<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security e Virtualization Blog di Feliciano Intini (e il suo team PCfSV2) : IE8 Security</title><link>http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx</link><description>Tags: IE8 Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Beta delle Security Baseline per Windows 7, BitLocker, e IE8</title><link>http://blogs.technet.com/feliciano_intini/archive/2009/07/14/beta-delle-security-baseline-per-windows-7-bitlocker-e-ie8.aspx</link><pubDate>Tue, 14 Jul 2009 16:45:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3263817</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3263817.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3263817</wfw:commentRss><description>Sono appena state pubblicate le beta delle Security Baseline per Windows 7, BitLocker, e IE8 : Sign-Up Now for the New Windows 7 and Internet Explorer 8 Security Baselines Beta Opening July 13th! Per chi ancora non sapesse cosa sono, ricordo che le Security...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2009/07/14/beta-delle-security-baseline-per-windows-7-bitlocker-e-ie8.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3263817" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Compliance+Management/default.aspx">Security Compliance Management</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+7+Security/default.aspx">Windows 7 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Bitlocker/default.aspx">Bitlocker</category></item><item><title>Analisi di rischio sui Bollettini di sicurezza Microsoft – giugno 2009</title><link>http://blogs.technet.com/feliciano_intini/archive/2009/06/10/analisi-di-rischio-sui-bollettini-di-sicurezza-microsoft-giugno-2009.aspx</link><pubDate>Wed, 10 Jun 2009 02:31:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252770</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3252770.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3252770</wfw:commentRss><description>L’emissione dei bollettini di sicurezza Microsoft di questo mese è caratterizzata dal rilascio di 10 bollettini , che risolvono in totale 31 vulnerabilità . Vi riporto la tabella riepilogativa dell’ exploitability index da cui si evince che quasi tutti...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2009/06/10/analisi-di-rischio-sui-bollettini-di-sicurezza-microsoft-giugno-2009.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3252770" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Office+Security/default.aspx">Office Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Bulletin+and+Advisory+Risk+Analysis/default.aspx">Security Bulletin and Advisory Risk Analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+XP+Security/default.aspx">Windows XP Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Active+Directory+Security/default.aspx">Active Directory Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Scareware_2F00_Rogueware/default.aspx">Scareware/Rogueware</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+2000+Security/default.aspx">Windows 2000 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2003+Security/default.aspx">Windows Server 2003 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IIS+Security/default.aspx">IIS Security</category></item><item><title>Rilasciato Internet Explorer 8</title><link>http://blogs.technet.com/feliciano_intini/archive/2009/03/19/rilasciato-internet-explorer-8.aspx</link><pubDate>Thu, 19 Mar 2009 20:33:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3215329</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3215329.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3215329</wfw:commentRss><description>Rilancio telegraficamente l'importante annuncio del rilascio sul web di Internet Explorer 8 , dato dai due blog di IE e Windows e ripreso da Renato: Internet Explorer 8 Final Available Now Final Release of Internet Explorer 8 Now Available Internet Explorer...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2009/03/19/rilasciato-internet-explorer-8.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3215329" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category></item><item><title>Disponibile IE8 RC1 con la nuova protezione anti-Clickjacking (che fa discutere)</title><link>http://blogs.technet.com/feliciano_intini/archive/2009/01/29/disponibile-ie8-rc1-con-la-nuova-protezione-anti-clickjacking-che-fa-discutere.aspx</link><pubDate>Thu, 29 Jan 2009 19:16:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3194427</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3194427.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3194427</wfw:commentRss><description>L'impegno pressante nel nuovo ruolo (e i festeggiamenti ;-) hanno fatto slittare la mia ripresa di questa importante segnalazione, lanciata dal puntualissimo Renato su Technet e ieri ripresa da Lorenza su MClips: Disponibile Internet Explorer 8.0 RC 1...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2009/01/29/disponibile-ie8-rc1-con-la-nuova-protezione-anti-clickjacking-che-fa-discutere.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3194427" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Malware+and+Attack+analysis/default.aspx">Malware and Attack analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/5.0+User+Security/default.aspx">5.0 User Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/1.0+Internet+Security/default.aspx">1.0 Internet Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Ecosystem/default.aspx">Security Ecosystem</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Clickjacking/default.aspx">Clickjacking</category></item><item><title>Security Advisory 961051 su Internet Explorer: nuovi workaround</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/12/13/security-advisory-961051-su-internet-explorer-nuovi-workaround.aspx</link><pubDate>Sat, 13 Dec 2008 14:43:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3168031</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3168031.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3168031</wfw:commentRss><description>Anche se due giorni fa non ho avuto la possibilità di aggiornarvi tempestivamente sull'uscita di questo advisory " Microsoft Security Advisory (961051) - Vulnerability in Internet Explorer Could Allow Remote Code Execution ", ora ho modo di farlo in modo...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/12/13/security-advisory-961051-su-internet-explorer-nuovi-workaround.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3168031" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Bulletin+and+Advisory+Risk+Analysis/default.aspx">Security Bulletin and Advisory Risk Analysis</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+XP+Security/default.aspx">Windows XP Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+2000+Security/default.aspx">Windows 2000 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2003+Security/default.aspx">Windows Server 2003 Security</category></item><item><title>Disponibilità di IE 8 Beta 2 in italiano e riepilogo post sulla sicurezza di IE8</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/17/disponibilit-di-ie-8-beta-2-in-italiano-e-riepilogo-post-sulla-sicurezza-di-ie8.aspx</link><pubDate>Wed, 17 Sep 2008 19:11:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3125271</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3125271.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3125271</wfw:commentRss><description>Approfitto della necessaria segnalazione della disponibilit&amp;#224; di Internet Explorer 8 Beta 2 in italiano come riportato da Renato , per riportarvi l'insieme dei post del blog di IE nei quali sono stati forniti i dettagli delle varie funzionalit&amp;#224;...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/17/disponibilit-di-ie-8-beta-2-in-italiano-e-riepilogo-post-sulla-sicurezza-di-ie8.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3125271" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Google Chrome apre la "1st World Browser War": chi vincerà la battaglia su Sicurezza e Privacy?</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/03/google-chrome-apre-la-1st-world-browser-war-chi-vincer-la-battaglia-su-sicurezza-e-privacy.aspx</link><pubDate>Wed, 03 Sep 2008 16:40:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3116826</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>13</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3116826.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3116826</wfw:commentRss><description>E' indubbio che l'arrivo di Google Chrome segner&amp;#224; il vero e proprio scoppio della &amp;quot;1a Guerra Mondiale dei Browser&amp;quot; (magari le guerre fossero tutte combattute a questo livello... :-(...): non voglio dire che fino ad ora il confronto IE-Firefox...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/03/google-chrome-apre-la-1st-world-browser-war-chi-vincer-la-battaglia-su-sicurezza-e-privacy.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3116826" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Firefox+Security/default.aspx">Firefox Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Google+Security/default.aspx">Google Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Chrome+Security/default.aspx">Chrome Security</category></item><item><title>Disponibile IE8 Beta 2, con importanti novità in area Privacy</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/08/27/disponibile-ie8-beta-2-con-importanti-novit-in-area-privacy.aspx</link><pubDate>Thu, 28 Aug 2008 00:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3113017</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3113017.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3113017</wfw:commentRss><description>La notizia merita una brevissima interruzione del silenzio blogging che mi sono imposto durante le ferie (secondo la descrizione di Simona sono classificabile tra i &amp;quot;fortunati&amp;quot;, visto che sono ancora in vacanza, giusto per quest'ultima, terza...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/08/27/disponibile-ie8-beta-2-con-importanti-novit-in-area-privacy.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3113017" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>IE8 Security: SmartScreen® Filter, il nuovo Phishing Filter con funzionalità anti-malware</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/07/03/ie8-security-smartscreen-filter-il-nuovo-phishing-filter-con-funzionalit-anti-malware.aspx</link><pubDate>Thu, 03 Jul 2008 12:40:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3082817</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3082817.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3082817</wfw:commentRss><description>Ieri &amp;#232; stata pubblicata sul blog di IE una raffica di informazioni sulle nuove funzionalit&amp;#224; di sicurezza che verranno incluse in IE8 . La prima che vi riporto &amp;#232; quella che impatta pi&amp;#249; direttamente l'esperienza dell'utente, il nuovo...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/07/03/ie8-security-smartscreen-filter-il-nuovo-phishing-filter-con-funzionalit-anti-malware.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3082817" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Anti-Phishing/default.aspx">Anti-Phishing</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Anti-Malware/default.aspx">Anti-Malware</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>IE8 security: i miglioramenti negli ActiveX</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx</link><pubDate>Thu, 08 May 2008 12:51:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3052200</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3052200.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3052200</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;E' da poco uscito il secondo post di approfondimento delle novit&amp;#224; di sicurezza di &lt;strong&gt;Internet Explorer 8&lt;/strong&gt;, come vi ho segnalato nello &lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx" target="_blank"&gt;scorso post a proposito del DEP/NX&lt;/a&gt;. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Questa volta il tema &amp;#232; tra i pi&amp;#249; importanti: &lt;a href="http://blogs.msdn.com/ie/archive/2008/05/07/ie8-security-part-ii-activex-improvements.aspx" target="_blank"&gt;i miglioramenti negli &lt;strong&gt;ActiveX&lt;/strong&gt;&lt;/a&gt;. Come ho avuto di dire pi&amp;#249; volte, gli ActiveX hanno da sempre rappresentato una sorta di tallone di achille per Internet Explorer per un motivo molto semplice: di fatto esprimono l'eterno, delicato, equilibrio da raggiungere tra ricchezza di funzionalit&amp;#224; ed esigenze di maggiore sicurezza&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;gli ActiveX sono di fatto dei componenti pensati per &lt;u&gt;estendere&lt;/u&gt; le funzionalit&amp;#224; del browser e quindi per &lt;u&gt;arricchirlo&lt;/u&gt;: la loro esistenza ha di fatto avvantaggiato tutto il mercato delle aziende che sviluppano software per il web...&lt;/font&gt; &lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;d'altra parte incorporare nel tuo sistema un componente sviluppato da una parte terza su cui Microsoft non pu&amp;#242; effettuare un controllo di qualit&amp;#224; non &amp;#232; il massimo dal punto di vista della sicurezza: ...ma il modello &amp;#232; nato quando la sicurezza non era una preoccupazione riconosciuta fuori dalle universit&amp;#224;...&lt;/font&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Quando ci si &amp;#232; accorti che la rischiosit&amp;#224; di questo modello era diventata elevata a causa degli attacchi che indirizzavano gli ActiveX scritti male (ossia non scritti secondo le &lt;em&gt;best practice&lt;/em&gt; di &lt;em&gt;secure coding&lt;/em&gt;) non si &amp;#232; potuto dire &amp;quot;OK, allora aboliamo il modello...&amp;quot;: cosa ne sarebbe stato di tutte le applicazioni web che si appoggiano agli ActiveX per arricchire e personalizzare l'esperienza degli utenti sul web? L'unico percorso possibile &amp;#232; stato quello di avviare un irrobustimento del modello per contrastare via via le tipologie di minacce che si sono osservate, bilanciando sempre il guadagno in termini di protezione rispetto all'inevitabile impatto sulle applicazioni terze che rischiavano di non funzionare pi&amp;#249;. Il passo pi&amp;#249; deciso in questa direzione &amp;#232; avvenuto con &lt;strong&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=E550F940-37A0-4541-B5E2-704AB386C3ED&amp;amp;displaylang=en" target="_blank"&gt;i miglioramenti di sicurezza di IE6 nel Service Pack 2 di Windows XP&lt;/a&gt;&lt;/strong&gt;, e i ritorni positivi di quella esperienza hanno alimentato i &lt;strong&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=6AA4C1DA-6021-468E-A8CF-AF4AFE4C84B2&amp;amp;displaylang=en" target="_blank"&gt;miglioramenti di IE 7&lt;/a&gt;&lt;/strong&gt;, per giungere ora a queste nuove funzionalit&amp;#224; in IE8, di cui vi fornisco un breve accenno delle pi&amp;#249; significative, invitandovi alla lettura completa del &lt;a href="http://blogs.msdn.com/ie/archive/2008/05/07/ie8-security-part-ii-activex-improvements.aspx" target="_blank"&gt;post di Matthew David Crowley&lt;/a&gt; per l'elenco completo:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&lt;b&gt;Per-User (Non-Admin) ActiveX&lt;/b&gt;&lt;font face="Calibri" size="3"&gt;: &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;Running IE8 in Windows Vista, a standard user may install ActiveX controls in their own user profile without requiring administrative privileges. This improvement makes it easier for an organization to realize the full benefit of User Account Control by enabling standard users to install ActiveX controls used in their day-to-day browsing. If a user happens to install a malicious ActiveX control, the overall system will be unaffected, as the control was installed only under the user&amp;#8217;s account. Since installations can be restricted to a user profile, the risk and cost of compromise (and, in turn, the total cost of administering users on a machine) will be lowered significantly. [...]&lt;/font&gt;&lt;/p&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#0000ff"&gt;Per-Site ActiveX&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;When a user navigates to a Web site containing an ActiveX control, IE8 performs a number of checks, including a determination of where a control is permitted to run. This check is referred to as Per-Site ActiveX, a defense mechanism to help prevent malicious repurposing of controls. If a control is installed, but is not permitted to run on a specific website, an Information Bar appears asking the user whether or not the control should be permitted to run on the current website. [...]&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#0000ff"&gt;Enforcing Per-Site with ATL SiteLock Technology&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color="#0000ff"&gt;If your ActiveX control is designed for use only on your web site, then locking it to the domain of that Web site will make it harder for other sites to repurpose the control in a malicious manner. [...]&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;La lettura completa del post di IE spero vi trasmetta anche l'importante attenzione posta alle esigenze degli amministratori di sistema di poter gestire in modo semplice e granulare tutte queste nuove opzioni tramite Group Policy e avere il pieno governo delle impostazioni correlate con la sicurezza: &lt;/font&gt;&lt;font face="Calibri" size="3"&gt;ricordate il mio motto &amp;quot;...&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2007/05/03/Lancio-di-Forefront-e-System-Center-la-sicurezza-e-nulla-senza-il-controllo.aspx" target="_blank"&gt;la sicurezza &amp;#232; nulla senza il controllo&lt;/a&gt;...&amp;quot;? &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;em&gt;&lt;u&gt;Add-on del 9 maggio 2008&lt;/u&gt;&lt;/em&gt;: come noterete dal trackback nei commenti, l'amico Renato su Technet ha ripreso ed ampliato il tema di questo mio post con un interessante &lt;a href="http://blogs.technet.com/italy/archive/2008/05/09/activex-kill-bit-disabilitazione-selettiva-degli-activex-in-internet-explorer.aspx" target="_blank"&gt;approfondimento sul Kill Bit&lt;/a&gt; (con una serie di link a risorse utili sul tema).&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx&amp;amp;;title=IE8 security: i miglioramenti negli ActiveX" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx&amp;amp;title=IE8 security: i miglioramenti negli ActiveX" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx&amp;amp;title=IE8 security: i miglioramenti negli ActiveX" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx&amp;amp;title=IE8 security: i miglioramenti negli ActiveX" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/05/08/ie8-security-i-miglioramenti-negli-activex.aspx&amp;amp;t=IE8 security: i miglioramenti negli ActiveX" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3052200" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category></item><item><title>IE8 security: DEP/NX abilitato by default</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx</link><pubDate>Thu, 17 Apr 2008 17:40:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3038692</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3038692.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3038692</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;Lo scorso evento dell'RSA Conference 2008 &amp;#232; stata anche l'occasione per incominciare a rilasciare qualche dettaglio sulle novit&amp;#224; di sicurezza di &lt;strong&gt;Internet Explorer 8&lt;/strong&gt;, che indirizzeranno principalmente la mitigazione del rischio in tre ambiti specifici di attacco: &lt;u&gt;social engineering&lt;/u&gt;, &lt;u&gt;vulnerabilit&amp;#224; lato Web server&lt;/u&gt; e &lt;u&gt;vulnerabilit&amp;#224; lato browser&lt;/u&gt;.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Il primo dettaglio di cui ha &lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx" target="_blank"&gt;trattato Eric Lawrence sul blog di IE&lt;/a&gt; &amp;#232; stata proprio la funzionalit&amp;#224; di &lt;strong&gt;Data Execution Prevention&lt;/strong&gt; (anche nota come &lt;strong&gt;No Execute&lt;/strong&gt;).&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Questa funzionalit&amp;#224; era stata introdotta con il Service Pack 2 di Windows XP per poter bloccare una serie di attacchi diretti allo sfruttamento di vulnerabilit&amp;#224; di tipo &lt;em&gt;Buffer Overrun.&lt;/em&gt; Grazie all'uso di microprocessori che supportano questa funzionalit&amp;#224; (credo che ormai lo siano quasi tutti) si riesce a impedire che un codice non autorizzato venga eseguito da una zona di memoria che sia stata marcata come adibita alla sola memorizzazione di dati, bloccando cos&amp;#236; il meccanismo alla base dell'efficacia di questo tipo di attacchi. Funzionalit&amp;#224; egregia, se non fosse che in quel momento non &amp;#232; stato possibile &amp;quot;costringere&amp;quot; tutte le applicazioni ad utilizzarla per ovvi problemi di compatibilit&amp;#224; applicativa. Cos&amp;#236; a partire da Windows XP SP2 in poi l'approccio &amp;#232; stato di tipo &lt;em&gt;opt-in&lt;/em&gt;: le applicazioni che desiderano utilizzare il DEP lo dichiarano esplicitamente, altrimenti l'impostazione predefinita &amp;#232; di avere il DEP disabilitato. Risultato: funzionalit&amp;#224; potente che potrebbe quasi azzerare i problemi di &lt;em&gt;buffer overrun&lt;/em&gt; ed &amp;#232; stata tenuta praticamente spenta!!!&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Grazie alla realizzazione di nuove API per il DEP/NX &amp;#232; stato possibile ridurre l'impatto dei problemi di compatibilit&amp;#224; applicativa ed ora si &amp;#232; riusciti ad &lt;u&gt;abilitare il DEP/NX per IE8 su Windows Vista SP1 e Windows Server 2008&lt;/u&gt;, con l'importante particolarit&amp;#224; che &lt;u&gt;i vantaggi di questa funzionalit&amp;#224; protettiva ricadono anche su tutti gli add-on che IE carica, estendendo quindi la protezione anche sul software di terze parti&lt;/u&gt;.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Trovate gli altri dettagli pi&amp;#249; tecnici nel &lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx" target="_blank"&gt;post&lt;/a&gt; che vi ho citato.&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx&amp;amp;;title=IE8 security: DEP/NX abilitato by default" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx&amp;amp;title=IE8 security: DEP/NX abilitato by default" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx&amp;amp;title=IE8 security: DEP/NX abilitato by default" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx&amp;amp;title=IE8 security: DEP/NX abilitato by default" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/04/17/ie8-security-dep-nx-abilitato-by-default.aspx&amp;amp;t=IE8 security: DEP/NX abilitato by default" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3038692" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/4.0+Application+Security/default.aspx">4.0 Application Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Internet+Explorer+Security/default.aspx">Internet Explorer Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/IE8+Security/default.aspx">IE8 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/DEP_2F00_NX/default.aspx">DEP/NX</category></item></channel></rss>