- TalkBack 4 of 36:
- Next »
- « Previous
- Thread View
- Flat View
- I think you're fairly safe...
-
...if you don't run IE/Outlook/Outlook Express. Many of the email bugs and virtually all of the Web page exploits (much more serious, in my opinion) depend on the HTML/ActiveScript parsing engine from IE (which also functions in Outlook/Outlook Express). Mozilla/Opera/Safari and all the others use their own parsing engines, none of which can parse and execute VBScript code, as far as I know. VBScript is the bad boy to watch out for: you can currently completely hide Windows executables in a VBScript array (so that your AV program and Windows security services can't detect it), then execute the code through parsing HTML/VBScript in IE's parsing engine (through either Microsoft's Web browser or their email clients). If you come across, say, a Web page or email message with malicious code embedded, on Mozilla (for example) when the HTML makes a call to parse and execute some VBScript via the <script> tag...nothing happens. Mozilla's parsing engine doesn't know what to do with the embedded VBScript, so it cheerfully ignores it. Badness Averted.
Also, you can use Windows Media Player to sidestep around Windows security zones, so you have to be careful with downloading streaming media in the .ASF, .WMA, .WMV and a couple of other media formats proprietary to Windows. I've encountered .ASF files that could cause Media Player to launch your default browser and make it surf to a predetermined URL. Ouch. I haven't seen this lately, so perhaps Microsoft fixed this in a security patch over the last few months.
I'm going to experiment in a few days with completely removing the Windows Media Player executable ("wmplayer.exe") and see if my Win2K Pro box will still function. If it does, I can then use WinAmp or another media player for media content. - Posted by: Yen_z Posted on: 01/28/04 You are currently: a Guest | Members login | Terms of Use
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Recovery Manager for Active Directory ScriptLogic Recovery Manager for Active Directory? offers an easy-to-use solution for ... Download Now
- Performance Automation in DB2 LUW Quest Software Are you getting top notch performance from your DB2 LUW applications? ... Download Now
- Desktop Authority Version 7.8.1 ScriptLogic Desktop Authority centralizes control over the desktop, combining into one ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Save time with automated shipping solutions
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Visit the UPS Business Essentials Guide
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
- The Compelling Case for Conferencing
-
Read the whitepaper to discover the specific ways Unified Communications can improve your bottom line.

- Click to download >>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study






