Technology Questions

Go Back   Technology Questions > Software Questions > Internet > Internet Explorer

Internet Explorer Discuss IE7 or any other IE version.

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 07-09-2009, 09:50 PM
MaryBeth
Newsgroup Contributor
 
Posts: n/a
Microsoft Security Advisory (972890)


Has anyone applied the changes to Internet Explorer 7.0.5730.13IC as advised
in this alert? It appears someone has managed to exploit a vulnerability in
Microsoft Video ActiveX Control. Though the advisory states it is not
necessary for the operation of IE 7 & below, some websites especially game
sites rely on it. The file msvidctl.dll is the target of the attack. The
workaround suggests disabling all DirectX scripting within IE 7 until a patch
is developed. Would it be OK to enable DirectX scripting while in a gamesite
and then disabling it when on the web?
Thanks -- MaryBeth
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 07-09-2009, 09:50 PM
  #2 (permalink)  
Old 07-09-2009, 11:20 PM
Timothy Casey
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft Security Advisory (972890)


"MaryBeth" <MaryBeth@discussions.microsoft.com> wrote in message
news:633D0546-B301-4ADE-8796-308083BF1F51@microsoft.com...
> Has anyone applied the changes to Internet Explorer 7.0.5730.13IC as
> advised
> in this alert? It appears someone has managed to exploit a vulnerability
> in
> Microsoft Video ActiveX Control. Though the advisory states it is not
> necessary for the operation of IE 7 & below, some websites especially game
> sites rely on it. The file msvidctl.dll is the target of the attack. The
> workaround suggests disabling all DirectX scripting within IE 7 until a
> patch
> is developed. Would it be OK to enable DirectX scripting while in a
> gamesite
> and then disabling it when on the web?
> Thanks -- MaryBeth


No. too easy to forget to turn it off after - or before visiting a risky
site.

1. Click the Internet Zone (bottom right of the browser)
2. Click Internet Icon
3. Click Custom Level... button
4. Disable everything not vital to loading an honest document (IE that could
facilitate an infection: eg. scripting, Java, VBScript, ActiveX, .NET, XAML,
binary behaviours, etc.)

Once this lot is set, none of the web pages that rely on hacking into your
computer to make their functionality work will be able to do so - including
the banks, escrows, and your game sites. So the next step is to add those
sites you trust to your trusted sites list:

1. Click the Internet Zone (bottom right of the browser)
2. Click Trusted Icon
3. Add the site you trust
4. You may need to untick the HTTPS box

This ensures that only those sites you trust can access your browser API and
that of the Win32 Host while all others are denied.

Having said this, the person who set up the custom level security options
doesn't know the difference between a program launch and a program
download - so if you want to be able to download any programs (eg shareware,
some value added programs, and certain updates) at all you will need to make
sure that the: "Launching applications and unsafe files" option under
"Miscellaneous" is set to "Prompt". It is vital to your computer's security
that you make sure that this option is not set to "enable" or programs
(including self loading viruses) will be able to install without your
consent.

This is how I kept the cybercriminals out of a Win98 system for more than
ten years.

Good luck

--
Timothy Casey - Email: 5th-prime-number@timothycasey.info
Software: http://software-1011.com; Scientific IQ Test, Web Menus, Security
http://web-design-1011.com http://speed-reading-comprehension.com
Science & Geology: http://geologist-1011.com; http://geologist-1011.net

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 07-10-2009, 12:10 AM
PA Bear [MS MVP]
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft Security Advisory (972890)

Please see http://support.microsoft.com/kb/972890

NB: MS CSS tells me that the FixIt is for Vista and Windows 2008, as well,
and recommends those running those OSS use it, too (despite what
http://www.microsoft.com/technet/sec...ry/972890.mspx may say about
those OSS).

PS: It's a Windows vulnerability which involves IE.

More about this here:
http://blogs.technet.com/msrc/archiv...ry-972890.aspx
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Client - since 2002


MaryBeth wrote:
> Has anyone applied the changes to Internet Explorer 7.0.5730.13IC as
> advised
> in this alert? It appears someone has managed to exploit a vulnerability
> in
> Microsoft Video ActiveX Control. Though the advisory states it is not
> necessary for the operation of IE 7 & below, some websites especially game
> sites rely on it. The file msvidctl.dll is the target of the attack. The
> workaround suggests disabling all DirectX scripting within IE 7 until a
> patch is developed. Would it be OK to enable DirectX scripting while in a
> gamesite and then disabling it when on the web?
> Thanks -- MaryBeth


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 07-10-2009, 06:10 AM
Leonard Grey
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft Security Advisory (972890)


I rely on Microsoft Update to provide whatever updates are needed for my
Microsoft software. I rely on my security software, not to mention my
careful behavior on the internet, to protect me.
---
Leonard Grey
Errare humanum est

MaryBeth wrote:
> Has anyone applied the changes to Internet Explorer 7.0.5730.13IC as advised
> in this alert? It appears someone has managed to exploit a vulnerability in
> Microsoft Video ActiveX Control. Though the advisory states it is not
> necessary for the operation of IE 7 & below, some websites especially game
> sites rely on it. The file msvidctl.dll is the target of the attack. The
> workaround suggests disabling all DirectX scripting within IE 7 until a patch
> is developed. Would it be OK to enable DirectX scripting while in a gamesite
> and then disabling it when on the web?
> Thanks -- MaryBeth

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 07-10-2009, 07:10 AM
MaryBeth
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft Security Advisory (972890)


Thank you everyone for your replies. I did read the technet blog announcing
a patch would be available next Tuesday. 5 days without ActiveX scripting is
a small price to pay for a hacked computer. I will also apply the
adaptations you suggest Timothy, in IE. As always, your gems of wisdom,
experience, & technical knowledge are greatly appreciated, gentlemen.
~MaryBeth
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #6 (permalink)  
Old 07-10-2009, 10:01 AM
PA Bear [MS MVP]
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft Security Advisory (972890)

Did you read KB972890? If you take advantage of that FixIt, it isn't
necessary to disable ActiveX scripting.

MaryBeth wrote:
> Thank you everyone for your replies. I did read the technet blog
> announcing
> a patch would be available next Tuesday. 5 days without ActiveX scripting
> is a small price to pay for a hacked computer. I will also apply the
> adaptations you suggest Timothy, in IE. As always, your gems of wisdom,
> experience, & technical knowledge are greatly appreciated, gentlemen.
> ~MaryBeth


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Security George-NY Windows XP 4 02-14-2009 10:22 PM
Transaction Advisory Services Manager - Working Capital Advisory Services -New York TPC Tablet PC Jobs 0 11-15-2008 01:50 AM
BRS Real Estate Advisory Services--Construction Advisory Staff 2 - 00GL3 TPC Tablet PC Jobs 0 12-20-2007 05:30 AM
BRS Real Estate Advisory Services--Construction Advisory Staff 2 - 00GL3 TPC Tablet PC Jobs 0 11-15-2007 03:20 AM
Microsoft Keeps Secrets on Security Roy.Schavesmewankz@gmail.com Windows Vista 0 03-01-2007 03:45 PM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 08:14 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0