Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 07, 2004

Disabling the ADODB.Stream Object

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, I wrote about two ways to quickly and easily work around problems with Microsoft ADO databases (ADODB). One solution is a registry script from eEye Digital Security and the other is PivX Solutions' Qwik-Fix. As far as I know, both of these solutions can disable parts of ADODB. If you missed last week's newsletter, you can read about the solutions at

http://www.winnetmag.com/article/articleid/43131/43131.html

The combined attack method that I wrote about last week involves the use of the ADODB.Stream object, which Microsoft says is essentially a memory-based file. Now Microsoft has released an official fix to disable ADODB.Stream for Windows Server 2003, Windows XP, and Windows 2000. You can download the "Critical Update for Microsoft Data Access Components - Disable ADODB.Stream object from Internet Explorer" fix at:

http://www.microsoft.com/downloads/details.aspx?familyid=4d056748-c538-46f6-b7c8-2fbfd0d237e3&displaylang=en

According to the related Microsoft article "How to disable the ADODB.Stream object from Internet Explorer," the fix makes changes to the registry that prevent the ADODB.Stream object from accessing the local disk drives via Microsoft Internet Explorer (IE). However, other applications that use the object can still access the disk if necessary.

http://support.microsoft.com/?kbid=870669

In addition to installing the Microsoft fix, which I think most security professionals would recommend, you might want to consider other configuration changes to your IE installations. Another Microsoft article, "How to strengthen the security settings for the Local Machine zone in Internet Explorer," describes how to disable ActiveX controls and Java applets, prompt the user before running scripts, prompt the user before accessing a database in another zone, control how zone security is applied (e.g., per user or the same settings for all users, whether users can change those settings), and use Group Policy to control IE security zone settings. Be aware that you might experience unwanted effects (as noted in the article) when you make some of the recommended changes.

http://support.microsoft.com/?kbid=833633

Two other articles--"How to Stop an ActiveX Control from Running in Internet Explorer" and "How to Remove an ActiveX Control in Windows"--describe how to prevent IE from using particular ActiveX controls and how to remove ActiveX controls if you need to do that for whatever reason. By using some or all of the recommended IE security settings, you can significantly increase browser security

http://support.microsoft.com/?kbid=240797

http://support.microsoft.com/?kbid=154850

Microsoft said that in the coming weeks it will release a series of security updates for IE that will provide additional protection; however, the company hasn't said what those updates might actually entail. The company also said that it's working on a "comprehensive update for all supported versions of Internet Explorer [which] will be released once it has been thoroughly tested and found to be effective across a wide variety of supported versions and configurations of Internet Explorer."

The company also said that the upcoming XP Service Pack 2 (SP2) will better protect users against attacks and unwanted content, including downloads. So in addition to the already-mentioned fixes and configuration changes, more help is on the way.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement