Solution Builder - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Locking Down Internet Explorer

    in Solution Builder



    Article Rating:starstarstarstarstar / 0
    Article Views: 3046

    IE's My Computer zone has been an open door to security threats, but now you can padlock it.

    Rate This Article:
    Add This Article To:

    If you've read about Microsoft's Service Pack 2 for Windows XP, you know about the new, improved firewall that is turned on by default. But there's a more important security enhancement in SP2 that will make a bigger dent in the stream of vulnerabilities in Internet Explorer: SP2 locks down the My Computer zone.

    The security model for Internet Explorer has been based on security zones. Different Web pages execute in different zones, which have varying levels of privilege. To see this, go to Tools | Internet Options and click on the Security tab. Click on a zone and you can add a site to it if you like or change the security settings.

    One of the most important zones is the My Computer security zone, which is actually hidden by default. (To view and modify the settings for this zone, see "How to Enable the My Computer Security Zone in Internet Options".) Web pages on your computer run in the My Computer zone, which is completely trusted. The theory is that pages running on your computer were installed—perhaps as part of an application—and need access to local resources such as files on the system.

    The problem is that a large number of cross-zone vulnerabilities, such as the one described at www.securityfocus.com/bid/9628/, have let Web pages on the Internet execute script and other code in the My Computer zone.

    Click here to view the complete story on PCmag.com.




    comments dic


     
     
    >>> More Solution Builder Articles          >>> More By Larry Seltzer
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement