#544 awstats_misc_tracker exposed in IE7 security change

closed
Other (206)
9
2012-10-11
2006-04-25
No

The Windows Media check in awstats_misc_tracker triggers the new
security mechanism in Internet Explorer 7, bringing up a message bar
prompting the IE7 user to install the Windows Media 6.4 Player Shim".

A possible workaround would be to remove the line var TRKwma =
awstats_detectIE("MediaPlayer.MediaPlayer.1") from the
awstats_misc_tracking.js file if no newer detection method can be
employed, or if the Windows Media 6.4 Player Shim is allowed or included
in the official IE7 release.

Discussion

  • lewis francis

    lewis francis - 2006-04-26

    Logged In: YES
    user_id=1006385

    Occurred to me that this may in fact be a bug in IE 7bx as the new security
    model reportedly contains a list of "allowed" ActiveX controls that do not
    trigger the security alert bar such as Flash Player; presumably Microsoft
    would want its own Media Player to be treated equally so. http://
    blogs.msdn.com/ie/archive/2005/09/19/471316.aspx

    I'ver entered a bug report and we can track this issue on Microsoft Connect
    (free registration and MS Passport required).
    https://connect.microsoft.com/feedback/ViewFeedback.aspx?
    SiteID=136&FeedbackID=65236

     
  • lewis francis

    lewis francis - 2006-04-26

    Logged In: YES
    user_id=1006385

    sigh. should have written "prompting the IE7 user to run the Windows Media
    6.4 Player Shim control".

     
  • lewis francis

    lewis francis - 2006-05-28

    Logged In: YES
    user_id=1006385

    Microsoft responded that the Windows Media 6.4 Player Shim will NOT be pre-
    approved in IE7. It looks like the ProgID needs to be changed from
    'MediaPlayer.MediaPlayer.1' to 'wmplayer.ocx', the latter which detects WMP7
    and above.

     
  • lewis francis

    lewis francis - 2006-05-28

    Logged In: YES
    user_id=1006385

    Microsoft responded that the Windows Media 6.4 Player Shim will NOT be pre-
    approved in IE7. It looks like the ProgID needs to be changed from
    'MediaPlayer.MediaPlayer.1' to 'wmplayer.ocx', the latter which detects WMP7
    and above.

     
  • lewis francis

    lewis francis - 2006-10-07

    Logged In: YES
    user_id=1006385

    With the RC release, looks like QuickTime detection is also triggering the alert
    and info bar.

    Microsoft's IEBlog states that IE7 will be released this month, with automatic
    update starting a few weeks after the download is made available. Clearly,
    many users are soon going to be having problems with AWStats installations
    that also track plugin usage.

    http://blogs.msdn.com/ie/archive/2006/10/06/IE7-Is-Coming-This-
    Month_2E002E002E00_Are-you-Ready_3F00_.aspx

     
  • lewis francis

    lewis francis - 2006-10-11

    Logged In: YES
    user_id=1006385

    The fix for the QuickTime detection trigger is to change the QT ActiveX line to:

    var TRKmov = awstats_detectIE("Quicktime.Quicktime")

    This info, along with the earlier stated fix for WMP detection, should be enough
    to resolve this issue -- what are the next steps to getting these changes moved
    into awstats_misc_tracker.js?

     
  • Laurent Destailleur (Eldy)

    Logged In: YES
    user_id=96898
    Originator: NO

    Added/Fixed in CVS tree. Will be available in next version.

     
  • Anonymous

    Anonymous - 2007-01-08

    Logged In: YES
    user_id=22084
    Originator: NO

    Hi eldy,

    Just wondering which version this has been fixed in? I'm currently using Advanced Web Statistics 6.6 (build 1.871) as a Fedora Core 6 RPM.

    Thanks,
    Guy

     
  • lewis francis

    lewis francis - 2007-02-13

    Logged In: YES
    user_id=1006385
    Originator: YES

    Guy, you've prob figured this out by now, but the fix is in the 6.6 official release.

     
  • Laurent Destailleur (Eldy)

    Bug added or fixed in last release.

     

Log in to post a comment.