Files missing at startup

  • Thread starter Thread starter Jack Bruss
  • Start date Start date
David H. Lipman said:
Art's comments on IE are correct and apropos! Incorrect.


Even the US CERT has indicated NOT using IE due to all the
vulnerabilities that IE brings to
the table.
The key word being "has", which is past tense. Keep
reading.
 
Frederic Bonroy said:
Do you have a link? The only recent security problem that I am aware of
is the one that led to the release of version 1.7.1, and that hole was
plugged within a few days.


No. IE has always been a sick puppy. Since Mozilla-based browsers don't
support ActiveX and the like, their users won't run into problems
related to that "technology". That's a good start, no? ;-)
Look at how common hijacking issues have become in recent months, and
they always concern - surprise - IE.

No, IE has been defraulted to its most functional states.
The fact that you CANNOT do things with those other browsers
makes them undesirable IMO, and if I want THAT kind of
capability, it's readily available in IE. Why would I want
to use something crippled like that? I'll bet that at the
same time you deride IE, you also still go out ande buy the
latest OS, PC, and peripherals just because they exist: As
in, progress for the sake of progress? That kind of
attitude is actually a wart on the ass of progress to put it
succinctly.
Shortly, you are going to notice that the tide is turning
to other browsers too as the bad boys & kiddies become more
and more proficient and looking to make names for
themselves. Can you imagine the paper headlines and the
pride that kiddie will feel? It'sstarting: Stand by.
 
"Beauregard T. Shagnasty" <[email protected]>
wrote in message
Quoth the raven Frederic Bonroy:


Plugged within about 12 hours.

In the address bar, enter: about:config
In the ensuing "filter" bar, enter: shell
If nothing shows, right-click in window, choose New > boolean
and add:
Preference Name:
network.protocol-handler.external.shell
Value:
false

That is all the patch does.

LOL! Really! You couldn't do that with a setting
somewhere?
 
....
I haven't looked in a week or two. What "bugs" related to serious
security problems do you have in mind?

You're offering bad advice here when you suggest to naive users to
continue using IE with activex enabled. ...
...
Now, that I can agree with; ActiveX should not be enabled by
default, but at the same time, it should be obvious what it
is for, and how to turn it "on" or "off", which it isn't. I
wonder why IE doesn't have "Profiles" so you can easily
switch from "all on" to "mimic the cripples"; that would be
handy. I imagine it's all marketing decisions, not really
MS's forte.

Pop
 
I can't reconcile that comment with the next one:


How could a recommendation to not use IE be self serving.
condescending, egocentric and uncalled for when that's exactly what I
do at my web site that you say you liked? You don't make any sense at
all.


Art
http://www.epix.net/~artnpeg

If you mean what you said here, I feel sorry for you; you
can't read. I don't really care whether you can "reconcile"
it or not - you've now made our "no-visit" lists due to your
closed mindedness. You'll never miss us, we're small, but
you'll also never see any of us there. When we surpass
1,000 hits/day consistantly, I'll come back and give you the
URL.
Cheers,
Pop
 
Quoth the raven Pop Rivet:
LOL! Really! You couldn't do that with a setting somewhere?

This IS a setting.

It's a new pref. You could type the few words, or you could download
the 11MB version. Your choice.
 
If you mean what you said here, I feel sorry for you; you
can't read. I don't really care whether you can "reconcile"
it or not - you've now made our "no-visit" lists due to your
closed mindedness. You'll never miss us, we're small, but
you'll also never see any of us there. When we surpass
1,000 hits/day consistantly, I'll come back and give you the
URL.

Please do. I always enjoy a good laugh :)


Art
http://www.epix.net/~artnpeg
 
On that special day, Pop Rivet, ([email protected]) said...
No, IE has been defraulted to its most functional states.

What's that? A freudian slip towards frauded setups?
The fact that you CANNOT do things with those other browsers
makes them undesirable IMO,

Not for me. I don't need no stinking ActiveX, Jscript or RealPlayer. Or
Flash.
and if I want THAT kind of
capability, it's readily available in IE.

What if I don't want that virus/trojan capa/compatibility?
Why would I want
to use something crippled like that?

I just do it. I didn't get Korgos or hijacked startpage sites.
I'll bet that at the
same time you deride IE, you also still go out ande buy the
latest OS, PC, and peripherals just because they exist: As
in, progress for the sake of progress?

I am currently writing on a PII 400 MHz with Windows 98 First Edition,
and it works just fine, with an exchanged hard drive, an additional one,
a cdrom exchanged for a dvd drive, an additional cd burner, a slightly
larger video card, an additional Realtek, and a *very* reliable intel BX
chipset. Why should I ask for more, if I don't play with realtime
shooters or driver simulations?

Yes, it is a bit slow for recent RPGs, and I will replace it within the
next months.

When XP is available with Service Pack2. Not sooner. When XP came out,
Bill Gates claimed that it was the most secure Windows ever made. Until
Blaster came and leveled his card house. And it didn't get any better
afterwards.
That kind of
attitude is actually a wart on the ass of progress to put it
succinctly.

If you are in favour of progress generally, are you also in favour of
better nuclear weapons? Genetically enhanced babies? Cloned politicians?
A RFID'd life from birth to bier? Or is there a moment which makes you
stop and say: I don't think that *this* "progress" will make my life
really better, after all?
Shortly, you are going to notice that the tide is turning
to other browsers too as the bad boys & kiddies become more
and more proficient and looking to make names for
themselves. Can you imagine the paper headlines and the
pride that kiddie will feel? It'sstarting: Stand by.

a. It is way more difficult to get local authority on the machine, if
ActiveX cannot be exploited.

b. The alternative browsers aren't too interesting, because they are
used by few people, and these people are a bit more safety aware than
the average John Doe user.

c. Trying to spread malware by *these* means would result in a *very*
low impact, and low impact obstructs the aimed at goal: to achieve
public attention because the programmer's "baby" managed to harm
$bigcompany.

d. recent programmers aren't only kiddies that want to raise attention;
more and more of them sell their "services" (mostly installed relays and
trojans) to spammers and other internet abusers, for the *money*. A low
distribution of $malware doesn't yield high profits, so why should they
try to infect machines that browse with non-IE applications? The
default, uninformed IE user is a much easier target, and there are
zillions out there to be exploited.

Randex was created to sell the victims to a spammer. The creator
confessed that to a German student in a chat.

Where there is interest, there will be business. I don't want to get
caught in that kind of "business". There are by sure areas in your home
town, where you won't walk at night, if don't really have to. I see IE
as such a red light area.


Gabriele Neukam

(e-mail address removed)
 
On Wed, 28 Jul 2004 15:49:31 GMT, (e-mail address removed) wrote:

[Snip]
Sure I looked at it. It concerned the use of a activex blocker.

Apparently you didn't actually read it... If had you know that it
describes how to stop ActiveX controls from running in Internet
Explorer. Something you can by modifying the data value of the
Compatibility Flags DWORD value for the Class identifier (CLSID) of
the ActiveX control.

You don't need any third party software... Just download the .reg file
and import it.

[Snip]
That's a matter to debate on the list. Since Cert recommends not using
IE, and since many security experts have long advised against using
it, I thing that's a _very_ debateable issue.

Did you actually read the US-CERT vulnerability note or are you just
repeating what's been reported by the media?

US-CERT recommend several risk mitigation steps

1) Disable Active Scripting & ActiveX
2) Apply the Outlook E-mail Security Update
3) Read and send e-mail in plain text
4) Maintain updated anti-virus software
5) Don't follow unsolicited links
6) Use a different browser

It's also worth note the Windows XP service pack 2 makes change to the
Local Machine Zone that should fix specific conditions US-CERTs
vulnerability note deals with.

You find the full vulnerability note @
<http://www.kb.cert.org/vuls/id/713878>


Cheers-

Jeff Setaro
jasetaro@SPAM_ME_NOT_mags.net
http://people.mags.net/jasetaro/
PGP Key IDs DH/DSS: 0x5D41429D RSA: 0x599D2A99 New RSA: 0xA19EBD34
 
Pop said:
No, IE has been defraulted to its most functional states.
The fact that you CANNOT do things with those other browsers
makes them undesirable IMO,

For you. Not for the security-conscious person that I am. I don't need
ActiveX. I have never needed it. The same goes for VBScript. We had
JavaScript already. What did we need VBScript for?
and if I want THAT kind of
capability, it's readily available in IE. Why would I want
to use something crippled like that? I'll bet that at the
same time you deride IE, you also still go out ande buy the
latest OS, PC, and peripherals just because they exist: As
in, progress for the sake of progress? That kind of
attitude is actually a wart on the ass of progress to put it
succinctly.

No. XP has been out for almost three years and I have been using 2000
since January only; I used 98 SE before that. And I would still be using
98 if I hadn't been able to acquire 2000 for free (legally). And I had
to get rid of my Pentium III 500 to do someone a favor (sounds weird,
but you will just have to believe me). That's why I have a fast Athlon
now. I probably wouldn't have bought it otherwise.
I have absolutely no intention to switch to XP because I consider it to
be the worst piece of miserable shit that has ever seen the light of the
day (after IE). Perhaps I will have to switch one day, when 2000 becomes
too obsolete. But I dread that day.
Shortly, you are going to notice that the tide is turning
to other browsers too as the bad boys & kiddies become more
and more proficient and looking to make names for
themselves. Can you imagine the paper headlines and the
pride that kiddie will feel? It'sstarting: Stand by.

Assuming that Mozilla based browsers will become more popular in the
future, they will obviously be targetted more frequently by the bad
boys. That doesn't change the fact that IE is *inherently* less secure
than alternative browsers and that we will very probably see fewer
problems with them.
 
No, IE has been defraulted to its most functional states.
The fact that you CANNOT do things with those other browsers
makes them undesirable IMO, and if I want THAT kind of
capability, it's readily available in IE. Why would I want
to use something crippled like that? I'll bet that at the
same time you deride IE, you also still go out ande buy the
latest OS, PC, and peripherals just because they exist: As
in, progress for the sake of progress? That kind of
attitude is actually a wart on the ass of progress to put it
succinctly.

You don't have a clue. There's nothing new about the alternate
browsers at all. I was using Netscape (which is based on earlier
builds of Mozilla) back in the Win 3.1 days. Opera isn't new. My OS
isn't new. And I know Frederic's isn't either. I ran Win 98 with IE
eradicated for years and never missed that piece of junk once. What
good is a browser that you have to keep scripting and activex disabled
because of endless unpatched vulnerabilities? And who wants to play
the silly IE patchwork roulette game? With Mozilla, the rare
vulnerabilities have been found and fixed before the bad guys get a
chance to exploit them. Yes, it is a good idea to use the latest
released version. But that's about it.
Shortly, you are going to notice that the tide is turning
to other browsers too as the bad boys & kiddies become more
and more proficient and looking to make names for
themselves. Can you imagine the paper headlines and the
pride that kiddie will feel? It'sstarting: Stand by.

That's a tired old argument that doesn't hold water for many reasons.
The fact is that most users are far better off using a alternate
browser that's reasonably secure right out of the box.


Art
http://www.epix.net/~artnpeg
 
Jeffrey said:
Art; There more to this than security problems... Take look at the
number reports about web sites that don't render properly with
Mozilla.

Whose fault is that? Is Mozilla buggy, or are the pages just badly written?
True but if you bothered to read the link posted and the associated MS
knowledge base article you see the are way dealing with "bad" activeX
controls that don't involve trading in one set of problem for another
different set. Personally, I'm about ready to toss Mozilla out on it
is back side and stick with Opera!

Well, that's interesting. As far as I am concerned, Opera is lying on my
hard disk just as a back-up in case Mozilla won't work for some reason.
I found it way too annoying and unstable in day-to-day use.
By the way, Opera releases security updates quite often - more often
than Mozilla.
 
Whose fault is that? Is Mozilla buggy, or are the pages just badly written?

Both... Some of the problems come from the way Mozilla's developers
have chosen to implement certain "standards".

As an aside when I look at the logs for the web site I manage and see
95 to 99 percent of the hits come from IE there's very little
incentive from me to support other browsers.
Well, that's interesting. As far as I am concerned, Opera is lying on my
hard disk just as a back-up in case Mozilla won't work for some reason.
I found it way too annoying and unstable in day-to-day use.
By the way, Opera releases security updates quite often - more often
than Mozilla.

Don't get me wrong they both have problems... Opera so has done a
better job of rendering pages that Mozilla chokes on. Unfortunately I
have a couple of sites I use fairly regularly that just won't render
properly in anything other than IE.


Cheers-

Jeff Setaro
jasetaro@SPAM_ME_NOT_mags.net
http://people.mags.net/jasetaro/
PGP Key IDs DH/DSS: 0x5D41429D RSA: 0x599D2A99 New RSA: 0xA19EBD34
 
Jeffrey said:
As an aside when I look at the logs for the web site I manage and see
95 to 99 percent of the hits come from IE there's very little
incentive from me to support other browsers.

It's a vicious circle. If you don't want to support other browsers,
people won't use them. And if they don't use them, you won't want to
support them. The way out of this dilemma is standards compliant HTML.
If a browser won't work with compliant HTML then you and your visitors
have a good reason to shun it.
 
Jeffrey A. Setaro wrote:

@#$%^&* Have you looked at the bug reports for Mozilla and FireFox
recently?

Do you have a link? The only recent security problem that I am aware of
is the one that led to the release of version 1.7.1, and that hole was
plugged within a few days.

[Snip]

<http://www.securityfocus.com/bid/vendor/> Search on vendor "Mozilla"

Boredom set in quickly as I went down through and found that the most
recent vulnerabilites listed are ancient history ... version 1.0 when
Moz is up to 1.71. Be nice to be pointed to something applicable such
as a old security issue that hasn't been fixed along the way.

[Snip]

And how many users have upgraded to more recent releases? The same
people who are have problems IE being hijacked are the same people who
would be running exploitable versions Mozilla... They the people who
don't bother installing patches and regularly do stupid stuff like
cruising around the seedy underbelly of the net looking for free porn,
or blindly double-click anything you put in front of them.

The biggest security problem we face isn't crappy software it's
clueless users... Send a day manning the help desk any decent sized
enterprise you'll be amazed at the spectacularly stupid things users
can do!


Cheers-

Jeff Setaro
jasetaro@SPAM_ME_NOT_mags.net
http://people.mags.net/jasetaro/
PGP Key IDs DH/DSS: 0x5D41429D RSA: 0x599D2A99 New RSA: 0xA19EBD34
 
On Wed, 28 Jul 2004 21:24:10 +0200, Frederic Bonroy

[Snip]
The way out of this dilemma is standards compliant HTML.
If a browser won't work with compliant HTML then you and your visitors
have a good reason to shun it.

Who's standards the World Wide Web consortium's, Microsoft's,
Mozilla's? Part of the problem that browser developers have
implemented the standards slightly differently ways or have
implemented their own version of the standard or chosen to add
extensions to the standard that only work in their browser.

Creating a modern web site with all the bells and whistles that
renders properly in all browsers isn't a simple task and in some case
the client doesn't want to pay for the other one percent.


Cheers-

Jeff Setaro
jasetaro@SPAM_ME_NOT_mags.net
http://people.mags.net/jasetaro/
PGP Key IDs DH/DSS: 0x5D41429D RSA: 0x599D2A99 New RSA: 0xA19EBD34
 
There are by sure areas in your home
town, where you won't walk at night, if don't really have to. I see IE
as such a red light area.

If IE were to re-bulb itself with red ones, the casual user might be a
bit warned, but it's instead all lit up like a car dealership, with
pennants fluttering, suggesting the epitome of transportation
excellence, yet none of the airbags are functional, nor do any of the
cars even have bumpers. <g>
 
Back
Top