| SANS Top-20 Internet Security Attack Targets: Internet Explorer Attack Targets (3/3) | |||
|
|||
| Internet Explorer Attack Targets |
W1.6 How to Secure Internet Explorer To configure the Security settings for Internet Explorer: * Select Internet Options under the Tools menu. * Select the Security tab and then click Custom Level for the Internet Zone. * Most of the flaws in IE are exploited through Active Scripting or ActiveX Controls. * Under Scripting, select Disable for Allow paste operations via script to prevent content from being exposed from your clipboard. Note: Disabling Active Scripting may cause some web sites not to work properly. ActiveX Controls are not as popular but are potentially more dangerous as they allow greater access to the system. * Select Disable for Download signed and unsigned ActiveX Controls. Also select Disable for Initialize and script ActiveX Controls not marked as safe. * Java applets typically have more capabilities than scripts. Under Microsoft VM, select High safety for Java permissions in order to properly sandbox the Java applet and prevent privileged access to your system. * Under Miscellaneous select Disable for Access to data sources across domains to avoid Cross-site scripting attacks. * Ensure that no un-trusted sites are in the Trusted sites or Local intranet zones as these zones have weaker security settings than the other zones. W1.7 References Internet Explorer Security Updates
US-CERT Securing Web Browser Information |
| Page: 1 2 3 |
| Return to Category | Return To Main Index |
| Identity Theft Protection Services : | |
|
LifeLock Identity Theft Prevention Solution
Veracity Credit Optimization Services Equifax Credit Watch |
Free Credit Report Identity Truth Privacy Matters 123 |














