sau đó nó sẽ có thể có hiệu quả phân phối một chương trình độc hại trên Internet. Một vấn đề khác là nếu thông tin hợp lệ được cung cấp cho CA, nhưng giấy chứng nhận được gắn vào phần mềm với mã xấu hoặc độc hại. Sử dụng phần mềm như Microsoft Certificate | 98 Chapter 3 Understanding the Risks Associated with Mobile Code Lowering JavaScript Security Risks Precautions that administrators will take to protect their users from damage include first and foremost making sure that users have the latest software versions and that they have all the patches. As we mentioned in this section most holes with JavaScript were related to the implementation of the scripting language on the part of browser makers. If they are using Web-based mail administrators will make sure that users subscribe to a service that filters out potential security threats. Hotmail and others remove any JavaScript from incoming messages before you see them other Web-based e-mail providers may be more casual toward security threats so they may not provide filtering of scripting. A more radical step is that they might disable is also an option for the program to prompt the user each time JavaScript is run but then users might get an overwhelming number of prompts. Netscape allows users to disable JavaScript either for the browser only or for mail only. VBScript The other embedded scripting language out there that you can use in HTML documents is Microsoft is short for Visual Basic for Scripting Edition. As the name suggests the syntax of the language looks very similar to Visual Basic much like JavaScript resembles Java. It offers approximately the same functionality as JavaScript in terms of interaction with a Web main difference is that VBScript can interact with ActiveX controls that a user has installed. VBScript only works with Microsoft Internet Explorer and Outlook so it is not nearly as popular in Web pages as JavaScript is. The only way to get VBScript working with Netscape Messenger or Navigator is to download a plug-in for Netscape such as is an extra step that many users will avoid because they aren t aware of it or don t want to be bothered. However Internet Explorer is included with