<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx</link><description>I've received some great feedback from my " Browsing the Web and Reading E-mail Safely as an Administrator, Part 2 " article, but a number of people asked how they can get started without using the tool. Here's some text I want to add to the article:</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#363994</link><pubDate>Mon, 31 Jan 2005 19:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:363994</guid><dc:creator>Kevin Marquette</dc:creator><description>I am considering doing this for my friends and family that have a hard time with spyware.  Thanks for the tip</description></item><item><title>Running IE with SAFER</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364076</link><pubDate>Tue, 01 Feb 2005 01:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364076</guid><dc:creator>.Net Security Blog</dc:creator><description /></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364102</link><pubDate>Mon, 31 Jan 2005 23:28:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364102</guid><dc:creator>Anonymous</dc:creator><description>Try running Firefox.  That's a great solution to this problem.  And best of all you don't need to hack the registry.  All you have to do is visit &lt;a target="_new" href="http://www.mozilla.org"&gt;http://www.mozilla.org&lt;/a&gt; and anyone with a brain and the ability to download software of their own accord will be able to browse the web without worrying about spyware.</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364147</link><pubDate>Tue, 01 Feb 2005 00:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364147</guid><dc:creator>Denso</dc:creator><description>I don't quite understand that last paragraph.&lt;br&gt;Let's say I'd like to run as a user, so I copy&lt;br&gt;iexplore.exe to the desktop. I have to double&lt;br&gt;click the icon to run it, but if I do, the wording&lt;br&gt;says I'm the admimistrator. Please clarify.&lt;br&gt;Thanks,&lt;br&gt;Denso</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364293</link><pubDate>Tue, 01 Feb 2005 04:57:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364293</guid><dc:creator>Michael Howard</dc:creator><description>You should read the entire article! In short, you're an admin, but want to use your browser as a user to reduce your attack profile. The SAFER policy will allow you to run the normal IE (c:\progfiles\internet explorer\iexplore.exe) as user, even though your're an admin. However, you may, for some reason want to run IE as an admin to do admin tasks. So if you copy iexplore.exe to your desktop, it's not covered by the SAFER policy so it runs as you - an admin. Does that make sense?!</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364674</link><pubDate>Tue, 01 Feb 2005 16:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364674</guid><dc:creator>JD</dc:creator><description>&lt;br&gt;Mike, will these changes make their way into Longhorn? I love the tips you are giving (essential, since I've almost abandoned IE for Opera except for intranet and secure sites) but is this driving improvements into the actual product?&lt;br&gt;&lt;br&gt;That is, will my mom have a SAFER browser and email by default? Will she know where to look/how to run the &amp;quot;unsafe&amp;quot; version?  Or are other mitigations available?&lt;br&gt;&lt;br&gt;&lt;br&gt;[aside - I run as nonadmin now at home, but I'm unusual in liking Win2k3 at home with IE lockdown as well. At work I've found it hard to work as nonadmin as the software I develop doesn't work well as nonadmin. Still at least that mainly applies to the test machine, dev machine doesn't even Office on it and has IE lockdown (2k3)]&lt;br&gt;</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#364741</link><pubDate>Tue, 01 Feb 2005 18:08:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:364741</guid><dc:creator>Michael Howard</dc:creator><description>A goal for LH is to make the normal user the default, and not make them an admin. There are a whole slew of issues we need to resolve, but the intention is to make the experience cleaner for most users!</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#367479</link><pubDate>Sat, 05 Feb 2005 00:02:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:367479</guid><dc:creator>Michael Kennedy</dc:creator><description>Hi,&lt;br&gt;&lt;br&gt;I have two comments and a question. &lt;br&gt;&lt;br&gt;First of all, thanks Michael for putting this information out there. It's very useful.&lt;br&gt;&lt;br&gt;The second comment is directed at the Firefox guy who commented &amp;quot;Try running Firefox...&amp;quot;. Does he not realize that Fire fox has holes too and when running as admin with Firefox you're in just as bad of shape? Before I get flamed for even speaking with less than high praise for Firefox, my point is that he should have taken this approach instead:&lt;br&gt;&lt;br&gt;--------------&lt;br&gt;I use firefox, so I'll be using your registry settings somewhat differently:&lt;br&gt;&lt;br&gt;Windows Registry Editor Version 5.00&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths\{effd8629-e248-4c3c-a06b-c178921c6745}]&lt;br&gt;&amp;quot;Description&amp;quot;=&amp;quot;Internet Explorer&amp;quot;&lt;br&gt;&amp;quot;ItemData&amp;quot;=&amp;quot;C:\\Program Files\\Mozilla Firefox&amp;quot;&lt;br&gt;&amp;quot;SaferFlags&amp;quot;=dword:00000000&lt;br&gt;&lt;br&gt;Thanks!&lt;br&gt;--------------&lt;br&gt;&lt;br&gt;And he whould have been browsing the web safer than before. But he didn't. His loss.&lt;br&gt;&lt;br&gt;Finally, my question: How would I take this registry entry as a template and use it to lockdown several applications. For example, I want to run the following as a regular user:&lt;br&gt;&lt;br&gt;Outlook&lt;br&gt;Web Browser&lt;br&gt;MSN Messanger&lt;br&gt;and a couple of other internet facing applications.&lt;br&gt;&lt;br&gt;Thanks again!&lt;br&gt;Michael&lt;br&gt;&lt;br&gt;</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#367600</link><pubDate>Sat, 05 Feb 2005 05:06:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:367600</guid><dc:creator>Michael Howard</dc:creator><description>Michael, you're a voice of reason in the wilderness :)&lt;br&gt;&lt;br&gt;Now to the questions, first you may want to change the description of your Firefox entry to say &amp;quot;FireFox&amp;quot; and not &amp;quot;Internet Explorer&amp;quot; :)&lt;br&gt;&lt;br&gt;Next, make sure the GUID is unique, it can be anything, just make it unique. What I do is just take a handful of the values in an existing GUID and tweak 'em!&lt;br&gt;&lt;br&gt;Next to apply to say, Outlook, just set the ItemData to the directory, or the full path to the executable, C:\Program Files\Microsoft Office\OFFICE11\outlook.exe.&lt;br&gt;&lt;br&gt;That's it :)&lt;br&gt;&lt;br&gt;</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#367615</link><pubDate>Sat, 05 Feb 2005 06:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:367615</guid><dc:creator>Michael Kennedy</dc:creator><description>Hi again,&lt;br&gt;&lt;br&gt;I realized a little after posting my last post that I had left Internet Explorer in for the description. Thanks for pointing it out.&lt;br&gt;&lt;br&gt;Ok, so change the path, description, and GUID and the registry setting will work for a different program. Great, thanks again!&lt;br&gt;&lt;br&gt;Regards,&lt;br&gt;Michael</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#369459</link><pubDate>Tue, 08 Feb 2005 23:02:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369459</guid><dc:creator>Rowdie_at_GEAC</dc:creator><description>With 2 copies of IE ( installed #1 SAFER 'basic user' and copied #2 user login credentials 'Admin') whichever ran last is the one which answers to .htm document/link association.  After wrestling with this for a couple of hours, I thought I would mention it to any of you encountering the same problem.       &lt;br&gt;Great series, Michael!  &lt;br&gt;I wouldn't have been able to get to here without PrivBar as well.  Thanks aaron_margosis!</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#371355</link><pubDate>Fri, 11 Feb 2005 21:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:371355</guid><dc:creator>rcme</dc:creator><description>This is a great article!!&lt;br&gt;&lt;br&gt;Will the policy changes work with Windows domains? This is just the solution I am looking for. I am helping a friend who has recently setup a Windows Small Business Server with about 30 users (running Windows XP SP2 desktops). He recently discovered that even though all users are in the &amp;quot;User&amp;quot; group on the Windows 2003 server, all users actually have administrator rights on their desktop computers!! He found this out the hard way, having thought the users would be limited to &amp;quot;User&amp;quot; group privileges on the desktops. The SAFER policy changes would be great for restricting access for Internet facing applications. Being able to set this with Windows 2003 Group Policy would prevent having to go to all the desktops to set this up individually. </description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#371703</link><pubDate>Sat, 12 Feb 2005 23:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:371703</guid><dc:creator>YM</dc:creator><description>Great article and very effective especially combined with PrivBar. Thanks for the tip.&lt;br&gt;&lt;br&gt;Have a question on this. I added the registry key, and IE starts as Users (according to PrivBar). But then I was trying to start MSN Messenger, the messenger prompted for a new version. When I clicked on &amp;quot;What's New&amp;quot; button, it opens an new instance of IE and running with &amp;quot;Administrator&amp;quot; according to the PrivBar. &lt;br&gt;&lt;br&gt;Is this considered a potential security problem? Or it is the expected behavior that MSN Messenger (or any window service running as Admin) can bypass this policy and start IE as Administrator?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#371791</link><pubDate>Sun, 13 Feb 2005 05:52:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:371791</guid><dc:creator>Peter Amlot</dc:creator><description>Thanks for this very useful article. I've tried running your SetSafer.exe program after installing the latest version of .Net Framework ver 2 beta but it doesn't run because the build number of .Net ver 2 is much lower than the one required to run your program. How does one get around this? &lt;br&gt;I have configured the Safer settings manually and it works beautifully. You can quickly revert to Unrestricted using mmc if you want to use Windows Update. Thank you. </description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#374234</link><pubDate>Wed, 16 Feb 2005 10:17:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:374234</guid><dc:creator>Pete Cole</dc:creator><description>I am unable to get LowRightsIE.reg to work - I've tried on two machines both running XP SP2 with all the latest patches. Logoff/logon makes no difference. I can use mmc OK and I notice that it creates a bunch of stuff under HKEY_CURRENT_USER/.../Group Policy Objects. I was wanting to write a script to take around all the machines we use (not having .NET beta 2 installed on them all).</description></item><item><title>Saferflags value</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#375462</link><pubDate>Thu, 17 Feb 2005 18:23:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:375462</guid><dc:creator>Scotty </dc:creator><description>Hey Everyone:&lt;br&gt;&lt;br&gt;This idea worked great on our computers here at our testing labs.  We just have one question though, are there any other values that can be used for the Saferflags value instead of the 00000000?  If so, what would the other values do?  Thanks for all the help!</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#375576</link><pubDate>Thu, 17 Feb 2005 21:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:375576</guid><dc:creator>Michael Howard</dc:creator><description>&amp;gt;&amp;gt;other values that can be used for the Saferflags value instead of the 00000000&lt;br&gt;&lt;br&gt;It turns out the only valid value is zero! it may be used in the future to allow for certain UI prompting, but I wouldn't hold your breath!&lt;br&gt;&lt;br&gt;</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#376063</link><pubDate>Fri, 18 Feb 2005 14:02:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:376063</guid><dc:creator>Joe</dc:creator><description>Hi,&lt;br&gt;&lt;br&gt;Interesting stuff - let's face it, everyone knows that they shouldn't run in admin, but it's such a hassle to run as user and runas / makemeadmin that most people give it up...&lt;br&gt;I'm in the middle of a war with management to allow me to remove user's admin rights, but will be guaranteed loads of calls from users who are frustrated at having their access removed creating work for me...&lt;br&gt;&lt;br&gt;Lowering IE and Outlook to user with group policy will be great...&lt;br&gt;Unfortunately, I'm having problems applying it on my W2k Server...&lt;br&gt;I've opened the policy on my XP machine, but even after applying the registry tweak of DWORD value named Levels set to 0x20000 to:&lt;br&gt;&lt;br&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft&lt;br&gt;\Windows\Safer\CodeIdentifiers&lt;br&gt;I've been finding that the basic user isn't appearing...&lt;br&gt;Also, how would I add the restricted and untrusted users to the Software Restrictions Policy?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#376143</link><pubDate>Fri, 18 Feb 2005 16:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:376143</guid><dc:creator>Scotty Inzeo</dc:creator><description>after i download and install programs that i already have associated with this file, for example AIM, when I try to uninstall it, it doesn't allow me to because of the user rights thing, is there an easy way around this?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#376145</link><pubDate>Fri, 18 Feb 2005 16:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:376145</guid><dc:creator>Scotty Inzeo</dc:creator><description>after i download and install programs that i already have associated with this file, for example AIM, when I try to uninstall it, it doesn't allow me to because of the user rights thing, is there an easy way around this?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#377242</link><pubDate>Mon, 21 Feb 2005 10:15:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:377242</guid><dc:creator>Joe</dc:creator><description>Useful stuff...&lt;br&gt;&lt;br&gt;I'm trying to implement it at Group Policy level, and I've found that I can't import the administrative template into Windows 2K server.&lt;br&gt;If I make a custom adm file to update the registry keys, will it work, or will there be conflicts with the actual policy that it setup...?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#377422</link><pubDate>Mon, 21 Feb 2005 17:27:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:377422</guid><dc:creator>Michael Howard</dc:creator><description>&amp;gt;&amp;gt;Windows 2K server&lt;br&gt;SAFER works only on WinXP and later...</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#377423</link><pubDate>Mon, 21 Feb 2005 17:28:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:377423</guid><dc:creator>Michael Howard</dc:creator><description>&amp;gt;&amp;gt;I am unable to get LowRightsIE.reg to work &lt;br&gt;really dumb question from me - how do you know it's not working?&lt;br&gt;&lt;br&gt;also, is the directory set correctly?</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#377428</link><pubDate>Mon, 21 Feb 2005 17:33:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:377428</guid><dc:creator>Michael Howard</dc:creator><description>&amp;gt;&amp;gt;Have a question on this. I added the registry key, and IE starts as Users (according to PrivBar). But then I was trying to start MSN Messenger, the messenger prompted for a new version. When I clicked on &amp;quot;What's New&amp;quot; button, it opens an new instance of IE and running with &amp;quot;Administrator&amp;quot; according to the PrivBar. &lt;br&gt;&lt;br&gt;&lt;br&gt;I'd need to find out how MSN Mgr instantiates IE - lemme find out.</description></item><item><title>There is *NO* backdoor in the XPSP2 firewall!  Why is this so hard to understand?</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#378021</link><pubDate>Tue, 22 Feb 2005 18:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:378021</guid><dc:creator>Open-node.net</dc:creator><description /></item><item><title>There is *NO* backdoor in the XPSP2 firewall!  Why is this so hard to understand?</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#378048</link><pubDate>Tue, 22 Feb 2005 18:37:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:378048</guid><dc:creator>Open-node.net</dc:creator><description /></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#379755</link><pubDate>Thu, 24 Feb 2005 18:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:379755</guid><dc:creator>Pete Cole</dc:creator><description>&amp;gt;&amp;gt; really dumb question from me - how do you know it's not working? &lt;br&gt;&lt;br&gt;I think I know because it looks to me like iexplore.exe still has administrator permissions when looked at with process explorer and I can do things with IE, like install ActiveX controls.  I can't do these things after using mmc and using process explorer iExplore doesn't have administrator.&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt; also, is the directory set correctly? &lt;br&gt;&lt;br&gt;Which directory? The path in ItemData looks right.&lt;br&gt;&lt;br&gt;I'm probably doing something incredibly dumb but I still can't find out what.&lt;br&gt;</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#381760</link><pubDate>Mon, 28 Feb 2005 19:08:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:381760</guid><dc:creator>Stefan Kanthak</dc:creator><description>Although I dislike XP (and stay with 2000) these (de-)enhancements are just good!&lt;br&gt;What's not so good are the hard coded path names:&lt;br&gt;you won't always install Windows on C;&lt;br&gt;you might have a localized version of Windows.&lt;br&gt;&lt;br&gt;So why don't you do it right:-?&lt;br&gt;The following will restrict IE and OLEXP independent of place and language.&lt;br&gt;&lt;br&gt;--- cut here ---&lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths\{EFFD8629-E248-4C3C-A06B-C178921C6745}]&lt;br&gt;&amp;quot;Description&amp;quot;=&amp;quot;Internet Explorer&amp;quot;&lt;br&gt;&amp;quot;ItemData&amp;quot;=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,49,6e,74,65,72,6e,65,74,20,45,78,70,6c,6f,72,65,72,00&lt;br&gt;&amp;quot;SaferFlags&amp;quot;=dword:00000000&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths\{EFFE51CA-369D-4A15-BA47-D465336EFCBF}]&lt;br&gt;&amp;quot;Description&amp;quot;=&amp;quot;Outlook Express&amp;quot;&lt;br&gt;&amp;quot;ItemData&amp;quot;=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,4f,75,74,6c,6f,6f,6b,20,45,78,70,72,65,73,73,00&lt;br&gt;&amp;quot;SaferFlags&amp;quot;=dword:00000000&lt;br&gt;&lt;br&gt;--- cut here ---&lt;br&gt;&lt;br&gt;The tagline REGEDIT4 is important!&lt;br&gt;The REG_EXPAND_SZ is &amp;quot;encoded&amp;quot; in ASCII here. If you use the tagline&lt;br&gt;Windows Registry Editor Version 5.00 &lt;br&gt;you'll first have to create the file in Unicode, and second have to &amp;quot;encode&amp;quot; the paths in Unicode too (which is easy here: just add ,00, after each &amp;quot;character&amp;quot;).</description></item><item><title>re: SAFER and Internet Explorer</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#382145</link><pubDate>Tue, 01 Mar 2005 06:04:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:382145</guid><dc:creator>Stefan Kanthak</dc:creator><description>After reading quite some articles on SAFER a.k.a. Software Restriction Policies I'm missing a description of the resp. registry entries.&lt;br&gt;&lt;br&gt;1. On a fresh installed XP I can only find the keys&lt;br&gt;[HKLM\...\Safer\CodeIdentifiers\0\Hashes]&lt;br&gt;with five subkeys ...\{GUID}] for some ancient MDAC and MSADC CAB files and&lt;br&gt;[HKLM\...\Safer\CodeIdentifiers\0\Paths] with one subkey ...\{GUID}] for %TIF%OLK*.&lt;br&gt;These six entries are not displayed in the SRP MMC snap-in!&lt;br&gt;&lt;br&gt;2. After creating the first policy in the SRP MMC snap-in the key&lt;br&gt;[HKLM\...\Safer\CodeIdentifiers\262144\Paths]&lt;br&gt;with 4 subkeys ...\{GUID}] allowing execution for %SystemRoot%, %SystemRoot%*.exe, %SystemRoot%System32\*.exe and %ProgramFiles% are created.&lt;br&gt;These 4 entries are shown in the snap-in.&lt;br&gt;&lt;br&gt;3. Now enter the above written *.REG:&lt;br&gt;   entries beneath ...\131072] are not shown in the snap-in.&lt;br&gt;&lt;br&gt;What's the meaning (and the supported range) of the numerical subkeys after ...\Safer\CodeIdentifiers]?&lt;br&gt;They look like &amp;quot;Levels&amp;quot; ...&lt;br&gt;&lt;br&gt;What's the criterion that entries are hidden or shown?&lt;br&gt;&lt;br&gt;And at last: bug or feature (not really:-)?&lt;br&gt;I created a deny rule for %UserProfile%. With this in effect I wasn't able to start the MMC via Start-&amp;gt;Programs-&amp;gt;Administrative Tools-&amp;gt;*.LNK, but had to enter&lt;br&gt;&amp;quot;%SystemRoot%\System32\secpol.msc /s&amp;quot;&lt;br&gt;in Start-&amp;gt;Run or a CMD window.</description></item><item><title>wlog.webbase.us &amp;raquo; safer group policy reghack</title><link>http://blogs.msdn.com/michael_howard/archive/2005/01/31/363985.aspx#4754704</link><pubDate>Wed, 05 Sep 2007 07:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4754704</guid><dc:creator>wlog.webbase.us » safer group policy reghack</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://dw.webbase.us/?p=2038"&gt;http://dw.webbase.us/?p=2038&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>