Zone non-secure form submission

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Zone non-secure form submission

Platforms: Windows NT, Internet Explorer
Description:

The security zone settings allow the web browser to submit non-encrypted form data to the URL security zone of the HTML page making the data request. Potentially sensitive data may be intercepted in transit by packet sniffing.

Remedy:

Depending on your version, select one of the following choices in Internet Explorer:

  • For Internet Explorer 4.x:

    1. Open Internet Explorer 4.x.
    2. From the View menu, select Internet Options.
    3. Click the Security tab.
    4. Select the appropriate Zone.
    5. Click Custom (for expert users).
    6. Click Settings.
    7. Disable Submit non-encrypted form data.
    8. Click OK twice to apply the changes.

  • For Internet Explorer 5.x:

    1. Open Internet Explorer 5.x.
    2. From the Tools menu, select Internet Options.
    3. Click the Security tab.
    4. Select the appropriate Zone.
    5. Click Custom Level.
    6. In the Miscellaneous area, disable Submit non-encrypted form data.
    7. Click OK twice to apply the changes.

References:

X-Force Logo
Know Your Risks