<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Still more on WMA and spyware</title>
	<atom:link href="http://www.edbott.com/weblog/?feed=rss2&#038;p=342" rel="self" type="application/rss+xml" />
	<link>http://www.edbott.com/weblog/?p=342</link>
	<description>Helping PC users make sense of Microsoft software since 1991</description>
	<lastBuildDate>Fri, 20 Nov 2009 18:54:09 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Andrew Clover</title>
		<link>http://www.edbott.com/weblog/?p=342&#038;cpage=1#comment-595</link>
		<dc:creator>Andrew Clover</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=342#comment-595</guid>
		<description>&gt; That&#039;s an automatic update from Windows Media Player. It&#039;s not served up as HTML, and it looks completely different.

Maybe under SP2 (haven&#039;t managed to test this; probably SP2 already has the required DRM stuff concerned built-in), but in my test with stock-XP the automatic update confirmation box was exactly the same design as the ActiveX download box.

&gt; Microsoft should release a WMP patch that disables all ActiveX functionality in the instance of Internet Explorer that is hosted by the License Acquisition dialog box.

I agree. It would have to cover any pop-ups opened from the hosted box too (not sure if this would happen by default).</description>
		<content:encoded><![CDATA[<p>> That&#8217;s an automatic update from Windows Media Player. It&#8217;s not served up as HTML, and it looks completely different.</p>
<p>Maybe under SP2 (haven&#8217;t managed to test this; probably SP2 already has the required DRM stuff concerned built-in), but in my test with stock-XP the automatic update confirmation box was exactly the same design as the ActiveX download box.</p>
<p>> Microsoft should release a WMP patch that disables all ActiveX functionality in the instance of Internet Explorer that is hosted by the License Acquisition dialog box.</p>
<p>I agree. It would have to cover any pop-ups opened from the hosted box too (not sure if this would happen by default).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Bott</title>
		<link>http://www.edbott.com/weblog/?p=342&#038;cpage=1#comment-596</link>
		<dc:creator>Ed Bott</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=342#comment-596</guid>
		<description>SP2 does not have the DRM stuff built in. This is a feature of WMP. I&#039;ll take some screen shots to show the difference.

As for &quot;stock XP&quot; versus SP2, anyone who has not installed SP2 is simply asking for trouble. The improvements are so profound and far-reaching that the only excuse for not installing this update is if you are in a coporate environment that is adequately protected by other measures and has compatibility issues with mission-critical applications.

With SP2 installed, any pop-ups opened by the License Acquisition dialog box would be subject ot all the security protections I listed earlier, including blocking of ActiveX controls.

As far as I am concerned, no one running Windows XP should even think about using a P2P file-sharing service without SP2 installed. (Of course, I don&#039;t think any sane person should use Kazaa or Grokster at all, but that&#039;s a topic for another day.)</description>
		<content:encoded><![CDATA[<p>SP2 does not have the DRM stuff built in. This is a feature of WMP. I&#8217;ll take some screen shots to show the difference.</p>
<p>As for &#8220;stock XP&#8221; versus SP2, anyone who has not installed SP2 is simply asking for trouble. The improvements are so profound and far-reaching that the only excuse for not installing this update is if you are in a coporate environment that is adequately protected by other measures and has compatibility issues with mission-critical applications.</p>
<p>With SP2 installed, any pop-ups opened by the License Acquisition dialog box would be subject ot all the security protections I listed earlier, including blocking of ActiveX controls.</p>
<p>As far as I am concerned, no one running Windows XP should even think about using a P2P file-sharing service without SP2 installed. (Of course, I don&#8217;t think any sane person should use Kazaa or Grokster at all, but that&#8217;s a topic for another day.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Clover</title>
		<link>http://www.edbott.com/weblog/?p=342&#038;cpage=1#comment-597</link>
		<dc:creator>Andrew Clover</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=342#comment-597</guid>
		<description>Hmm... that WMP9 dialogue is not the box I was talking about. I think it *was* actually a downloader for the WM9 codecs (as I was using stock XP it only had WMP 7), which is the normal style of ActiveX downloader window.</description>
		<content:encoded><![CDATA[<p>Hmm&#8230; that WMP9 dialogue is not the box I was talking about. I think it *was* actually a downloader for the WM9 codecs (as I was using stock XP it only had WMP 7), which is the normal style of ActiveX downloader window.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Bott</title>
		<link>http://www.edbott.com/weblog/?p=342&#038;cpage=1#comment-598</link>
		<dc:creator>Ed Bott</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=342#comment-598</guid>
		<description>My mistake. I put WMP 9 in the text without checking. That was a clean install of Windows XP RTM, which actually includes Windows Media Player 8 for Windows XP (version 8 was never released for any other Windows version, IIRC). I&#039;ve corrected the post. I didn&#039;t get prompted to download any additional codecs when testing this file.

There are actually three different styles of ActiveX downloader. The first came with XP RTM, the second (cleaner, easier to read) with SP1, and the third with SP2.

I honestly don&#039;t see the point of testing any of these infected files on a version of Windows XP with no service packs installed. In that configuration you can be infected by all sorts of viruses and worms, in the preview pane of a message window or even over an open Internet connection a la blaster. Anyone who&#039;s running without SP1 or SP2 will be infected with something before too long.</description>
		<content:encoded><![CDATA[<p>My mistake. I put WMP 9 in the text without checking. That was a clean install of Windows XP RTM, which actually includes Windows Media Player 8 for Windows XP (version 8 was never released for any other Windows version, IIRC). I&#8217;ve corrected the post. I didn&#8217;t get prompted to download any additional codecs when testing this file.</p>
<p>There are actually three different styles of ActiveX downloader. The first came with XP RTM, the second (cleaner, easier to read) with SP1, and the third with SP2.</p>
<p>I honestly don&#8217;t see the point of testing any of these infected files on a version of Windows XP with no service packs installed. In that configuration you can be infected by all sorts of viruses and worms, in the preview pane of a message window or even over an open Internet connection a la blaster. Anyone who&#8217;s running without SP1 or SP2 will be infected with something before too long.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: laura</title>
		<link>http://www.edbott.com/weblog/?p=342&#038;cpage=1#comment-599</link>
		<dc:creator>laura</dc:creator>
		<pubDate>Wed, 31 Dec 1969 17:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.edbott.com/wordpress/?p=342#comment-599</guid>
		<description>How do I delete these unwanted files!  They are write-protected.

Laura
</description>
		<content:encoded><![CDATA[<p>How do I delete these unwanted files!  They are write-protected.</p>
<p>Laura</p>
]]></content:encoded>
	</item>
</channel>
</rss>
