Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows NT/2000/2003 Server/2008 Server
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions.

Reply
 
LinkBack Thread Tools
Old 02-20-2008, 09:30 AM   #1 (permalink)
Registered User
 
Join Date: Feb 2008
Posts: 2
OS: xp,vista,centos,2003server


Windows server 2003 Security - Javascript

Me and a friend have purchased a dedicated server.

This box is running Windows 2003 Standard R2 x86


We use it as a web server along with running a game server (CS:S)

We are having a debate on the security issues implied with enabling Javascript inside Internet Explorer 7 on the server.

When using remote desktop, we want to be able to download mods/mappacks etc for the server. But doing this is difficult as most websites require javascript enabled.

I know javascript enabled is a security risk if the user visits a "dodgy" website.

But is it a security risk just being enabled? He seems to insist people could use php exploits to upload/activate custom javascripts on the server.

I cannot find any reference to these exploits on the internet, ive found some with shell/asp scripts but not with javascript.

Thankyou

/pantho
Pantho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-20-2008, 02:49 PM   #2 (permalink)
TSF Enthusiast
 
XtabbedoutX's Avatar
 
Join Date: Sep 2007
Location: Oklahoma City
Posts: 1,189
OS: Server 2K3 R2 SP 2, Server 2K SP4, XP PRO SP 3, Mac OS X 10.5, iPhone

My System

Send a message via AIM to XtabbedoutX
Re: Windows server 2003 Security - Javascript

I would disable it AS LONG AS you are only going to download map packs and patches. I would not surf the internet with a server any way. Use a client computer to download the map packs and patches then upload them to the server.

With a gaming server you have to leave ports open anyway so that is a greater security risk than java script.
XtabbedoutX is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-20-2008, 07:15 PM   #3 (permalink)
Registered User
 
Join Date: Feb 2008
Posts: 2
OS: xp,vista,centos,2003server


Re: Windows server 2003 Security - Javascript

Quote:
Originally Posted by XtabbedoutX View Post
I would disable it AS LONG AS you are only going to download map packs and patches. I would not surf the internet with a server any way. Use a client computer to download the map packs and patches then upload them to the server.

With a gaming server you have to leave ports open anyway so that is a greater security risk than java script.
Problem with servilely limited upload capabilities on client side.

But i already decided on the action, and jscript will be disabled.

But i am trying to settle a debate on the subject :)

Does enabling javascript, even if we never surfed the internet, have any significant security risks?
Pantho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-21-2008, 10:16 AM   #4 (permalink)
TSF Enthusiast
 
XtabbedoutX's Avatar
 
Join Date: Sep 2007
Location: Oklahoma City
Posts: 1,189
OS: Server 2K3 R2 SP 2, Server 2K SP4, XP PRO SP 3, Mac OS X 10.5, iPhone

My System

Send a message via AIM to XtabbedoutX
Re: Windows server 2003 Security - Javascript

Quote:
Originally Posted by Pantho View Post
But is it a security risk just being enabled? He seems to insist people could use php exploits to upload/activate custom javascripts on the server.
No. You can run JavaScript on a server without having it enabled in IE anyway. JavaScript is used for more than just websites.

I have a content filter that the management console is written in java and does not use a browser.
XtabbedoutX is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:27 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85