NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
Home / News / Microsoft / Tweak Mode

Tweak Mode


IE7 Mark of The Web

Internet vs. intranet vs. the window.status method call

By Marius Oiaga, Technology News Editor

14th of February 2007, 12:14 GMT

Adjust text size:


What do you think Dave Massy, the IE Senior Program Manager, is up to in his last days at Microsoft? Well, not much. Except a blog entry on MOTW. The Mark of the Web was designed
as a security feature that manages web pages over security zones in accordance with the restrictions imposed by the Local Machine zone. The fact of the matter is that in Internet Explorer, the browser's default settings can differ according to the security zone where the page is running.

"By default the security settings for content running in the Internet zone are a little more restrictive than those for content running in the intranet zone. One example is that in IE7 under default security settings a web page running in the Internet zone may not write text to the IE status bar using the window.status method call, whereas the call is allowed in the intranet zone," revealed Massy, adding that the limitation was designed as a protection method against spoofing.

In Internet Explorer 7, online content cannot have any impact in the exterior of the HTML rendering area. Microsoft advised developers to extensively test web pages content outside the local server, and check the results of a call to set window.status on the Internet as opposed to the intranet.

"To avoid these differences and have content run in the internet zone despite it originating on the intranet you can add the Mark Of The Web (MOTW) to pages. The MOTW is a comment that should be placed at the start of the HTML page to show that the content is from the internet in the form ," explained Massy. "Including the MOTW in pages and checking that you have default security settings during development can help ensure that you are experiencing the same settings as users of IE on the internet will have when your pages are deployed."


Rating:
Very Good (4.2/5) 4 vote(s) so far    

Read by 1,721 user(s) | Add comment | Link to this article
Subscribe to news | Print article | Send to friend

© Copyright 2001-2008 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Firefox 2.0 Continues to Grow in the Detriment of IE7

God Save Internet Explorer

Remove the Search Box from Internet Explorer 7

Internet Explorer Sinks Under 80%

284 Days - The Attack Window of IE in 2006

Internet Explorer 7 vs. Firefox 2.0

Internet Explorer 8.0

100 Million Installations - Internet Explorer 7

Microsoft Is Already Running Internet Explorer 8.0

Internet Explorer 8.0 Features

Microsoft in the House of Lords

Manage Internet Explorer 7 Protect Mode

IE 7 Global Usage Share Grows to 10.97%

Internet Explorer 8 Feature Survey Email

Internet Explorer 8.0 Available for Download on Peer-to-Peer Networks

The First Security Vulnerability in Internet Explorer 7

Microsoft Contracts Web Standards Evangelist

Targeted Attack Scenario via a Microsoft Vulnerability

IE7 - the First Browser to Support EV SSL Certificates

Microsoft Revamped IE Add-ons

IE7 Security Features Should, In Theory, Protect the Computer?

Internet Explorer 7 - Scarred By Vulnerabilities

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 






SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM