Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Siddhartha Jain
    Windows Update - Unsafe ActiveX control
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Windows Update - Unsafe ActiveX control

    Hello,

    I just tried to download the latest Microsoft security update by using the
    Windows update utility in Internet Explorer. However, I could not do so
    because I had disabled all ActiveX controls in the security settings (after
    reading a terrifying paper on ActiveX security).

    After this I enabled "Download Signed ActiveX Controls" and "Run ActiveX
    controls and plugins". I ran the Windows update utility again and got this
    message:
    "An ActiveX control on this page is not safe. Your current security settings
    prohibit running unsafe controls on this page. As a result, this page may
    not display as intended."
    URL: http://v4.windowsupdate.microsoft.com/en/default.asp

    After I clicked "Ok", I got the error message that this utility is to run by
    "Administrators Only".

    I am running Microsoft Windows 2000 Server SP4 and IE 6.0.2800.1106 SP1
    Q818529.

    So Microsoft expects me download critical patches using an unsafe ActiveX
    control??

    Regards,

    Siddhartha Jain

    "This email message is intended for the named recipient only. It may be
    privileged and/or confidential. If you are not the intended named recipient
    of this email then you should not copy it or use it for any purpose, nor
    disclose its contents to any other person which is strictly prohibited and unlawful"


  2. #2
    Jackson, Chris
    Windows Update - Unsafe ActiveX control
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: Windows Update - Unsafe ActiveX control

    > "An ActiveX control on this page is not safe. Your current security
    settings
    > prohibit running unsafe controls on this page. As a result, this page may
    > not display as intended."
    > So Microsoft expects me download critical patches using an unsafe ActiveX
    > control??


    Safe for Scripting indicates that a control does not access files, memory,
    or registers directly. The only purpose of the Windows Update control is to
    access (and update) files directly, so it should not be marked as safe for
    scripting.

    --
    Chris Jackson
    Software Engineer
    Microsoft MVP
    --


  3. #3
    Drew Copley
    Windows Update - Unsafe ActiveX control
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: Windows Update - Unsafe ActiveX control

    You should not enable "unsafe activex", in order to get Windows Update
    to work, however.

    http://*.windowsupdate.com , http://download.microsoft.com,
    http://windowsupdate.microsoft.com , https://download.microsoft.com, and
    http://*.windowsupdate.com should all be enabled in trusted sites zone.
    This is by default on Windows 2003.

    Some references which are a good rule of thumb:
    http://msdn.microsoft.com/library/de...p/security/szo
    ne/overview/esc_changes.asp

    Windows 2003 does have a good system in this way for the paranoid. It
    disables activex and activescripting, but it allows for Windows Update
    to properly work. Its' settings are documented in the above url.



    > -----Original Message-----
    > From: Jackson, Chris [mailto:CJackson@bridgecom.com]
    > Sent: Thursday, July 17, 2003 10:35 AM
    > To: 'Siddhartha Jain(IT)'; BUGTRAQ@SECURITYFOCUS. COM
    > Subject: RE: Windows Update - Unsafe ActiveX control
    >
    >
    > > "An ActiveX control on this page is not safe. Your current security

    > settings
    > > prohibit running unsafe controls on this page. As a result,

    > this page
    > > may not display as intended." So Microsoft expects me download
    > > critical patches using an unsafe ActiveX control??

    >
    > Safe for Scripting indicates that a control does not access
    > files, memory, or registers directly. The only purpose of the
    > Windows Update control is to access (and update) files
    > directly, so it should not be marked as safe for scripting.
    >
    > --
    > Chris Jackson
    > Software Engineer
    > Microsoft MVP
    > --
    >
    >



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics