Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

March 28, 2001 12:00 AM

Internet Explorer Security Options, Part 1

Windows IT Pro
InstantDoc ID #20468
Rating: (0)

Browsing the "wild, wild Web" can be dangerous. Combine today’s highly functional Microsoft Internet Explorer (IE) 5.0 with less-than-security-savvy users who visit all types of Web sites, and you take some serious risks. Several methods exist for embedding malicious content into Web pages. To suffer from a security attack, however, you don’t need to land on the Web site of a malicious Web master. Many Web sites such as eBay and Hotmail let users embed HTML and active content into their postings. When you view a Web page that contains active content (e.g., a Java applet), you let untrusted code execute on your computer. Even with the built-in security features in Java and other scripting languages, attackers have found many ways to access files on the local drives of the computer browsing the Web and to access resources on your company's other servers.

In this series of articles, I’ll show you how to reduce the risk of browsing the Web by properly configuring IE’s security options. However, because you can have hundreds or thousands of IE installations, you can’t afford to configure each computer individually—not to mention reconfigure IE installations when users reverse your security settings. I’ll show you how to use Group Policy to securely configure IE and to prevent users from defeating your restrictions. To begin, it's important that you know how to use IE's security zones to apply the appropriate level of security and restrictions to each Web site that you and your users visit.

IE Security Zones
Many of IE's security options can cause inconvenience or loss of functionality, and some Web sites deserve more trust than others. IE uses the concept of Web content zones to let you apply the correct amount of security to each site. To view the security settings, open IE, select Tools, Internet Options, and select the Security tab, as Figure 1 shows. IE has four zones: Internet, Local intranet, Trusted sites, and Restricted sites. Each zone has a preset level of security—Low, Medium-low, Medium, or High. You can change these levels, or you can select Custom Level to specify your own settings. Let's look at each zone—we'll explore the Custom Level settings in Part 2.

Internet Zone
The Internet zone includes all Web sites you haven't specified in the other three zones. The default level for the Internet zone is Medium. You can move the slider to change this setting, as Figure 1 shows. For example, if you change the security to Medium-low, a warning dialog box pops up, asking if you really want to change the setting. If you click Yes, the level changes and displays information about the setting. (Any time you change a zone's default setting, you'll get a synopsis about the setting.)

Local Intranet Zone
The Local intranet zone defaults to Medium-low security that typically includes all content on your local computer and on your company's intranet servers within your local network. To fine-tune the sites in this zone, click Sites. IE opens a small dialog box with three check boxes representing different types of Web sites, as Figure 2 shows.

If you check Include all local (intranet) sites not listed in other zones, you include Web sites that start with a drive letter (content on your local computer) and Web sites that don’t include dots (e.g., .com, .org). Typically, you access an intranet Web site with only its base computer name (i.e., //humanresources). If you check Include all sites that bypass the proxy server and your browser uses a proxy server, you include all Web sites that bypass the proxy server. If you don’t use a proxy server, this check box has no effect, regardless of how you set it.

If you check Include all network paths (UNCs), IE considers any Web pages that you access using the Universal Naming Convention (UNC) to be part of this zone (e.g., a UNC path is in the format of \\\\). To add specific Web sites that you trust to the Local intranet zone, click Advanced to access a dialog box that lets you enter specific addresses, as Figure 3 shows. These addresses can be in any format that IE accepts, such as addresses on the Internet (e.g., http://www.win2000mag.com) UNC names (e.g., \\mktg\projections), or intranet sites (e.g., //hrsvr). You can also add trusted Internet Web sites so that your internal servers treat the sites as though they're in your local network.

If you check Require server verification (https:) for all sites in this zone, this option prevents you from connecting to Web sites using HTTP on TCP port 80. Instead, IE only lets you connect through Secure Sockets Layer (SSL) on port 443. This option is valuable because as part of SSL, the server must authenticate itself to your browser using a certificate signed by a Certificate Authority (CA) that your computer trusts. However, this option typically isn't appropriate for the Local intranet zone because you usually trust Web sites within your internal network and because Web servers must be specially configured with certificates to support SSL.

Trusted Sites
You can use the Trusted sites zone for highly trusted and functional Web sites where you need active content or sites where you need minimal security. These sites might include internal Web sites or the Web sites of trusted business partners. Trusted sites defaults to a security setting of Low and doesn't include any Web sites. Click Sites to access a dialog box that lets you add and remove specific Web addresses, as Figure 3 shows. If the Web site supports SSL for all Web pages, you should select the Require server verification (https:) for all sites in this zone check box. Unfortunately, most Web sites use SSL only for specific Web pages that display or accept confidential information.

Restricted Sites
You can use the Restricted sites zone for Web sites that users must visit but that are dangerous. The Restricted sites zone defaults to a security setting of High and doesn’t include any Web sites. You can select Sites to add and remove specific Web addresses, which looks the same as Figure 3 except there is no Require server verification (https) for all sites in this zone check box. Be sure you to set up your zones correctly so that each Web site is subject to the appropriate security level. In Part 2 of this article, I'll explain the settings in Custom Level.

Related Content:

ARTICLE TOOLS

Comments
  • Kevin
    8 years ago
    May 10, 2004

    I think you mean your IP address actually. This can be changed by your ISP. Contact them and find out what they can do for you. Ask them if your IP changes. Many times it doesn't if you are using broadband access such as DSL or cable modem. Second you can look into using an anonymous browsing software or internet site. One of these is Anonymizer (I think I spelled this correctly.)

  • WINSTON
    9 years ago
    Nov 12, 2003

    I understand the article just fine, but it neglects to mention what action should be taken in the event that you cannot access the "internet tools" option. I keep getting an "access denied, talk to your system administrator" message. I don't have a system administrator. How do I undo whatever I did to get this message? Any help is greatly appreciated.
    Sincerely,
    Winston

  • Barbara Hale
    11 years ago
    Mar 30, 2001

    I am a member of excite chat/virtual places..I go to 50 Plus-1 chat room..I wish to change my ISP {Internet Service Provider #}..Internet Exployer!! Each time I enter this room regardless what name I use people know me by this #!! I have had terrorist threats, called every vulgar name you could possibly imagine, and threats to fry my computer, also someone does mess with my computer at times by booting, and a ringing in my box and screen freezing. HOW DO I CHANGE THIS? THIS IS VERY SCARY!!! All this was started by one individual and spread by her actions!

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.