02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DID: 4046925<br />

UNCLASSIFIEDh'f"6R 6f"f"leIAL US! 6NLY<br />

More recently, malicious users have found devilishly clever ways to use ActiveX,<br />

Java, and JavaScript to hijack browsers, or to be more precise, to hijack Internet<br />

Explorer. The least innocuous form of browser hijacking involves changing <strong>the</strong><br />

browser's home page and favorites, but most browser hijackers do a lot more, from<br />

creating endless pop-up windows to taking complete control of your browser.<br />

Browser hijacking software also usually includes some form of spyware to monitor<br />

and report your Internet activity. Worse, <strong>the</strong>y are notoriously difficult to remove.<br />

ActiveX has been implicated in <strong>the</strong> surreptitious installation of software known as<br />

drive-by downloads. Drive-by downloads180 occur when a user simply visits a<br />

<strong>web</strong>site or views an HTML email. These sites exploit a vulnerability in Internet<br />

Explorer's ActiveX to download, install, and run software on an unsuspecting user's<br />

computer without his knowledge or consent. This type of software can also be very<br />

difficult to remove.<br />

Keep in mind that, by default active scripting is enabled by default in Internet<br />

Explorer! The problem with simply disabling <strong>the</strong>se controls is that you will encounter<br />

difficulties viewing some <strong>web</strong>pages. Experiment with turning <strong>the</strong>m off or, in <strong>the</strong> case<br />

of MSIE, having your browser "Prompt" you and see what happens.<br />

Here are recommendations for increased security settings in IE's Internet Zone<br />

(remember, you can put sites where you need to use <strong>the</strong>se controls into your<br />

Trusted Sites Zone):<br />

Tools I Internet Options I Security I Internet Zone I Custom Level<br />

• ActiveX Controls and plugins<br />

o<br />

o<br />

o<br />

o<br />

o<br />

Download signed ActiveX controls [Prompt or Disable]<br />

Download unsigned ActiveX controls [Disable]<br />

Initialize and script ActiveX controls not marked as safe [Disable]<br />

Run ActiveX controls and plug-ins [Disable]<br />

Script ActiveX controls marked safe for scripting [Prompt or Disable]<br />

180 "A drive-by download is a program that is automatically downloaded to your computer, often<br />

without your consent or even your knowledge. Unlike a pop-up download, which asks for assent<br />

(albeit in a calculated manner likely to lead to a "yes"), a drive-by download is carried out invisibly to<br />

<strong>the</strong> user: it can be initiated by simply visiting a Web site or viewing an HTML e-mail message.<br />

Frequently, a drive-by download is installed along with ano<strong>the</strong>r application. For example, a file<br />

sharing program might include downloads for a spyware program that tracks and reports user<br />

information for targeted marketing purposes, and an adware program that generates pop-up<br />

advertisements using that information. If your computer's security settings are lax, it may be possible<br />

for drive-by downloads to occur without any action on your part." "Drive-by Download,"<br />

SearchSMB.com, (14<br />

November 2006).<br />

530 UNCLASSIFIEDHFOR OFFlGIAb l:JS~ g~JbY

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!