Re: Double clicking on innocent looking files may be dangerous

From: Gary Flynn (flynngnat_private)
Date: Tue Apr 17 2001 - 06:25:42 PDT

  • Next message: secureat_private: "[CLA-2001:393] Conectiva Linux Security Announcement - netscape"

    Verified on NT SP6 Workstation with all NeverShowExt values
    removed from registry. I used an existing HTA file and just
    added the extension. Side notes:
    
    1) Right-clicking and selecting "rename" will not show the
       CLSID extension.
    
    2) Type shows as "HTML Application" in detailed view and properties.
    
    3) File doesn't show up in File dialog when trying to open it
       for editing in Notepad with "display all files selected". Had
       to create a shortcut which did show up in the File dialog and
       was editable.
    
    4) Netscape Messenger 4.76 and Outlook Express 5.00.2919.6600 show
       attachment as something other than a simple .txt file depending
       upon how it was sent (send-to Messenger, send-to MAPI. File did
       not display in File dialog when trying to attach within mail
       client). Mulberry shows it as a .html.
    --
    Gary Flynn
    Security Engineer - Technical Services
    James Madison University
    
    Please R.U.N.S.A.F.E.
    http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml
    



    This archive was generated by hypermail 2b30 : Tue Apr 17 2001 - 10:38:27 PDT