Channel Insider - Solution Builder
 
 

Locking Down Internet Explorer


Article Rating:starstarstarstarstar / 0

Rate This Article:
Add This Article To:
IE's My Computer zone has been an open door to security threats, but now you can padlock it.

If you've read about Microsoft's Service Pack 2 for Windows XP, you know about the new, improved firewall that is turned on by default. But there's a more important security enhancement in SP2 that will make a bigger dent in the stream of vulnerabilities in Internet Explorer: SP2 locks down the My Computer zone.

The security model for Internet Explorer has been based on security zones. Different Web pages execute in different zones, which have varying levels of privilege. To see this, go to Tools | Internet Options and click on the Security tab. Click on a zone and you can add a site to it if you like or change the security settings.

One of the most important zones is the My Computer security zone, which is actually hidden by default. (To view and modify the settings for this zone, see "How to Enable the My Computer Security Zone in Internet Options".) Web pages on your computer run in the My Computer zone, which is completely trusted. The theory is that pages running on your computer were installed—perhaps as part of an application—and need access to local resources such as files on the system.

The problem is that a large number of cross-zone vulnerabilities, such as the one described at www.securityfocus.com/bid/9628/, have let Web pages on the Internet execute script and other code in the My Computer zone.

Click here to view the complete story on PCmag.com.



Discuss Locking Down Internet Explorer
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Solution Builder Articles          >>> More By Larry Seltzer
 


 
Commentary


Vizard: The Great Certification Circus

Certifications are one of the few tools they think they can rely on to determine which partners should be in their gold or silver programs while the rest of the channel pretty much gets treated as the great unwashed mass.

CHANNEL DEEP DIVES
CareersLinux and Unix
Computer NetworkingPrinters
SecuritySMB Partner
StorageSurveys
Solution BuilderMessaging/Collaboration
Dell ResellersMicrosoft Partners

SIGN UP FOR CHANNEL INSIDER NEWSLETTERS
Reliable, timely information on the business of technology. Sign up now.


 

 
CHANNEL RESOURCE CENTER

CA IT Management Exchange provides information on IT governance, business service management and security management, with an emphasis on educating CIOs and other IT leaders on how to use a portfolio of services to maximize business value Find the latest news, and tools at this comprehensive performance information hub. Visit Now >>
Learn more about digital infrastructure with latest news, information and resources on security (SMTP authentication, spam, phishing), communications (VoIP, mobile commerce, real-time web), and internet services (DNS, RFID, DRM tools).  
Visit Now >>
HP is an innovator when it comes to energy efficient storage solutions. Learn how HP can help cut costs and deliver effective results for your business. Visit the HP Storage Room today to access the latest white papers and features. Visit Now >>