Re: !Testing for the latest vulnerabilities...

From: Colin Nash [MVP] (x_at_x)
Date: 12/28/04

  • Next message: shadowwarrior: "RE: Netmeeting can make, but not receive calls"
    Date: Mon, 27 Dec 2004 22:58:58 -0500
    
    

    "Max Burke" <mlvburke@%$%#@.nz> wrote in message
    news:uqLa39I7EHA.3856@tk2msftngp13.phx.gbl...
    > But is easily prevented by users altering a few security settings in IE.
    > (on XP SP2)
    >
    > --

    Agreed... but the vulnerability needs to be fixed because most users won't
    bother playing with the settings. Also, those restrictive settings do
    interfere with a lot of legitimate sites, which is why they are not turned
    on by default in SP2 (Microsoft did a lot of testing on this stuff.) So its
    a balance between security and making sure that the web browser doesn't bug
    you with annoying warning popups every 10 seconds (the average user will
    either look for a way to turn off these warnings, or start blindly clicking
    'yes'.)

    Perhaps Microsoft needs to redesign the whole security model that IE uses...
    Longhorn should bring some big updates to IE. But for now, all they can do
    is patch these individual problems as quickly as possible.


  • Next message: shadowwarrior: "RE: Netmeeting can make, but not receive calls"

    Relevant Pages

    • Re: GPO Update Problem (SYSVOL access via UNC)
      ... Server Security and Auditing Policy ... This list only includes links in the domain of the GPO. ... The settings in this GPO can only apply to the following groups, users, ...
      (microsoft.public.win2000.group_policy)
    • Re: GPO Update Problem (SYSVOL access via UNC)
      ... > Server Security and Auditing Policy ... > This list only includes links in the domain of the GPO. ... > The settings in this GPO can only apply to the following groups, users, ...
      (microsoft.public.win2000.group_policy)
    • Re: GPO Update Problem (SYSVOL access via UNC)
      ... >> Server Security and Auditing Policy ... >> The settings in this GPO can only apply to the following groups, users, ... >> Windows Firewall: Allow file and printer sharing exception Enabled ...
      (microsoft.public.win2000.group_policy)
    • Re: Problem with NT4 domain trusting W2003 domain
      ... | implemented the settings you suggested in the "default domain controller ... | GPO" and not in the local GPO, and verified with GPMC that they are ... |> suspect there are some settings in security options caused this problem, ...
      (microsoft.public.windows.server.migration)
    • Re: Open file - security warning....How do I disable it?
      ... You possibly should move this over to the IE security newsgroup, ... IE internet options have both all user and per user settings. ... We are in the process of migrating to windows server 2003. ... and then remove security inside the network. ...
      (microsoft.public.security)

  • Quantcast