ActiveX Control Vulnerability

ActiveX Control Vulnerability

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
ActiveX Control Vulnerability bryan 12-26-2007
Posted by =?Utf-8?B?YnJ5YW4=?= on December 26, 2007, 10:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options
My research takes me to a wide variety of web sites. I am running Win XP sp2,
IE 7, Kaspersky Internet Suite, Spywareblaster and Linkscanner. To protect
against the threats inherent in activex controls I disabled the security
setting in IE 7 for ‘runactivex controls and plug-ins’.
While most web pages still load 'adequately', my problem is with video
files. Many (if not most) do not run unless I re-enable the setting. Setting
a register bit (a suggestion by some experts) is too complex. Will switching
to Mozilla (no activex problem) solve my problem? Is there a way to keep IE 7
and avoid the security issues and inconveniences of the activex controls?

Any suggestions would be greatly appreciated.

Thanks,

Bryan


Posted by on December 26, 2007, 11:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello Bryan,

Are the websites that require ActiveX for videos trusted? If so, you
can add them to the Trusted sites (Tools > Internet Options > Security
Tab, highlight Trusted sites, click [Sites].) Set the Trusted Sites to
enable ActiveX for your videos. Disable ActiveX on the Internet. This
is a whitelist approach that I find works very well, particularly if
combined with web surfing as a normal user (e.g., not as
Administrator).

J Wolfgang Goerlich

> My research takes me to a wide variety of web sites. I am running Win XP sp2,
> IE 7, Kaspersky Internet Suite, Spywareblaster and Linkscanner. To protect
> against the threats inherent in activex controls I disabled the security
> setting in IE 7 for 'runactivex controls and plug-ins'.
> While most web pages still load 'adequately', my problem is with video
> files. Many (if not most) do not run unless I re-enable the setting. Setting
> a register bit (a suggestion by some experts) is too complex. Will switching
> to Mozilla (no activex problem) solve my problem? Is there a way to keep IE 7
> and avoid the security issues and inconveniences of the activex controls?
>
> Any suggestions would be greatly appreciated.
>
> Thanks,
>
> Bryan


Posted by =?Utf-8?B?YnJ5YW4=?= on December 26, 2007, 12:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi J Wolfgang,
Thanks for your reply. I have been using my trusted sites as you have
suggested. The problem is that when I browse movie trailers via Windows Media
Player etc, the videos take me to many different sites and it gets cumbersome
adding each site to the trusted list. Also, unless I enable ''run activex
controls and plug-ins", none of the videos on the Yahoo web site run at all.

"jwgoerlich@gmail.com" wrote:

> Hello Bryan,
>
> Are the websites that require ActiveX for videos trusted? If so, you
> can add them to the Trusted sites (Tools > Internet Options > Security
> Tab, highlight Trusted sites, click [Sites].) Set the Trusted Sites to
> enable ActiveX for your videos. Disable ActiveX on the Internet. This
> is a whitelist approach that I find works very well, particularly if
> combined with web surfing as a normal user (e.g., not as
> Administrator).
>
> J Wolfgang Goerlich
>
> > My research takes me to a wide variety of web sites. I am running Win XP sp2,
> > IE 7, Kaspersky Internet Suite, Spywareblaster and Linkscanner. To protect
> > against the threats inherent in activex controls I disabled the security
> > setting in IE 7 for 'runactivex controls and plug-ins'.
> > While most web pages still load 'adequately', my problem is with video
> > files. Many (if not most) do not run unless I re-enable the setting. Setting
> > a register bit (a suggestion by some experts) is too complex. Will switching
> > to Mozilla (no activex problem) solve my problem? Is there a way to keep IE 7
> > and avoid the security issues and inconveniences of the activex controls?
> >
> > Any suggestions would be greatly appreciated.
> >
> > Thanks,
> >
> > Bryan
>
>

Posted by =?Utf-8?B?YnJ5YW4=?= on December 26, 2007, 10:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
As it turned out, the videos on the Yahoo web site all seem to use the same
url so I added it to my trusted sites. Most important of all, I can do my
research work by browsing sites with 'run activex controls and plug-ins'
disabled and the web pages load reasonably well. I will continue to operate
this way. Thanks again for your assistance.

Regards,

Bryan

"bryan" wrote:

> Hi J Wolfgang,
> Thanks for your reply. I have been using my trusted sites as you have
> suggested. The problem is that when I browse movie trailers via Windows Media
> Player etc, the videos take me to many different sites and it gets cumbersome
> adding each site to the trusted list. Also, unless I enable ''run activex
> controls and plug-ins", none of the videos on the Yahoo web site run at all.
>
> "jwgoerlich@gmail.com" wrote:
>
> > Hello Bryan,
> >
> > Are the websites that require ActiveX for videos trusted? If so, you
> > can add them to the Trusted sites (Tools > Internet Options > Security
> > Tab, highlight Trusted sites, click [Sites].) Set the Trusted Sites to
> > enable ActiveX for your videos. Disable ActiveX on the Internet. This
> > is a whitelist approach that I find works very well, particularly if
> > combined with web surfing as a normal user (e.g., not as
> > Administrator).
> >
> > J Wolfgang Goerlich
> >
> > > My research takes me to a wide variety of web sites. I am running Win XP
sp2,
> > > IE 7, Kaspersky Internet Suite, Spywareblaster and Linkscanner. To protect
> > > against the threats inherent in activex controls I disabled the security
> > > setting in IE 7 for 'runactivex controls and plug-ins'.
> > > While most web pages still load 'adequately', my problem is with video
> > > files. Many (if not most) do not run unless I re-enable the setting.
Setting
> > > a register bit (a suggestion by some experts) is too complex. Will
switching
> > > to Mozilla (no activex problem) solve my problem? Is there a way to keep
IE 7
> > > and avoid the security issues and inconveniences of the activex controls?
> > >
> > > Any suggestions would be greatly appreciated.
> > >
> > > Thanks,
> > >
> > > Bryan
> >
> >

Posted by =?Utf-8?B?QW50ZWF1cw==?= on December 31, 2007, 3:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I would get Firefox, Seamonkey, or Opera. With these the Activex problem is
largely academic. With the exception that WMP itself may have exploits, of
course.



Similar ThreadsPosted
ActiveX Control To Read Certificate (ASP.Net app) November 3, 2005, 4:40 am
ActiveX control security mechanisms in IE 6.0 vs IE 7.0 September 15, 2006, 7:21 pm
ActiveX Control To Read Certificate (ASP.Net app) February 17, 2007, 5:02 pm
IE 6 won't accept signed ActiveX control April 16, 2008, 5:06 pm
Microsoft Internet Explorer ActiveX Vulnerability September 27, 2006, 10:11 pm
Unlock activeX February 15, 2006, 6:53 am
ActiveX Security March 22, 2006, 3:35 pm
ActiveX needs to be enabled April 28, 2006, 8:23 am
ActiveX Problems June 11, 2006, 8:39 am
activex controls prohibited September 27, 2005, 6:36 pm

The site map in XML format XML site map

Contact Us | Privacy Policy