Windows Security
  Home arrow Windows Security arrow Page 2 - Microsoft's Latest Security Updates -- The...
ASP Free Forums 
.NET  
ASP  
ASP Code  
ASP.NET  
ASP.NET Code  
BrainDump  
C#  
Code Examples  
Database  
Database Code  
IIS  
Microsoft Access  
MS SQL Server  
Visual Basic.NET  
Windows Scripting  
Windows Security  
XML  
ASP Web Hosting  
ASP.NET Web Hosting 
Dedicated Servers 
Actuate Whitepapers 
VeriSign Whitepapers 
Windows Web Hosting
 
IBM® developerWorks 
Sun Developer Network 
Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
WINDOWS SECURITY

Microsoft's Latest Security Updates -- The Good, the Bad, and the Ugly
By: Terri Wells
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 5 stars5 stars5 stars5 stars5 stars / 7
    2004-07-26

    Table of Contents:
  • Microsoft's Latest Security Updates -- The Good, the Bad, and the Ugly
  • Three Configuration Changes
  • Download.ject Virus

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT

    Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here

    Microsoft's Latest Security Updates -- The Good, the Bad, and the Ugly - Three Configuration Changes


    (Page 2 of 3 )

    Three Configuration Changes Recommended

    So much for the patches -- but we're not done yet.  In addition to these seven security bulletins, Microsoft also recommended three configuration changes to enhance security.  These changes affect Internet Explorer 6.0 and Outlook Express 5.5 SP2.  If you use either of those, you might want to pay attention.

    Disable ADODB.Stream in Windows ActiveX Control

    First, for Internet Explorer 6.0, ADODB.Stream in Windows ActiveX Control needs to be disabled. This change applies to Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, Windows 98, Windows 98 SE, and Windows Millennium Edition. To fix this problem, you're going to have to modify the registry; make sure you make a back-up first.  Knowledge Base Article 870669 contains the information you'll need to make this change.  Why does this configuration need to be changed?  When the normal configuration is combined with certain well-known security vulnerabilities in IE, an attacker can use a malicious Web site to execute script from the victim's Local Machine zone.  That's because, when ADODB.Stream is enabled, and hosted in IE, it permits access to the hard disk.  

    Limit Shell Automatic Service ActiveX Control

    For the second configuration change, you'll need to limit the functionality of the Shell Automatic Service ActiveX control (shell.application).  This fix is included in the seventh security bulletin.  It's also available through Windows Update or the Microsoft Download Center.

    Read HTML Mail in Restricted Zones

    The third configuration change is included with the first patch.  This one is especially for Outlook Express 5.5 SP2. It forces users to read HTML mail in the restricted zones of the program. This way, users (and networks) will be less likely to fall victim to malicious code sent in e-mail.

    More Windows Security Articles
    More By Terri Wells


       · I found the article about as confusing as the Microsoft patches themselves. I used...
       · I agree with you about most of Microsoft's patches and such. They WILL slow alot of...
       · Yeah, forget Microsoft, use Linux instead of being used by m$.
     

    WINDOWS SECURITY ARTICLES

    - Advanced Data Protection in Windows
    - Basic Data Protection in Windows
    - Windows XP Security
    - Lucky You, Microsoft has Sent You an Email! ...
    - Implementing a PKI, Part III: Managing Micro...
    - Windows 2000 Security
    - A Security Roadmap
    - Implementing a Public Key Infrastructure (PK...
    - Hardening Communications
    - Windows Host Security: Network Security Hacks
    - Hardening Wireless LAN Connections, Part 2
    - Hardening Wireless LAN Connections Part 1
    - Windows Reverse Engineering
    - Microsoft's Latest Security Updates -- The G...
    - Cross Site Scripting (XSS): An Overview





    © 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway