Re: MS ISA activeX Filtering

From: Paul Kurczaba (paul_at_myipis.com)
Date: 10/04/04

  • Next message: Eric: "Re: Tool for removing LANMAN hashes from registry"
    To: "Casey DeBerry" <cdeberry@cobizinc.com>, <focus-ms@securityfocus.com>
    Date: Mon, 4 Oct 2004 14:51:56 -0400
    
    

    I would filter the following file extensions: cab, ocx, and dll. These are
    used by ActiveX.

    I don't know if ISA 2000 can block ActiveX. That would be kind of funny
    though...One microsoft technology blocking another microsoft technology.

    Note that if you block cab, ocx, and dll extensions, it will block the
    legitimate Windows Update site as well as the Office update site.

    -Paul
    ----- Original Message -----
    From: "Casey DeBerry" <cdeberry@cobizinc.com>
    To: <focus-ms@securityfocus.com>
    Sent: Monday, October 04, 2004 11:41 AM
    Subject: MS ISA activeX Filtering

    Will MS ISA 2000 Server block ActiveX applications on its own? In other
    words.. Users are unknowingly downloading the dowloader.MM trojan. My AV
    Software is finding and renaming/deleting it successfully, but I would like
    another layer of protection to keep the specific activeX application from
    entering the enterprise.

    Do I need another add-on?

    Thanks,
    Casey

    --------------------------------------------------------------------------------------------------------------------
    CONFIDENTIALITY NOTICE:

    This e-mail contains confidential information and is intended only for the
    individual named. If you are not the named addressee, you should not
    disseminate, distribute or copy this e-mail. Please notify the sender
    immediately if you have received this e-mail by mistake and delete this
    e-mail from your system. E-mail cannot be guaranteed to be secure or
    error-free as information could be intercepted, corrupted, lost, destroyed,
    arrive late or incomplete, or contain viruses. Neither the sender nor CoBiz
    Inc. and its subsidiaries accept liability for any errors or omissions in
    the contents of this message, which arise as a result of e-mail
    transmission.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Eric: "Re: Tool for removing LANMAN hashes from registry"

    Relevant Pages

    • RE: MS ISA activeX Filtering
      ... You've got to be a little careful with .dll - some sites use a dll on ... Subject: MS ISA activeX Filtering ... Will MS ISA 2000 Server block ActiveX applications on its own? ...
      (Focus-Microsoft)
    • Re: Java Applet Funktionalität in ASP.Net
      ... Ja indem du per Tag eine dotnet dll einbindest, ... Programmierung, also Applets, ActiveX, einschließlich javascript. ... ..NET Framework basierende Komponente" ist also keineswegs unsicherer. ... Packe dein Windows Formular in eine Windows Control Library, ...
      (microsoft.public.de.german.entwickler.dotnet.asp)
    • Re: why some dlls are scriptable and some are not?
      ... which is the same as ActiveX. ... So a COM DLL is also an ActiveX DLL. ... through its "OLE" functions to read type libraries. ... An object browser shows the methods and properties ...
      (microsoft.public.scripting.vbscript)
    • Re: Java Applet Funktionalität in ASP.Net
      ... >> Applets in normalen HTML Seiten hinzubekommen? ... > Packe dein Windows Formular in eine Windows Control Library, ... > du eine DLL. ... Bei ActiveX wird ja auch local beim Client was installiert, ...
      (microsoft.public.de.german.entwickler.dotnet.asp)
    • Re: Using a C++ Win32 DLL internally in an ActiveX deployed on a webpage
      ... A quick and dirty solution would be to dump the dll into the ... Active-X control is being installed. ... Can an MFC ActiveX control use a C++ DLL internally to process ... control on the client machine, ...
      (microsoft.public.vc.mfc)

    Loading