Active Cipher Filtering
As mentioned, alive agreeable in Web pages could be advised abominable from
a aegis point of view. Fortunately, there is a rather accessible and able way to
prevent this agreeable from extensive clients. In HTML, alive agreeable is denoted
by two types of tags.The aboriginal is:
object
…
/object
These tags are added accepted for ActiveX content, but they additionally can be used
by Java applets.There are additionally Java-only tags:
applet
…
/applet
When configured to attending for alive content, the PIX artlessly comments out
both of these tags central a TCP packet and the agreeable amid them, so they are
simply skipped by the client’s browser and anchored cipher is not run.The only
problem with this access is back the aboriginal tag is in one packet and the closing
tag is in addition packet, the PIX cannot accomplish this operation and the Web
page is anesthetized as is. For example, the HTML cipher central an admission packet
might be as apparent in Figure 4.10.