Re: WMF Vulnerability, Info.



Galen wrote:
> In news:enpJac%23DGHA.2892@xxxxxxxxxxxxxxxxxxxx,
> MAP <mikepawlak2REM@xxxxxxxxxxxxxx> had this to say:
>
> My reply is at the bottom of your sent message:
>
>> Hello all,
>> A short time ago while surfing I was redirected to a site that tried
>> to install this
>> "POS", fortunately NOD32 stopped it (I have my av set up to ask me
>> what to do) when I clicked on delete the warning popup was gone and
>> their was another window, the familiar download window
>> (open,save,cancel) which clearly identified a wmf file awaiting
>> download, my point is that if you change your internet security
>> custom levels to something more secure you might not get infected
>> with this,if you are paying attention.
>> My settings are as follows.
>>
>>
>> To help stop unauthorized downloads via your active x controls change
>> your default settings.
>> These settings are good for XP. The wording should be close for other
>> systems
>> as well.
>> Go to control panel and open "internet options".
>> Click on the security tab then custom level.
>> make sure these settings are as follows.
>>
>> Download signed active x controls>set to prompt
>> Download unsigned active x controls>set to disable
>> Initialize and script active x controls not marked as safe>set to
>> disable
>> Run active x controls and pluggins>set to enable
>> Script active x controls marked safe for scripting>set to enable
>> Java permissions>set to high
>> Launching programs and files in a IFRAME" > Prompt
>> Installation of Desktop items"> Prompt
>> Navigate sub-frames across different domains>prompt
>>
>> Any comment is welcomed!
>
> Well put and highly effective BUT there's the issue of usability. I
> often surf with those actually set to disabled and then consider
> adding them when the site's needed or with another browser. Sometimes
> I use a third party application to add an additional security zone
> between trusted and internet and surf with a locked down "Internet
> Zone" and leave the middle zone to the not-quite-trustable sites. So,
> the question is, really, that this is great advice but will people
> deal well with the constant prompting while trying to surf?

I only get prompts when I'm downloading something,regular surfing is no
trouble at all.

--
Mike Pawlak


.



Relevant Pages

  • Re: PestPatrol
    ... Most of the malware gets on a system these days via your active X settings ... Download signed active x controls>set to prompt ... Download unsigned active x controls>set to disable ... Initialize and script active x controls not marked as safe>set to disable ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WMF Vulnerability, Info.
    ... Open files based on content, ... clearly identified a wmf file awaiting download, my point is that if you ... My settings are as follows. ... To help stop unauthorized downloads via your active x controls change your ...
    (microsoft.public.security.virus)
  • Re: ActiveX controls
    ... Create a new user profile and see if you're able to download the ActiveX ... settings to your user profile. ... activex controls on the page won't let it work again.... ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • RE: Spyware/Programs Installed Themselves - SpyBot Doesnt Remove
    ... Google Norton 2005 demo, download it, install, and run. ... > To help stop unauthorized downloads via your activex controls change your ... > These settings are good for XP. ...
    (microsoft.public.windowsxp.general)
  • Re: Early Rumour:Fall Dash Update Details
    ... New screensaver settings - when away from Xbox 360, screensaver will play for optional time, before screen goes dark ... New Xbox Live Arcade blade - where you can download, play and learn about Xbox Live Arcade ... Brand new "web based adver-games" flash games which aren't downloaded, but are playable bite sized games, accessed via new Xbox Live Arcade Blade ...
    (uk.games.video.xbox)