Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Windows :: hack1835.htm

ActiveX control download and redirection



ActiveX control download and redirection

Hi,

I have been playing around with ActiveX controls and I noticed that IE shows
the complete URL even though the download has been redirected. From a user
perspective its a bit unclear where the actual ActiveX control is downloaded
from.

example can be found on (a self signed ActiveX control will be downloaded):

http://www.brinkers.cistron.nl/RedirectYahoo.htm 

It contains the following  tag.

codebase="http://rds.yahoo.com/*http://www.brinkers.cistron.nl/Redire ctTestP
roj1.cab#version=1,0,0,0"
>

IE now shows a dialog ( http://www.brinkers.cistron.nl/activex.jpg ) 
indicating the ActiveX control comes from:

http://rds.yahoo.com/*http://www.brinkers.cistron.nl/RedirectTestProj1. cab

but it is actually downloaded from http://www.brinkers.cistron.nl 

Its probably the correct behavior (by design) but I think it can be misused
in some ways?

Any comments?

Martijn Brinkers

m.brinkers@pobox.com 





TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH