• Home
  • Reviews
  • Articles
  • News
  • Tools
  • GamingHeaven
  • Forums
  • Network
 

Go Back   DriverHeaven.net > Forums > Software / Tools > Windows XP / 2000 / NT / 9x Forum

Notices

Reply
 
LinkBack Thread Tools
Old Jun 10, 2004, 10:37 PM   #1
DriverHeaven Lover
 
Join Date: Apr 2004
Posts: 123
Rep Power: 0
malkor is on a distinguished road

Enable 5th Hidden Security Zone

Especially for those who still insist upon using Internet Explorer

You actually have a 5th, hidden, security zone in your IE6 Internet Options->Security->Zones know as "My Computer". You can protect your system from yourself. Okay here's how

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\InternetSettings\Zones\0
"Flags"=dword: 0X00000021 (33) ---default
Change to
"Flags"=dword: 0X00000001 (1)

Now reboot or logoff and back on. My Computer should now be visible in the IE Security Zones selection.



Imagine the following scenario:

You’re happily surfing the web with your Internet zone configured to disable Java script when you arrive at a site which has a malicious java script embedded into the page, no problem your settings are set up to protect you and you move on, none the wiser.
What you may not be aware of is this page, complete with malicious code, has been saved / cached in your Temporary Internet Files directory.
The next time you decide to check this site out, the first thing your browser does is check your Temporary Internet Files directory and open the page from the cache. BANG !!
This page will be opened from cache and is not being opened in the Internet Zone, but in the My Computer zone, oops!! As you have not configured the security for this zone, you are not protected and the malicious code is executed.

So I reason that the 5th zone should be enabled and all the options should be set as set in 'internet zone' for maximum security. Especially to disable the downloading of unsigned activex controls. This setting alone could have saved many people from the .chm exploits before M$ put out a fix.


MSKB on Security Zones
malkor is offline   Reply With Quote


Old Jun 11, 2004, 12:58 AM   #2
DriverHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,122
Rep Power: 0
The_Neon_Cowboy is on a distinguished road
System Specs

Buy the way It's removed and disabled in sevice pack 2
The_Neon_Cowboy is offline   Reply With Quote
Old Jun 11, 2004, 01:45 AM   #3
DriverHeaven Lover
 
Join Date: Apr 2004
Posts: 123
Rep Power: 0
malkor is on a distinguished road

What has been removed and disabled? IE? lol j/k.

Do you mean the registry keys, the ability to set the security for this zone? It already was disabled. Why, I don't know. Why would they remove it entirely? I haven't had the chance to play with SP2. Have they resolved this vulnerabilty, rendering these settings unnecessary?
malkor is offline   Reply With Quote
 

 
Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
vBulletin implementation by Craig '5320' Humphreys

All times are GMT -5. The time now is 08:43 PM. Copyright ©2008 HeavenMedia.net