IE Trusted Domain Default Settings Facilitate Silent Installation of Exe
From: Greg Kujawa (anonymous_at_discussions.microsoft.com)
Date: 12/30/03
- Next message: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Previous message: Bones: "MS Office patch deployment..."
- In reply to: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Next in thread: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Reply: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 30 Dec 2003 07:56:29 -0800
This might sound saracastic but it isn't intended to be.
In order to address this wouldn't you just enter the
Trusted zone in the settings and adjust the default
settings to be stricter (or even custom)?
I agree by default IE should install with stricter
security settings for Intranet, Internet, Restricted, and
Trusted zones. Similar to how Windows XP shipped with lax
default security settings in many areas.
But a fix for this is simply publishing suggested settings
and providing navigational details to where you can change
these settings. Right?
>-----Original Message-----
>An exploit method was reported in Microsoft Internet
>Explorer, illustrating IE's weak default settings for the
>'Trusted Site' security zone. A remote user can create
HTML
>that will cause an arbitrary executable to be silently
>downloaded to and installed on a target user's system.
>
>http://www.securitytracker.com/alerts/2003/Dec/1008558.htm
l
>
>I hope this is addressed very quickly.
>.
>
- Next message: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Previous message: Bones: "MS Office patch deployment..."
- In reply to: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Next in thread: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Reply: Mike Larson: "IE Trusted Domain Default Settings Facilitate Silent Installation of Exe"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|