PDA

View Full Version : MS03-040 and blocking ActiveX


meneer
October 17th, 2003, 02:17 AM
Patch MS03-040 presumably closes a big ActiveX hole.
So far we are blocking ActiveX for internetsites. In his latest Brians Buzz (http://BriansBuzz.com/w/031016/) column, Brian Livingstone states that due to this patch, it no longer is necessary to disable ActiveX.
Is this a sound advise?

sig
October 23rd, 2003, 10:02 PM
I think that advice only applies for people who had blocked ActiveX specifically to avoid that particular exploit for which the patch has now been released.

Nevertheless, this MS patch doesn't address or protect (as far as I'm aware) against drive by downloads of spyware and other potentially unwanted or unfriendly stuff which can be an issue as long as ActiveX is enabled on all sites, trusted and unknown.

Apps such as SpywareBlaster help to guard against some of these but in general I wouldn't say, OK now you can enable ActiveX because MS released a patch. The patch does nothing for the other reasons one is advised not to let ActiveX run on the internet without restriction.

meneer
October 24th, 2003, 04:15 PM
Okay, thanks. I suppose I better keep my current policy.