Windows Script Host - Security Concerns

Security Concerns

Windows applications and processes may be automated using a script in Windows Script Host. Viruses and malware could be written to exploit this ability. Thus, some suggest disabling it for security reasons. Alternatively, antivirus programs may offer features to control .vbs and other scripts which run in the WSH environment.

Since version 5.6 of WSH, scripts can be digitally signed programmatically using the Scripting.Signer object in a script itself, provided a valid certificate is present on the system. Alternatively, the signcode tool from the Platform SDK, which has been extended to support WSH filetypes, may be used at the command line.

By using Software Restriction Policies introduced with Windows XP, a system may be configured to execute only those scripts which have been digitally signed, thus preventing the execution of untrusted scripts.

Read more about this topic:  Windows Script Host

Famous quotes containing the words security and/or concerns:

    We now in the United States have more security guards for the rich than we have police services for the poor districts. If you’re looking for personal security, far better to move to the suburbs than to pay taxes in New York.
    John Kenneth Galbraith (b. 1908)

    The idea that nations should love one another, or that business concerns or marketing boards should love one another, or that a man in Portugal should love a man in Peru of whom he has never heard—it is absurd, unreal, dangerous.... The fact is we can only love what we know personally. And we cannot know much.
    —E.M. (Edward Morgan)