Forum Moderators: open

Message Too Old, No Replies

IE Security Settings

XP2 default allows scumware

         

Iguana

8:45 pm on Sep 4, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've just upgraded to XP service pack 2 and all my security settings were reset. I went to check out a site because of a link request and noticed IE was unpacking a .cab file. I immediately killed the browser. I then checked my security and found that "Automatic Promting for ActiveX controls" was disabled. I think this means that any ActiveX marked as 'legitimate' (i.e. has gone through some Microsoft verification) will be installed on your machine without explicitly asking for your permission. This particular ActiveX was from Internet Search Technologies and installed a sidebar and a whole host of other spyware/shopping software.

I can't believe that Microsoft can allow the default settings of the browser to be set to allow this scumware onto a machine without warning. I just can't imagine the trouble this is causing most non-techie users (well, I can because I have had to de-infest other people's PCs and have a waiting list of acquaintances to do the same for).

I know, Firefox is the answer - but I like to browse with the same software as my website users. I'm just disappointed that XP2 is so insecure when it was trumpeted in such a different way. I sent a suitably angry response to the b***ard who asked for the link.

MatthewHSE

2:54 pm on Sep 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I know, Firefox is the answer - but I like to browse with the same software as my website users

So use Firefox for your main browser, and IE only for your own site. Works for me.

encyclo

3:04 pm on Sep 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Or use Linux for your operating system, and forget about IE except for testing! :)

jessejump

4:02 pm on Sep 5, 2005 (gmt 0)

10+ Year Member



Isn't Disabled the more secure choice?

Iguana

4:59 pm on Sep 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Disabled for this particular setting means it will just go ahead and install a signed ActiveX. There is another setting for disabling ActiveX altogether though.

One good thing about this whole situation is that I've been badly hit over the past 6 months with various infections/trojans etc. I tried all of the free removal software and virus checkers and none of them cleansed my PC. But I am now an expert at identifying and removing just about any unauthorised pests. Maybe I should go freelance and fix all thiose untechie computer users for a fee?

jessejump

5:29 pm on Sep 5, 2005 (gmt 0)

10+ Year Member



From some site: Normally, the Internet Explorer 6 information bar appears whenever it blocks a file or download. This informs you of the blocked file, plus it allows you to unblock the particular file or download. If you do not want this information to be displayed:

1. From Internet Explorer 6, click "Tools".

2. Select "Options".

3. When the multi-tabbed "Internet Options" dialog box appears, select the "Security" tab.

4. Click on the "Internet" zone, or other zone as appropriate if you have set them up for certain sites.

5. Click "Custom Level".

6. Under "Automatic prompting for ActiveX controls" select "Disable".