Disable ActiveX Controls That Are Under Attack
Set a kill bit in your Windows Registry to prevent rogue ActiveX contols from loading.
Andrew Brandt

Of late, evildoers have been finding ways to compromise ActiveX controls well in advance of Microsoft's fixes for the problems, meaning that even users who install patches immediately are sometimes at risk for weeks at a time. Recently, for instance, villains discovered that they could use an ActiveX control called ADODB.connection to hit computers with drive-by downloads of malicious software. Even PCs running the new IE 7 are vulnerable---and at press time, no fix existed.
There is one remaining way to protect yourself against an at-risk ActiveX vulnerability: Set a "kill bit" for it. By making a small change to the Registry, a kill bit prevents an ActiveX control from loading. If a vulnerable control isn't running when you stumble upon a malicious Web site, your PC's chances of getting hit with unwelcome software are drastically reduced.
To set a kill bit, you need to know an internal Windows code called the CLSID, which identifies the problematic ActiveX control. Security experts and organizations such as CERT, the security research center at Carnegie Mellon University, often publish the CLSIDs of ActiveX controls that bad guys are actively exploiting. For instance, you can find the CLSID of ADODB.connection at Handler's Diary.
Once you have the CLSID, you can tweak your Registry to protect your PC from attacks aimed at that particular ActiveX control.
First, back up your Registry (for instructions, see "Step-By-Step: Care and Feeding of the Windows Registry." Then open a Registry editor (to use Windows XP's version, go to Start, click Run, type in Regedit, and click OK). Drill down to the folder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility. Right-click ActiveX Compatibility in the left pane, and choose NewKey. Change the name of the new key to the CLSID, surrounded by curly brackets--the keystroke characters { and }, also known as braces or set symbols.
Then right-click the key you just entered in the left pane, and choose New, DWORD Value. Name the new entry Compatibility Flags, double-click that entry, change its value to 400, and make sure that the radio button labeled hexadecimal is selected. Click OK and you're done.
Be aware that setting a kill bit may disable useful functions in your browser, and may make it difficult to use some Web sites. You should restrict your use of kill bits to occasions when a serious ActiveX vulnerability has been made public, and no patch to fix the problem yet exists. Once a patch becomes available, you can delete the kill bit setting in the Registry---which will immediately reactivate the ActiveX control---and then update Internet Explorer at Microsoft Update.
Andrew Brandt is a contributing editor for PC World. E-mail him at privacywatch@pcworld.com.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
A Guide to Business IT
PCW Download Guide
Related Security Articles
- Vendors, Cops, Profs Team to Study Cybercrime Tech vendors and the Secret Service are among those working with an evaluation of trends and best practices for security.
- Microsoft Readies Flood of Patches The 11 patches include 4 critical fixes, plus updates to Windows, Office, and IE.
- Mafiaboy Grows Up; a Hacker Seeks Redemption Eight years later, the infamous teen hacker wants to move from his history of downing sites to using his skills for good.
- Google in Curious Alliance With Click-fraud Detection Firm Google has agreed to cooperate with its longtime adversary Click Forensics on click-fraud reports.
- PCI App Security: Who's Guarding the Data Bank? Compliance strategies for PCI's new application security requirements.
Best Prices on Security Software
Norton Internet Security 2008Price: $13.98
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.49
Norton Internet Security 2009Price: $25.49
Norton 360 2.0 ( PC)Price: $44.99
Kaspersky Internet Security 2009Price: $25.95
Internet Security Suite 2008 - 3-UserPrice: $14.95
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...







"Disable ActiveX Controls That Are Under Attack" Comments