On TechRepublic: Top 5 operating systems you never used

Search:
Go!


See video that entertains and explains the latest in tech

Click Here
advertisement

Security Watch : Don't get burned by viruses and hackers.
New Year, old flaws in Windows, Internet Explorer
By Robert Vamosi 
Senior editor, CNET Reviews
January 14, 2005

If you thought upgrading to Windows XP SP2 would end your Windows security nightmares, think again. Last Tuesday, Microsoft released three new security bulletins for 2005, including one critical patch for Windows XP SP2, last year's much-touted security upgrade of the Windows XP operating system. While Windows XP SP2 recompiled most of the basic system files to better protect you from malicious buffer overflows, the flaw in MS05-001 involves ActiveX, Microsoft's clever answer to Sun's Java technology. The two other vulnerabilities announced as part of the January monthly update release don't affect Windows XP SP2.

Security bulletin number one
Simply put, ActiveX is an omnibus term for interactive Microsoft technologies on the Web. On the plus side, ActiveX allows Microsoft Office apps to communicate across networks and in the Internet. On the downside, ActiveX allows flashy advertising on Web sites. It's the latter that's worrisome, as criminal hackers could use fancy ads on Web sites or referrals to maliciously coded Web sites to download malformed HTML Help ActiveX Controls onto your unprotected PC, then gain control of your machine.

Criminal hackers could use flashy ads on Web sites to download malformed HTML Help ActiveX Controls onto your unprotected PC, then gain control of your machine.
Among the many changes within Microsoft Windows XP SP2 is an enhanced Internet Explorer 6.0 that now displays which ActiveX Controls you're downloading whenever you visit a Web site. Non-Windows XP SP2 users don't have access to the enhanced version of Internet Explorer 6.0; last year, Microsoft announced that it's no longer adding new features to non-Windows XP SP2 Internet Explorer browsers. But even if you have XP 2 IE and can spot a maliciously coded HMTL Help ActiveX Control, what can you realistically do to stop it from infecting your PC?

My favorite anti-pop-up app, PopUpCop, includes XGuard, a nifty feature that blocks ActiveX downloads onto your computer. I like the granularity within PopUpCop because I can allow ActiveX on certain sites and block it on all others.

You can also go into Internet Explorer's tools and change the ActiveX setting from Enable to Prompt. The downside of this change is that on every Web page you visit, you will see a dialog box asking if you want to allow ActiveX Controls before IE downloads them. If you say no to the wrong control, you may also lose some functionality on that Web page. As an alternative, Microsoft, in its detailed summary of the security bulletin, offers other workarounds, including running the HTML Help ActiveX Control within the local security zone within Internet Explorer (for a detailed explanation of what that means, see MS05-001).

Bulletins two and three
The other critical flaw patched by Microsoft last Tuesday also involves Internet Explorer--all versions. Should you surf to a page containing a maliciously formed cursor or icon, you may find yourself controlled by a remote cracker. MS05-002 is rated critical, in part, because there are already working exploits out on the Internet. Once an exploit is available, it is often only a matter of time before someone finds a way to create a virus or a worm from it. Trend Micro has an independent security assessment of this vulnerability.

The other critical flaw patched by Microsoft last Tuesday also involves Internet Explorer.
Finally, the third patched flaw concerns the Windows indexing service, which is by default turned off on Windows XP and Windows Server 2003. Because of that, Microsoft has given MS05-003 its second-highest rating of "important."

Firefox to the rescue?
Mozilla Firefox has been designed to run without ActiveX. But in all fairness, now that people are rushing to install Firefox, more and more flaws have been announced. Still, the flaws discovered in Firefox pale against those that exist in Internet Explorer. For one thing, given that there are exploits for at least one of these new vulnerabilities, we know that criminal hackers are interested in attacking IE. When there's a worm spreading exclusively via Firefox, I'll let you know.

Do you feel safe using Internet Explorer? Why or why not? Talk back to me!


Security Center
Top antivirus apps
From CNET Reviews
Top antispyware apps
From CNET Reviews
Virus and security alert forums
From CNET Message Boards


More commentary
Buzz Report
Molly Wood
Taking a bite out of hype.
Security Watch
Robert Vamosi
Don't get burned by viruses and hackers.
Fully Equipped
David Carnoy
The electronics you lust for.
On Call
Kent German
Solutions for your wireless woes.
Driving It
Wayne Cunningham
What's hot and what's not in car tech.

TalkBack
41 messages

Article discussion: Security Watch: New Year, old flaws in Windows, Internet Explorer


Latest post:

"help me and my stupid browser"
by chloefoy (See profile) - November 16, 2005 3:34 AM PST
i have a mac 9.2. with internet explorer. i
recently changed a setting on the computer as
im no longer dial up connection. some web
pages appear quite strange or cannot... (Read more).
Sort by: Title |
Date
| Most helpful

Firefox for safer browsing

I gave up on Internet Explorer a long time ago. It brings nothing but troubles t... (Read more)
by JLP (See profile) - March 11, 2005 7:50 AM PST

Firefox

I have recently installed firefox and its much better than ie. Its also much bet... (Read more)
by masta_krish (See profile) - February 13, 2005 5:40 AM PST

Mac OS X to the rescue

Of course I don't think Windows is safe. After four years of email
problems,... (Read more)
by bblackley (See profile) - January 23, 2005 1:25 PM PST

IE vs The Others

Correct me if I'm wrong, but IE is an integrated and essentially non-removal par... (Read more)
by MleB (See profile) - January 23, 2005 8:55 AM PST

what does not Kill IE, will only make it stronger

Think of IE as your body, I would rather get the inoculations against the virus ... (Read more)
by iamanerd (See profile) - January 22, 2005 9:36 AM PST

IE:necessary evil at times, otherwise not worth it

I don't use IE unless absolutely necessary - getting updates from Microsoft (I r... (Read more)
by jd7wilson (See profile) - January 22, 2005 8:09 AM PST

Foxy,Missy and Safari

Let us not deviate from the conversation by talking about operating systems. Fo... (Read more)
by majoritywhip (See profile) - January 21, 2005 8:16 AM PST

AV and spyware

sounds like you are new to PC's as well. Your virus protection has nothing to so... (Read more)
by majoritywhip (See profile) - January 21, 2005 8:15 AM PST

Firefox!!! Gotta have it.

I fell in love with Firefox the minute I installed it. I kinda knew that there's... (Read more)
by  (See profile) - January 19, 2005 9:40 PM PST


Copyright ©2008 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use