attacks in its email view. ... To prevent the execution of JavaScript and VBScript code in HTML emails ... and to remove unwanted HTML tags, the IceWarp WebMail Server filters HTML ...
    (Full-Disclosure)

Quantcast