Forum Moderators: open
The strange thing to me is that even with the patch installed, a malicious source could still "undo" the patch and re-introduce the security hole. And Microsoft actually explains how-to in this bulletin!
XP users are apparently safe on this one - but everyone else may be at risk.
[edited by: tedster at 8:01 pm (utc) on Nov. 21, 2002]
I'm not looking forward to the day when a hacker gets into that Windows Update script. Just think, they hack it, out goes millions of update messages. Half of those people go through the automatic process of updating only to find out that their hard drive has been wiped clean!
[slashdot.org...]
What's interesting is that MS suggest that to be safe against
being being vulnerable after patching things up, one also
should remove everyone -- including Microsoft -- from the list
of "trusted publishers". I was amused at that when I read it.
So who do you then trust...and when...ever?
However, this hole that affects most folks out there
browsing the internet on their Windows PCs (except for
Windows XP according to Microsoft) is not amusing at all.
What's really scary about this is that someone can run
any code they want on your system -- like code to format
your hard drive or install a trojan -- without your
knowledge simply by you either visiting their web page
or opening an HTML e-mail. Just think if some spammer
sent out an HTML e-mail to millions of folks who open
their spam HTML mail before deleting by going message
to message instead of "select all -- delete" without
actually opening the e-mails.
Talk about an easy way to create a DDOS attack network.
This is a menace to the entire internet community.
Take care,
Louis
More specifically, if I set each of the following to disable am I ok?
Download signed ActiveX controls
Download unsigned ActiveX controls
Initialize and script ActiveX controls not marked as safe
Run ActiveX controls and plug-ins
Script ActiveX controls marked safe for scripting
A bit OT, but can anyone explain what the difference is between "Download", "Initialize", "Script", and "Run" above? And what is the minimum I need to enable to allow Flash to run and is there any security risk in doing that?
Thanks!
And, by the way, could those IE6 security and privacy settings be more confusing? I can't figure out half the time how the browser will change is I check a certain box.