Re: secure/nonsecure items dialog box is a PITA

From: newsrider3 (canttake_at_nospamhere.not)
Date: 02/19/05


Date: Sat, 19 Feb 2005 08:27:50 -0600


"Sandi - Microsoft MVP" <sandi_hardmeier@mvps.org> wrote in message
news:eVds5ojFFHA.936@TK2MSFTNGP12.phx.gbl...
> If you are using Internet Explorer 5, have a look at this link:
>
> Incorrect Error Message When Connecting to Secure Web Sites [Q273903]
> http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q273903
>
> Also, if you go to IE tools, internet options, security in IE6 there is an
> option under internet zone for 'display mixed content'. If this option is
> set to prompt, you will get the message you describe.

That's the one. Setting it to "enable" fixes my problem. There's an
associated risk but I'll have to take it. I need to see what certain secure
websites will otherwise not show me. I'm told that's bad web design, but if
so it's fairly common on the internet. Some pretty essential and otherwise
reliable sites have the "flaw". The one I'm thinking of is one of the bigger
domain registrars. The "flaw" happens with their WhoIs lookup.

> If the problem involves a PDF file, and a secure site, check out the URL
> below:
> http://support.microsoft.com/?kbid=321532
>
>
>
> Finally, have a look at this link - in this case there's nothing you can
> do personally to fix the error; you can only wait for the website's author
> to fix their problem:
>
>
>
> PRB: Security Warning Message Occurs When You Browse to a Page [Q261188]
> http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q261188
>
>
> --
> _______________________________________
> Hyperlinks used to ensure advice is current
> Sandi - Microsoft MVP since 1999 (IE/OE)
> http://inetexplorer.mvps.org
>
>
> "newsrider3" <canttake@nospamhere.not> wrote in message
> news:%23fad4ahFFHA.560@TK2MSFTNGP15.phx.gbl...
>> When I'm at a https site and loading different pages therein, I get the
>> following dialog box query very very frequently:
>>
>> Security Information
>> This page contains both secure and nonsecure items.
>> Do you want to display the nonsecure items?
>> Yes No More Info*
>>
>> There is not the usual checkbox so I can opt out of receiving this
>> notice. It is coming up much too frequently, and I must X it off each
>> time, so it is becoming a royal PITA.
>>
>> How can I kill it?
>> --
>> newsrider3
>> (not a MS-MVP)
>>
>> ___________________________________________________________
>> *Downloading non-secure content from a secure Web site
>>
>> The Web site you are viewing is a secure site. It uses a security
>> protocol such as SSL (Secure Sockets Layer) or PCT (Private
>> Communications Technology) to secure the information you send and
>> receive.
>> When sites use a security protocol, information that you provide, such as
>> your name or credit-card number, is encrypted so that other people can't
>> read it. However, this Web page also contains items that do not use this
>> secure protocol.
>> Given what you know about this Web site and your computer, you must
>> decide whether to continue working with this site.
>>
>> If you do not feel confident about working with this site, click No.
>>
>>
>



Relevant Pages

  • [NT] Vulnerability in Microsoft Agent Allows Code Execution (MS07-051)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in Microsoft Agent in the way ... Internet Explorer by setting the kill bit for the control in the registry. ...
    (Securiteam)
  • [NT] Microsoft JScript Remote Code Execution (MS06-023)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... There is a remote code execution vulnerability in JScript. ... Configure Internet Explorer to prompt before running Active Scripting ...
    (Securiteam)
  • [NT] Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS07-042)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vulnerability in Microsoft XML Core Services Could Allow Remote Code ... mode sets the security level for the Internet zone to High. ...
    (Securiteam)
  • [NT] Vulnerability in Microsoft Data Access Components Allows Code Execution (MS07-009)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... this vulnerability by preventing Active Scripting and ActiveX controls ... mode sets the security level for the Internet zone to High. ...
    (Securiteam)
  • Re: [Full-Disclosure] Gates: You dont need perfect code for good security
    ... on the internet trying to hack it and 20+K users pumping mail thru it 24x7. ... doesn't seem to matter when we talk about security so.. ... that it is indeed a secure product and that security is not just a marketing ... an ISP, the internet IS our internal network for many machines, as the world ...
    (Full-Disclosure)