On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 41 of 161:
Next »
« Previous
Let's look at IE's default settings....
I just re-installed XP Pro for a customer and applied SP1-a. (SP2 breaks their proprietary database system which they are NOT going to replace.)

IE's settings most relevant to security and spyware default to:

-> Run ActiveX controls and plug-ins: enabled (without promting)
-> Script ActiveX controls marked safe for scripting: enabled (without prompting)
-> Allow meta refresh: enabled
-> Launching programs and files in an IFRAME: prompt
-> Navigate sub-frames across different domains: enabled (without prompting)
-> Userdata persistence: enabled
-> Active Scripting: enabled (without prompting)
-> Allow paste operations via script: enabled (without prompting)
-> Scripting of Java applets: enabled (without prompting)
-> Install on Demand (other than IE): enabled

These are defaults with the medium security setting (also the default). They have apparently been chosen to keep the user from having those annoying warnings that some website (maybe not even the one you are visiting) is trying to change settings, install software, run a program, etc.

Granted, some of these settings are fairly benign and actually convenient in and of themselves, but there are bad combinations. For example, meta refresh is nice when it redirects you to a website's new address automatically or updates a page with volatile data such as stock quotes. But when it is used in a frame that points to a program file, this program will run on your computer without you even knowing it if running programs in a frame is enabled. You should get a prompt with the default settings in this case, but if you are in the habit of clicking 'OK' to get these annoying messages out of your way, it runs. If you don't want to click 'Cancel' because it might break something, it runs.

Good luck to the typical home user (not a technical person) to even find where to change these settings, much less understand them.
Posted by: Hugh Jass   Posted on: 01/22/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Viruses and spyware are often FUD  FreeBSD | 01/21/05
Also..  FreeBSD | 01/21/05
Yea  IT Scion | 01/21/05
Are you stupid?  FreeBSD | 01/22/05
A web server needs a GUI because...  Hugh Jass | 01/22/05
have you tried to get IIS running?  hipparchus2000 | 01/23/05
IIS  Grayson Peddie | 01/22/05
Hope you're a young man  AmusedAtItAll | 01/22/05
HAHAHAHAHAHAHA  htotten | 01/26/05
And then He can get  E=McSquared | 01/26/05
Wow, that's an excellent point.  el1jones | 01/22/05
Uneducated writers writing humbug  chiwawa | 01/21/05
Great point chiwawa - I liked this one, too:  mlindl | 01/22/05
Uneducated readers writing complaints  oasis268 | 01/22/05
As if  Omch'Ar | 01/23/05
People can parrot the Redmond line all they want  chiwawa | 01/26/05
Psychology of Hacks  PMC-CON | 01/28/05
Hallelujah! Hallelujah! Hallelujah! Hallelujah!  toadlife | 01/21/05
That is really sweet  Jeff Spicoli | 01/22/05
FUD helps Firefox's gaining.  pa2004 | 01/21/05
FUD helps Firefox's gaining???  AmusedAtItAll | 01/21/05
FUD. Yet another meaningless "word" tossed around by trolls  James T. Kirk | 01/21/05
Flame Bait all the way  nucrash | 01/21/05
Pathetic  Letophoro | 01/21/05
Where's little Mikey been?  drichards1953 | 01/22/05
You sound like Mike Cox  CobraA1 | 01/24/05
can't buy a Dell with firefox  sbj | 01/21/05
free download  DarthRidiculous | 01/22/05
Sorry, but in order to enjoy........  Prognosticator | 01/22/05
firefox  timswish@... | 01/22/05
Tabbed Browsing available for MSIE !  xtoptech@... | 01/25/05
Ditto!  slurpee | 01/27/05
English translation  Knorthern Knight | 01/22/05
Which beaches are you surfing?  Squawkbox | 01/23/05
I'll bet you $1000.....  hion2000 | 01/23/05
Rich, aren't we?!  Anton Philidor | 01/24/05
Shouldn't your username be...  Omch'Ar | 01/23/05
I've never run into that  voska | 01/24/05
IE-specifc services  bhayes@... | 01/26/05
Front Page?  slurpee | 01/27/05
Let's look at IE's default settings....  Hugh Jass | 01/22/05
They atack IE because it is easy, ok people hate MS, and it has over 90%  DonnieBoy | 01/22/05
Browser ID settings  ReFoRMaT | 01/22/05
why would microsoft make IE better?  hipparchus2000 | 01/22/05
When it gets to 50%, let us know  ejhonda | 01/22/05
I use all sorts of stuff like e-banking, e-telephone bill site, webshops et  hipparchus2000 | 01/22/05
Shock games don't work? That's news to me  Squawkbox | 01/23/05
Shockwave games work perfectly here  CobraA1 | 01/24/05
re: I use all sorts of stuff like e-banking, e-telephone bill site, webshop  Arlyss | 01/27/05
ditto....no issues...including embedding now  sent2null | 01/29/05
Re: When it gets to 50%, let us know  bhartman24 | 01/22/05
I use FF at home and work  ejhonda | 01/24/05
I've bumped into sites the IE won't work with  voska | 01/24/05
FF on sans.org  genome | 01/24/05
Is 23% good enough?  S.Howard-Sarin ZDNet Moderator | 01/24/05
Not Surprising  John Carroll ZDNet Moderator | 01/24/05
Still a record nonetheless, and I think it's appealing to non-techies also  CobraA1 | 01/24/05
Ahhh but....  PA-ITGuy | 01/25/05
I'm no Techie  cjm_z | 01/27/05
Not just tech sites.  Jack-Booted EULA | 01/25/05
that good but misleading  IT Scion | 01/26/05
FireFox's popularity may eventually attract the attention of malicious code  Squawkbox | 01/22/05
Firefox is a must for older systems..  thetruth_z | 01/22/05
Netscape  donashugh | 01/23/05
You're preaching to the choir here.  Squawkbox | 01/23/05
um...Open Source?  hion2000 | 01/23/05
Re: um...Open Source?  ReFoRMaT | 01/23/05
OK, Let's define it like this then...  Anti_Zealot | 01/24/05
Open Source Reviewing  bhartman24 | 01/24/05
That and closed sources companies can deny it  voska | 01/24/05
Catching Bugs  bhartman24 | 01/25/05
The only people 'reviewing' the source code...  obrad | 01/27/05
Remember Carl Sagan?  PMC-CON | 01/28/05
Right On . . . .  tcg25 | 01/26/05
Firefox  bgms | 01/26/05
Style  mtg_z | 01/23/05
Lack of CSS support???  K B | 01/23/05
Are you crazy?!?  hion2000 | 01/23/05
Causing me problems...  Mike Cox | 01/23/05
Message has been deleted.  Squawkbox | 01/23/05
Consider yourself lucky...  Anti_Zealot | 01/24/05
6.5  Real World | 01/24/05
That's disgusting behavior  bill@... | 01/25/05
why disgusting ....  kp3649 | 01/26/05
Mmmm not very good policy...  kokuryu | 01/26/05
How odd.  Tony3101 | 01/26/05
"you could do better than to call people liars in a forum!"  daniel7c7d | 01/27/05
Mike, That sure is good bait your using!  cjm_z | 01/27/05
Flashkey Funzies  robertltux | 01/26/05
Obviously a False Story  PMC-CON | 01/28/05
FANTASTIC!! Good solid competition makes everyone  Laff | 01/23/05
Consumer websites  Anton Philidor | 01/23/05
Business and Home use  Anti_Zealot | 01/24/05
Security as a sales advantage  Anton Philidor | 01/24/05
Concern for profit  Anti_Zealot | 01/24/05
A wall, not a bunker.  Anton Philidor | 01/24/05
Security is driving FireFox  voska | 01/24/05
Reached the limit of the discussion  Anti_Zealot | 01/24/05
Nice Post / Analysis  PMC-CON | 01/28/05
FF is good, but I still prefer IE...  ObiWayneKenobi | 01/23/05
Why "trolls" prefer FF  Anti_Zealot | 01/24/05
Windows bigotry  tic swayback | 01/24/05
Many Misconceptions  PMC-CON | 01/28/05
Now Now...  John Carroll ZDNet Moderator | 01/24/05
I think it's some we will have to get used to  voska | 01/24/05
Not just a media frenzie...  Anti_Zealot | 01/24/05
Evolution  John Carroll ZDNet Moderator | 01/24/05
Re: Evolution  Anti_Zealot | 01/25/05
Open standards allow for evolution  tic swayback | 01/25/05
To Tic Swayback  John Carroll ZDNet Moderator | 01/25/05
Very right  Anti_Zealot | 01/24/05
Standards  John Carroll ZDNet Moderator | 01/24/05
John, you kill me  JasonL31 | 01/24/05
What sites have you gone to?  sauerb01@... | 01/26/05
More to the question what sites have YOU gone too?  Jamik | 01/26/05
I can run executables from the FF  voska | 01/24/05
You must love viruses  CobraA1 | 01/24/05
You must be joking, right!  Grayson Peddie | 01/24/05
So what you're saying...  Omch'Ar | 01/24/05
i have to ask...  Monkey_MCSE | 01/24/05
I'm not joking, and I'm not taking it back either  CobraA1 | 01/24/05
You all misunderstood...  ObiWayneKenobi | 01/25/05
FF is good, but I still prefer IE...  Gregory.J.Bradley@... | 01/26/05
PRIME EXAMPLE OF MICROSOFT STUPIDITY  itanalyst | 01/23/05
ROTFLMAO  Squawkbox | 01/23/05
hahaha  ecbpro | 01/24/05
Message has been deleted.  Jeff Spicoli | 01/24/05
You should try getting to Tromso (NT)  Letophoro | 01/24/05
ms knew this would happen someday  JasonL31 | 01/24/05
Compare The Most Famous Example of Open- vs. Closed Source  bill@... | 01/25/05
Circular logic  rwgreene | 01/26/05
Firefox hackers  dennisling@... | 01/25/05
how do they earn a living  rwgreene | 01/26/05
FF attracting hackers...  WillemGrooters | 01/26/05
Firefox / Mozilla  edjcox@... | 01/26/05
So Did I!  flyday611 | 01/26/05
are you sure it was from FF?  tinball | 01/27/05
FireFox is a pain!  kp3649 | 01/26/05
Where did this "Firefox" come from?  Taylor_z | 01/26/05
Ease your pain - Protect Yourself  terryp90@... | 01/27/05
Ease OUR pain - Protect Yourself  Jiim_z | 02/17/05
Firefox is my choice  kewlsugr@... | 01/26/05
Try em all  bobb88 | 01/26/05
Firefox is not everyones choice  Tony3101 | 01/26/05
FireFox an immediate necessity  Laurie53 | 01/26/05
FoxfireVsIE  GrumpyDan | 01/26/05
No confidence in Firefox - after seeing Thunderbird  Emilio_z | 01/26/05
Firefox is the BEST!  computer_master103 | 01/26/05
Firefox draws hackers?  shujin | 01/26/05
It really doesn't Matter  Bob Hughes | 01/26/05
Sure it will attract some  agottschald | 01/26/05
fox versus IE  chanakya | 01/27/05
FireFox continues gains  stevezd | 01/27/05
IE Back-Doors vs FireFox guarded doors  RexBallard | 01/27/05
Firefox willl NEVER be hacked...  merlinregis | 01/27/05
Firefox willl NEVER be hacked  stevezd | 01/27/05
OF COURSE it will!  golowenow | 01/27/05
Should we choose the red honey or blue honey?  eantolik@... | 01/27/05
Do you think Firefox's increased popularity will attract hackers  IT be me | 01/27/05
Firefox? There May Be Better...  mrbiz@... | 01/31/05
How does one become a hacker of FireFox?  Amy Elliot | 04/14/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here