Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

forgot password?


Reply


Old
  Post #1 (permalink)   02-11-2010, 03:37 AM
HD Guru
 
Join Date: Jan 2008
Posts: 536

Status: AbbieRose is offline
I'm aware of the dangers that viewing pages with Active-X can pose, because of it's system access. But does it pose a risk to the server at all when your pages utilise it? Or is that merely a one way risk?
 
 
 


Old
  Post #2 (permalink)   02-11-2010, 09:30 AM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
From my understanding, it's only on the user end of things. The Active-X allows extra commands to operate without the users interaction. Personally on my computers, Active-X is disabled on all sites unless I gives specific access to a site I trust.

I don't believe the exploitation flows back to the server (unless the script loaded up a dDOS script to go after the serving page or something.
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #3 (permalink)   02-12-2010, 04:16 AM
HD Newbie
 
Join Date: Dec 2009
Posts: 44

Status: marissa jasmine is offline
i don't understand about Active X and Server Risks ..
Please tell me with details about that..

Thanks for the answers ..
 
 
 


Old
  Post #4 (permalink)   02-12-2010, 07:14 AM
HD Guru
 
Join Date: Jan 2008
Posts: 536

Status: AbbieRose is offline
Well as just explained the risk is not to the server but to the user. Active X allows things to be installed on your computer without your say so, and can change settings. It can be very dangerous-and I too have it disabled.
 
 
 


Old
  Post #5 (permalink)   02-12-2010, 09:49 AM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,008

Status: handsonhosting is offline
Did a quick hunt on Google regarding Active-X and Servers, and for the most part everything says it's an exploit on the user end of things for trojans etc, but then I found this article: http://www.crn.com/security/21840058...PCKHWATMY32JVN

It states that this particular vulnerability affects versions of Windows XP and Windows Server 2003. So it looks like SOME exploits *CAN* indeed flow back to the server level of things.

I've never had any issues on something like this myself, and until just this minute I'd never heard of an Active-X affecting a server. But then I'm a Unix guy and rarely deal with Windows severs.
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #6 (permalink)   02-15-2010, 10:46 AM
HD Guru
 
Join Date: Jan 2008
Posts: 536

Status: AbbieRose is offline
I would think that many people are like you and haven't had to consider it. It only came up because of some custom code that my partner's company refused to host, and I started to look into why and one question led to another. Thanks for the article.
 
 
 


Old
  Post #7 (permalink)   02-15-2010, 11:59 AM
HD Newbie
 
Join Date: Nov 2008
Posts: 44
Send a message via AIM to fortressDewey Send a message via MSN to fortressDewey

Status: fortressDewey is offline
HandsOn..thanks for that link above, I too was thinking it was only the end user.
__________________
Dewey, DedicatedNOW
Senior Account Rep
dcoerper [.at.] dedicatednow.com | 1-973-572-1069
Managed Servers Specials | Collocation | Load Balancing | Clustered Hosting
 
 
 


Old
  Post #8 (permalink)   02-26-2010, 11:26 PM
HD Addict
 
Join Date: Dec 2004
Posts: 198

Status: arbet is offline
Me too. I was kinda confused with ActiveX. Thanks for enlightening my mind about it. Lol.
__________________
Affordable Reseller Hosting: Free Private NS, Unlimited Accounts!
 
 
 


Old
  Post #9 (permalink)   02-28-2010, 12:07 PM
HD Newbie
 
Join Date: Feb 2010
Location: /etc/fstab
Posts: 41

Status: mellow-h is offline
Quote:
is that merely a one way risk?
Exactly! It acts based on your browser, it doesn't perform any operation in the server end. And an activex is coded for windows variant only. If your clients are using Linux, the activex won't load at all.
__________________
Mellowhost - Affordable Cpanel and WHM Reseller Hosting
R1Soft, RVSitebuilder, RVSkin, Softaculous, Fantastico, Domain Reseller and many more ...
Learn Hosting
 
 
 


Old
  Post #10 (permalink)   03-01-2010, 08:02 AM
HD Guru
 
Join Date: Jan 2008
Posts: 536

Status: AbbieRose is offline
Not only is it just windows, it is just internet explorer. None of the other browsers support active-X (thankfully) which I think is a wonderful thing.

I never did like the insecurity and vulnerability that active-X leaves us with, so never run those controls.
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: