Wednesday, April 04, 2007

Protected Mode for IE7 in Windows Vista

If you read the MSRC Blog post update about the Animated Cursor vulnerability, then you would have also read the following:
"If you are using Windows Vista, the Internet Explorer 7 protected mode provides additional protections against web-based attacks."
In a very timely manner, Sharath Udupa, a developer on the IE team, explained how to tell if the Protected Mode feature is turned on or off for Internet Explorer in Windows Vista. (Note that the Protected Mode feature is available only in Windows Vista.) By default, Protected Mode is enabled for Internet, Intranet and Restricted zones while disabled for the Trusted Sites and Local Machine zone.

Sharath explains that at times the text in the status bar may indicated “Protected Mode: Off” even when the Internet Options dialog indicates that Protected Mode is enabled. Following are a few exceptions that could potentially turn off Protected Mode:
  • User Account Control (UAC) is disabled – If UAC is disabled, Protected Mode is turned OFF. When UAC is disabled, some of the protections which Protected Mode depends on are not available, for example, UI Privilege Isolation (UIPI) is disabled. Hence, Protected Mode is turned off in this scenario.

  • IE is running with Administrator privileges – Protected Mode is turned off when IE is launched by right clicking on the IE icon and selecting “Run as administrator” or when IE is launched with administrative privileges from another application. This generally occurs when an installer/setup program running with administrator privileges starts a new IE process.

  • IE is navigated to a local HTML page – When the page being viewed is a local file, Protected Mode is turned OFF since the contents of the page are considered safe. Caveat: If the page was saved from a zone (for example Internet) which has Protected Mode enabled, then Protected Mode is turned ON.

See the illustration and follow the comments in Protected Mode for IE7 in Windows Vista - Is it On or Off?

Should you need to reference this information again, I've added the link to the Internet Explorer 7 page in Windows Vista Bookmarks.


Tuesday, April 03, 2007

MS07-017 For Animated Cursor Handling Released

MS07-017 is a Critical Update and everyone is strongly urged to obtain this update as soon as possible. This update is for all supported Microsoft operating systems, including Windows Vista. If you do not have automatic updates turned on, please visit the Microsoft Update site now. The update is small, only 455 KB - 1.7 MB and requires a restart, but well worth it to protect your computer from infection!

Please note this important information provided in the MSRC Blog, referenced below. I have taken liberties with the format to call important information to your attention:
"We noted in our original advisory that attacks against this vulnerability affect all supported versions of Windows and Windows Server, including Windows Vista, and have been web-based and e-mail based.
  • If you are using Windows Vista, the Internet Explorer 7 protected mode provides additional protections against web-based attacks.

  • If you’re using Outlook 2007, you’re protected against e-mail based attacks.

  • Running as a standard user further protects you by limiting the attacker’s code with the same limitation on the logged-on user.
We call these out in the Mitigating Factors section of the security bulletin MS07-017."

Of further interest is that there is currently a regular update scheduled for next Tuesday, April 10, 2007. The details of that update will be released on schedule on Thursday, April 5, 2007.

Important Note: There is an issue on a computer that is running Microsoft Windows XP with Service Pack 2, in that the Realtek HD Audio Control Panel may not start. The following error message may also be received:

Rthdcpl.exe - Illegal System DLL Relocation

The system DLL user32.dll was relocated in memory. The application will not run properly. The relocation occurred because the DLL C:\Windows\System32\Hhctrl.ocx occupied an address range reserved for Windows system DLLs. The vendor supplying the DLL should be contacted for a new DLL.

See Microsoft Knowledge Base Article KB 935448 for further information regarding a hotfix for this issue.


References:



Monday, April 02, 2007

Ethics and antispyware

Have you ever wondered how certain antispyware companies get such high ratings when their removal rate is not on par with what would be expected? Why do their "trials" only detect but not remove unless you shell out the big bucks for a license key?

Alex Eckelberry explains the "scan and scare" tactics used by these companies in simple terms -- the payback to the companies is significantly greater. CounterSpy V2 does not work that way. A trial version of their product is fully functional. Not only that, the cost of a license is about one-third less than most of the companies using the "scan and scare" technique.

After you read what Alex wrote about Ethics and antispyare, consider something else. Sunbelt has some of the best known people in the security community working for or consulting with them, including a number of Microsoft MVP's.

If you or someone you know needs security software for their computer, I strongly suggest considering Sunbelt's Counterspy and WinPatrol by Bill Pytlovany. I consider Alex Eckelberry and Bill Pytlovany two of the most honest, ethical people in the security industry.