More musings on the enhanced IE security in Win2K3

Posted Sunday, March 30, 2003 4:05 PM by G Andrew Duthie

One other cool thing included in the management recommendations for the Internet Explorer Enhanced Security Configuration (res://shdoclc.dll/IESechelp.htm#manage, on a Win2K3 machine), is a set of recommendations for browser security for servers. If all server admins followed these, that would certainly be an improvement. Unfortunately, many folks probably won't ever look at the docs for the Enhanced Security Configuration, which is why I'm reproducing these tips here:

Browser Security — Best Practices

Using servers for Internet browsing does not adhere to sound security practices because Internet browsing increases the exposure of your server to potential security attacks. Regardless of the browser you use, you should restrict browsing on your server.

To reduce the risk to your server of potential attacks from malicious Web-based content:

  • Do not use servers for browsing general Web content.
    Use client computers to download drivers, service packs, and so on.
  • Do not view sites that you cannot confirm are secure.
  • Use a limited user account instead of an administrator account for general Web browsing.
  • Use Group Policy to keep unauthorized users from making inappropriate changes to browser security settings.

Good advice. Now let's hope people follow it.


Quiz time! How many of you are running as Administrator (or an account with administrative rights) right now?

I'll start by fessing up that I am (at least on my day-to-day machine), which I should not be. There are two big problems with this practice.

The first problem, which affects mainly the person running as admin (as well as potentially any machine on their network) is that if malicious code gets executed while you're running as admin, you're basically owned by that code, it can do whatever it wants.

The second problem, for those of us who are developing code to be used by others, is that the habit of running as admin often means that code that we develop breaks when the user of that code isn't running as admin. This of course means that the user of the code may resort to running as admin just to get your code to work. Thus you've extended your bad habit to someone else. I can say at least that all of the code examples that I write for my books are now written and tested 100% under a non-admin account, so that my readers will never have to run as admin just to get the samples to work.

I'm working on weaning myself from running as admin, and I certainly hope if you're not already, that you will all work on this too.

So how about it? How many of you are running as admin? Let's see a (virtual) show of hands...

Comments

# re: More musings on the enhanced IE security in Win2K3

Sunday, March 30, 2003 1:37 PM by Anil John

I've not been running as Admin when developing and in daily life, since Nov/Dec of last year. Sometimes it is tough, but it works.

I wrote about this some time back as well @

http://www.learnmobile.net/weblog/secureCoding/RunningasLocalAdmin-JustS.html

and pointed to a couple of links that deal with configuration of VS.NET etc. when running as non-Admin.

# Guilt - A powerful motivator... : A Blog for Graymad

Sunday, March 30, 2003 4:05 PM by TrackBack

Guilt - A powerful motivator... : A Blog for Graymad

# Running as Admin : A Blog for Graymad

Sunday, March 30, 2003 4:05 PM by TrackBack

Running as Admin : A Blog for Graymad

# Update on running as Admin... : A Blog for Graymad

Sunday, March 30, 2003 4:05 PM by TrackBack

Update on running as Admin... : A Blog for Graymad

# A Blog for Graymad

Sunday, March 30, 2003 4:05 PM by TrackBack

A Blog for Graymad

# re: More musings on the enhanced IE security in Win2K3

Sunday, March 30, 2003 6:40 PM by Ian L

i always run an admin user, mainly just because i'm lazy, and relying on having a virus scanner and an ounce or two of common sense.

# re: More musings on the enhanced IE security in Win2K3

Monday, March 31, 2003 4:15 AM by Scott Sargent

I used to run as a less priviledged user in the past. I found it was great for the code writing aspects of development and that most of the life cycle worked well w/o admin rights. Now though my acct does have admin rights, mainly because my client is doing a lot of stuff with COM+ that requires me to use the admin tool, check the event log etc.. Those things can't be done w/o admin. I also had problems debugging through VS.NET when a non-admin.

# re: More musings on the enhanced IE security in Win2K3

Monday, March 31, 2003 7:29 AM by Xander Sherry

I'm running as admin. The little annoyances that I run into, when using a less privledged account just aren't worth it to me.

I'm careful when I develop, and I use non-admin accounts when I'm testing to catch any problems, and that works well for me. I haven't had to do enough re-work to make running day-to-day as a non-admin worth it.

# re: More musings on the enhanced IE security in Win2K3

Monday, March 31, 2003 11:36 AM by Ambrose

I tried not running as an admin on my last install, but I quickly found it to be far too annoying, particularly on programs that install for 'this user only' w/o asking, so when I'd Run As, they'd only be set up for the Administrator and not me. Maybe now that everything's set up, I'll try the ol' non-admin thing again to see how it goes...

# re: More musings on the enhanced IE security in Win2K3

Tuesday, June 03, 2003 10:51 AM by Michael J. Carter

After reading several articles about the dangers of running as admin, I too have been using a non-admin account for my day to day work.

I've created a set of shell scripts that create a command shell for admin access. I've also created a new toolbar and added all my admin tools to it. When I need to do something as an admin, I simply drag the icon to the admin shell, then press enter. Voila, instant admin access.

I can develop and debug just fine as a non-admin. For some programs that insist on writing to restricted registry keys or file locations, I simply give my account the proper permissions. RegMon and FileMon from sysinternals.com are great tools for tracking these things down.

Also, even for general browsing, I've set my default Internet zone to High, and Trusted zone to Medium. I have the IE PowerToys Add To Trusted Zone add-in, so I can allow scripting etc. on a site by site basis.

Sure, it can be a pain sometime, but I think the peace of mind I have far outweighs any inconvenience I may have.

Michael

# Terminal Server in Application mode - why can't SBS 2003 do it?

Monday, May 31, 2004 1:49 PM by TrackBack

# Terminal Server in Application mode - why can't SBS 2003 do it?

Monday, November 22, 2004 12:23 AM by TrackBack

# Registry Cleaner

Thursday, May 01, 2008 3:14 PM by Registry Cleaner

In C, allocate even uninitialized global variables in the data section of the object file, rather than generating them as common blocks. This has the effect that if the same variable is declared (without extern) in two different compilations, you will get

# dvd decrypt

Wednesday, June 25, 2008 8:24 AM by dvd decrypt

WN: No, because the ones they really like every night, I like, too, like“ On the Road Again.” Or“ Blue Eyes Crying in the Rain” — I didn’ t write it, but it’ s still a great song. “ Always On My Mind” — I didn’ t write that one, either, but I really enjoy

# dvdshrink

Wednesday, June 25, 2008 10:30 AM by dvdshrink

If you use your PC for work, don’ t use it for play, or allow family members to use it for play. Personal experiences show that the most common ways viruses, spyware, and other bad stuff gets on people’ s PC’ s is through“ play” stuff. This includes downloaded

# how to copy dvd

Thursday, June 26, 2008 4:09 AM by how to copy dvd

Link: Optimize Ubuntu Feisty Fawn for Speed- Tips for a faster Ubuntu machine! -

# dvd player decoders

Thursday, June 26, 2008 6:06 AM by dvd player decoders

Send a message Subscribe to RSS feed Tell a friend Add to My MSN Add to Live.

# dvd decrypter software

Thursday, June 26, 2008 7:11 AM by dvd decrypter software

scan IP address , scan your TCP/ UDP ports , scan several specifically popular TCP/ UDP ports.

# www.dvdrecordpro.com

Thursday, June 26, 2008 9:12 AM by www.dvdrecordpro.com

Why am I being called Neko- chan now... ON MY OWN SPACE* sobs* I\'m working on the next page even as we speak. Sorry \'bout the long wait, guys. Massive editing was being done then.

# dvd burning

Thursday, June 26, 2008 5:26 PM by dvd burning

Fortunately, we can strip this down for the sake of a simple test. We’ re using a local target so step 1 is unnecessary. We can also hard- code the MAC of the target machine, to also skip steps 2 to 4. An ICMP ECHO request packet can then be constructed

# coping dvds

Monday, July 07, 2008 11:35 AM by coping dvds

X- StartupManager (consente di visualizzare e gestire tutti i programmi che vengono eseguiti all’

# Lexapro abuse.

Monday, August 25, 2008 1:54 PM by Lexapro maximum effective dosage.

Stopping the use of lexapro. Lexapro side effects. Compare cymbalta lexapro.

# Lexapro.

Tuesday, August 26, 2008 12:04 PM by Lexapro.

Lexapro side effects. Lexapro. Provigil wellbutrin lexapro. When do you feel better with 10mg lexapro. Lexapro and side effects.

# re: More musings on the enhanced IE security in Win2K3

Saturday, December 27, 2008 4:57 PM by nick_erclet

# re: More musings on the enhanced IE security in Win2K3

Friday, May 15, 2009 3:09 AM by nick_raccoe

# re: More musings on the enhanced IE security in Win2K3

Wednesday, July 29, 2009 9:26 AM by name

I like your work!,

# re: More musings on the enhanced IE security in Win2K3

Saturday, August 01, 2009 7:16 AM by MOanednepspoppy

<a href=www.theelmsholidayinn.com/.../a>

If you are still skeptical of whether Effexor could work for you, schedule a short visit with your doctor and talk it over with him.

# re: More musings on the enhanced IE security in Win2K3

Saturday, March 06, 2010 10:21 AM by Jane

# re: More musings on the enhanced IE security in Win2K3

Sunday, March 07, 2010 2:09 AM by Arnie

<a href= http://wwwdisen

# re: More musings on the enhanced IE security in Win2K3

Sunday, March 07, 2010 1:34 PM by Arnie

<a href= blackandwhitepicsofsesshoumaru.hearpuffed.in >black and white pics of sesshoumaru</a>  

<a href= ht

# re: More musings on the enhanced IE security in Win2K3

Sunday, March 07, 2010 11:18 PM by Neo

<a href= soupplantationcouponsfamilydinner.leavepuffed.in >soup plantation coupons family dinner</a>  

# re: More musings on the enhanced IE security in Win2K3

Wednesday, March 10, 2010 9:16 AM by Dominic

# re: More musings on the enhanced IE security in Win2K3

Thursday, March 11, 2010 1:52 PM by Hero

<a href= kenmoresewingmachine117552.beganpuffed.in >kenmore sewing machi

# re: More musings on the enhanced IE security in Win2K3

Monday, March 15, 2010 1:05 PM by Hero

# re: More musings on the enhanced IE security in Win2K3

Monday, March 22, 2010 6:29 AM by Halo

<a href= mprx.o2active.cz/.../primarysharingtimechristmas.html >primary sharing time christmas</a>

# re: More musings on the enhanced IE security in Win2K3

Tuesday, April 06, 2010 8:08 PM by Arnie

# re: More musings on the enhanced IE security in Win2K3

Saturday, April 24, 2010 2:41 PM by Heel

# re: More musings on the enhanced IE security in Win2K3

Sunday, April 25, 2010 10:55 AM by Bill

<a href= 686ssrproseriesaccuracyforum.thinggooded.in >686 ssr pro serie

# re: More musings on the enhanced IE security in Win2K3

Saturday, May 15, 2010 8:26 AM by Heel

# re: More musings on the enhanced IE security in Win2K3

Tuesday, May 18, 2010 9:58 PM by Neo

<a href= http://anasites.onedaled.in/ >ana sites</a>

# re: More musings on the enhanced IE security in Win2K3

Thursday, May 27, 2010 8:59 PM by Aron

# re: More musings on the enhanced IE security in Win2K3

Thursday, September 02, 2010 7:21 PM by Bill

<a href= http://meryp

# re: More musings on the enhanced IE security in Win2K3

Monday, September 06, 2010 3:30 AM by Arnie

# re: More musings on the enhanced IE security in Win2K3

Wednesday, September 19, 2012 5:10 PM by icon design

 You, casually, not the expert?

P.S. Please review <a href="tonoficons.deviantart.com/.../Desktop-Buffet-Icons-278806223">Desktop Buffet Icons from tonoficons</a>

# re: More musings on the enhanced IE security in Win2K3

Friday, September 21, 2012 7:43 AM by icons

 I suggest you to visit a site, with an information large quantity on a theme interesting you.

P.S. Please review <a href="popavidi3.deviantart.com/.../Navigation-Toolbar-Icons-298879492">Navigation Toolbar Icons from popavidi3</a>

# re: More musings on the enhanced IE security in Win2K3

Saturday, September 22, 2012 4:55 PM by icon package

 It is possible to tell, this exception :)

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Saturday, September 22, 2012 7:25 PM by icons downloads

 The happiness to me has changed!

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Saturday, September 22, 2012 11:17 PM by icon package

 I apologise, but, in my opinion, you are not right. I am assured. I suggest it to discuss.

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Sunday, September 23, 2012 8:54 AM by icons set

 Let's return to a theme

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Sunday, September 23, 2012 2:54 PM by icons designs

 You are mistaken. I can prove it. Write to me in PM, we will discuss.

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Sunday, September 23, 2012 8:09 PM by icon set

 I can not recollect, where I about it read.

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Monday, September 24, 2012 12:16 AM by icons pack

 Let will be your way. Do, as want.

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Monday, September 24, 2012 5:24 AM by icon download

 And I have faced it. We can communicate on this theme.

<a href="www.hpixel.com/.../a>

# re: More musings on the enhanced IE security in Win2K3

Monday, September 24, 2012 3:52 PM by Win8 icone soft for Windows 8

 As the expert, I can assist. Together we can find the decision.

# re: More musings on the enhanced IE security in Win2K3

Monday, October 08, 2012 4:29 PM by icon designs

<a href="smile.softplatz.net/.../67793.html"> In my opinion it is not logical</a>

# re: More musings on the enhanced IE security in Win2K3

Tuesday, October 09, 2012 1:28 AM by icons download

<a href="profismael.dynip.sapo.pt/plogger Clearly, I thank for the information.</a>

# re: More musings on the enhanced IE security in Win2K3

Tuesday, October 09, 2012 8:10 AM by icons download

<a href="www.softviewer.com/download_detail.php Today I read on this question much.</a>

# re: More musings on the enhanced IE security in Win2K3

Wednesday, October 10, 2012 4:16 AM by icon pack

<a href="info.hs-lab.com.ua/.../Large-Vector-Icons_581.html"> Ithink, that you are not right. I am assured. I can defend the position. Write to me in PM, we will talk.</a>

# re: More musings on the enhanced IE security in Win2K3

Wednesday, April 17, 2013 1:57 PM by Knowlton

Hello there, I found your web site by the use of Google

even as looking for a related topic, your web site got

here up, it seems to be great. I have bookmarked it in

my google bookmarks.

Hi there, just become aware of your weblog through Google, and located that it's truly informative. I am gonna be careful for brussels. I'll appreciate if

you proceed this in future. Many other people

will likely be benefited from your writing.

Cheers!

Leave a Comment

(required) 
(required) 
(optional)
(required)