Try Again
Security Zone Spoofing
IE About:,Security Zone
credit: the Pull
you can run script in the security context of "My Computer" or "Trusted Sites" :
>MyComputer
Opens about page in My Computer zone and navigates to a javascript url. fig1
-> trusted Sites- Opens an about page in a trusted zone and navigates to a javascript url while remaining in the Trusted Zone. fig2 :
Domains - Opens two remote sites up in iframes while remaining in the My Computer Zone (instead of mixed).
You could just as well open up .hta, .vbs, even .bat files in this manner.