IE & OE Settings
français ici
This information was made with the help of several people and I have just compiled it into one source for you. Thanks to Winchester, BrianO, Maddoktor2, Corrine, and HTML by GOATIE.
UPDATED 03/14/2006
Hi, you are reading this because
(1) you are trying to get rid of some nasty things on your computer or
(2) you are worried about your settings, or both.
GOOD, that is the first step.
When Microsoft ships it's system they are trying to make it "easy" for you to surf the web, NOT SAFE!
You are responsible for the security of your computer, not Norton, Microsoft, Zone Alarm, but you.
You need both a good Firewall and Anti-virus software.
You need to make sure you are current in all patches and reference file updates.
(If you need either a Firewall or Anti-virus software, check here:Newbie/oldie Info List .)
Now that that is done, lets look at Outlook Express first:
NOTE: Outlook Express is part of Internet Explorer so the settings for one can affect the other.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
OUTLOOK EXPRESS
To make Outlook Express safe from virus attempts:
1. Open Internet Explorer and then click "Tools"
2. Go to "Internet Options" then "Security", click on "Restricted Zone"
3. Click on "Custom Level" and DISABLE EVERYTHING (setting it to "High" is not enough)
4. Click "OK" as much as you need to get out
5. When IE asks if you are sure, click "YES" and close any open IE windows
6. Now open Outlook Express. On the upper menu bars open "Tools"
7. Go to "Options" then "Security"
8. Place a dot in "Restricted Zone"
9. Click "OK" as many times as you need to get out
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
INTERNET EXPLORER
To make Internet Explorer safe from attacks, drive by downloads and other things:
1. Open Internet Explorer and then click "Tools"
2. Go to "Internet Options" then "Security", click on "Internet Zone"
3. Click on "custom Level"
4. Now the list MIGHT start off with "net framework". If so select "prompt" on both
5. Next comes Active X. Go down the list.
NOTE: for XP with SP-2 go here for "internet zone settings"
http://rcip.com/mitch/sp2.html
Let's start in the Security section with Active x. Just follow my lead.
- ActiveX: prompt, disable, disable, prompt, enable
- Downloads: enable, prompt
- MS VM: high safety
- Miscellaneous: prompt, enable, prompt, disable, enable, prompt, disable, enable, high safety, enable, disable
- Scripting: enable, prompt, prompt
- Authentication: prompt
Close out that "Security Folder"
6. Now at the top of the "Internet Options" is a sub folder called "Advanced". Click it. Check only the following boxes:
Accessibility:
- none checked, or use whatever you need.
Browsing:
- always send, close unused, disable script debugging
- enable folder view
- enable page transitions
- enable visual styles
- notify when downloads are complete
- show friendly, show friendly, show go
- underline links-always
- use inline autocomplete
- use smooth scrolling
- use http 1.1
MS VM:
Multimedia:
- play animations, sounds, and videos
- show pictures
- smart image dithering
Search:
go to most likely site
Security:
- do not save encrypted pages to disk
- empty temp folder when closed
- enable profile assistant
- use SSL 2.0 and 3.0
- warn if changing
- warn if forms submittal is being redirected
Hit apply, then ok.
And, we're all done.
Those basic settings will secure IE6 nicely.
If you would like to use any sites that have active scripting on them, you can enable them if you trust the site not to infect your computer.
That choice is yours.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
How to enable scripting on "Trusted Sites"
- Open Internet Explorer, then click on "Tools"
- Go to "Internet Options" then "Security", click on "Trusted Zone"
- Click on "Custom Level" and enable everything you would like to work on your trusted sites
- To add sites to your Trusted Sites folder, click on "Trusted Sites" in the upper menu window
- Click on "Sites" in the lower window, type or cut/paste the trusted site in the dialogue box, and click "ADD" then "OK" and then "OK" again. Now would be a good time to add the Windows Update Sites here as just described.
http://windowsupdate.microsoft.com
http://v4.windowsupdate.microsoft.com
- When IE asks if you are sure, click "YES"
- If you come across a site you wish to put in your trusted sites folder because you need to use a script on their page, simply add it following
steps 1-7 and then just refresh the page when you are done. One of the sites you will need to put in the "Trusted Zone is "Windows Update"
or your "online banking"
Ok, doing the above you have almost set up your Internet Explorer. You might change a setting or two. I think you will find that most sites
don't need the controls they ask for, and without granting them the access they can't put nasty things on your system.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
COOKIE SETTINGS
So lets talk about cookie settings. You can get a "cookie manager" for free or you can have Internet Explorer do it.
Here is the way for I.E to control cookies:
In your browser, go to
- "Tools", "Internet Options", "Privacy Tab", "Advanced Button".
- Check the box for "Override automatic cookie handling".
- Under "First-party Cookies" select "Prompt".
- Under "Third-party Cookies" select "Block".
- Check the box for "Always allow session cookies".
- Click "Ok" and "Ok".
Now when you surf to a web site that wants to save a cookie on your computer a "Privacy Alert" will pop up.
If it's a site you don't need to save any preferences or passwords/user names for,
- tick the box "Apply my decision to all cookies from this Web site" then press "Block Cookie".
- Press "Allow Cookie" for sites you want to save cookies for.
If you change your mind later, you can
- go back into "Tools", "Internet Options", "Privacy Tab" and click on "Edit".
- From there you can find the site in mind from the "Managed Web sites" box and double-click it.
- Choose either "Block, Allow or Remove" to change your preference.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
References
Microsoft: Setting Up Security Zones
http://www.microsoft.com/windows/ie/using/howto/security/setup.asp
Microsoft: Working with Internet Explorer 6 Security Settings
http://www.microsoft.com/windows/ie/using/howto/security/settings.asp
Customizing Outlook Express Security
http://web.brandeis.edu/pages/view/Bio/OutlookExpressSecurity