Re: MS Outlook alert : Cuartango Active Setup - Workaround

From: Mark (markat_private)
Date: Mon Nov 08 1999 - 13:37:28 PST

  • Next message: Microsoft Product Security Response Team: "Microsoft Security Bulletin MS99-047,"

    I believe the instructions below provided for Outlook 98 would be similar
    for Outlook 2000 clients, however I do not have immediate access to that
    client for inspection at this moment in time.
    
    Thanks,
    Mark, markat_private
    http://www.ntsecurity.net
    
    ==================================
    Adjusting Outlook 98 Adjustments -
    
    To guard against the risks presented in Juan's notice, be sure to adjust
    control of ActiveX Scripting as well as ActiveX Controls and Plugins in your
    Outlook mail client.
    
    For Outlook 98, choose Tools, Options, and then Security from the pull down
    menus. On the security tab, adjust the Secure Content Zone to Restricted
    Sites. This causes Outlook to employ the Restricted Sites security profile
    to all email content received with Outlook.
    
    Also, ensure that the Restricted Sites zone settings are adequate for your
    needs. To do so, on the same Outlook Security dialog, click the Zone
    Settings button, which opens a new dialog. On the new dialog, choose the
    Restricted Sites zone, and click the Custom Level button, which opens the
    Security Settings dialog window. On the dialog window, scroll through the
    list and adjust all ActiveX properties to either "Disable" or "Prompt." Keep
    in mind that if you set these controls to "Prompt," you may experience a
    large number of prompts on the screen while surfing the Internet. If the
    prompts become a bother, simply readjust the ActiveX properties to
    "Disable."
    ====================================
    
    
    > There is a workaround :
    > Change the temporary directories location defined in the
    > environment variables %TEMP% and %TMP%. Make this variables to
    > point over an unpredictable path. Another workaround would be the
    > traditional one : disable active scripting.
    > MS was informed about the issue last 12 October . They are
    > supposed to inmediately release a fix.
    > Regards,
    > Juan Carlos García Cuartango
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:10:09 PDT