Re: WMF Vulnerability, Info.



Open files based on content, not file extension = disabled

Charlie

"MAP" <mikepawlak2REM@xxxxxxxxxxxxxx> wrote in message
news:enpJac%23DGHA.2892@xxxxxxxxxxxxxxxxxxxxxxx

Hello all,
A short time ago while surfing I was redirected to a site that tried to
install this
"POS", fortunately NOD32 stopped it (I have my av set up to ask me what to
do) when I clicked on delete the warning popup was gone and their was
another window, the familiar download window (open,save,cancel) which
clearly identified a wmf file awaiting download, my point is that if you
change your internet security custom levels to something more secure you
might not get infected with this,if you are paying attention.
My settings are as follows.


To help stop unauthorized downloads via your active x controls change your
default settings.
These settings are good for XP. The wording should be close for other
systems
as well.
Go to control panel and open "internet options".
Click on the security tab then custom level.
make sure these settings are as follows.

Download signed active x controls>set to prompt
Download unsigned active x controls>set to disable
Initialize and script active x controls not marked as safe>set to disable
Run active x controls and pluggins>set to enable
Script active x controls marked safe for scripting>set to enable
Java permissions>set to high
Launching programs and files in a IFRAME" > Prompt
Installation of Desktop items"> Prompt
Navigate sub-frames across different domains>prompt

Any comment is welcomed!

--
Mike Pawlak


.



Relevant Pages

  • Re: PestPatrol
    ... Most of the malware gets on a system these days via your active X settings ... Download signed active x controls>set to prompt ... Download unsigned active x controls>set to disable ... Initialize and script active x controls not marked as safe>set to disable ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WMF Vulnerability, Info.
    ... >> download, my point is that if you change your internet security ... >> My settings are as follows. ... >> To help stop unauthorized downloads via your active x controls change ... I only get prompts when I'm downloading something,regular surfing is no ...
    (microsoft.public.security.virus)
  • Re: ActiveX controls
    ... Create a new user profile and see if you're able to download the ActiveX ... settings to your user profile. ... activex controls on the page won't let it work again.... ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • RE: Spyware/Programs Installed Themselves - SpyBot Doesnt Remove
    ... Google Norton 2005 demo, download it, install, and run. ... > To help stop unauthorized downloads via your activex controls change your ... > These settings are good for XP. ...
    (microsoft.public.windowsxp.general)
  • Re: ZA Conceptual Question
    ... > There is plenty you can do with the firewall settings. ... > Program controls will not by themselves control traffic to a server ... > port 80 for example you would have to use the firewall controls to ...
    (comp.security.firewalls)