another IE weakness exposed

Heeter

Overclocked Like A Mother
Joined
Jul 8, 2002
Messages
2,732
#1
A cut 'n' paste from Bink.nu.

Critical: Moderately critical
Impact: Security Bypass

Where: From remote

Software: Microsoft Internet Explorer 6

Description:
http-equiv has identified a vulnerability in Internet Explorer, allowing malicious web sites to spoof the file extension of downloadable files.

The problem is that Internet Explorer can be tricked into opening a file, with a different application than indicated by the file extension. This can be done by embedding a CLSID in the file name. This could be exploited to trick users into opening "trusted" file types which are in fact malicious files.

Secunia has created an online test:
http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/

This has been reported to affect Microsoft Internet Explorer 6.

NOTE: Prior versions may also be affected.

Solution:
Do not use "Open" file, always save files to a folder as this reveals the suspicious filename.

Provided and/or discovered by:
http-equiv


News Source: MSFN.org


Heeter
 

Reg

eXperienced!
Joined
Mar 2, 2002
Messages
639
#2
I've seen that before back in the day with IE5. I'm surpised they haven't fixed that by now. Well, good thing I don't use IE.
 

Xie

- geek -
Joined
Sep 29, 2003
Messages
5,275
#3
How can an exploit in the day and age of spam/IRC, and other places ppl are exposed to a never ending spam of URL's, be only "Moderately critical" when they could be clicking what they think is a harmless jpg and instead is a exe that destroys everything on there computer or turns it into a DDoS zombie?
 

Members online

No members online now.

Latest posts

Latest profile posts

Perris Calderon wrote on Electronic Punk's profile.
Ep, glad to see you come back and tidy up...did want to ask a one day favor, I want to enhance my resume , was hoping you could make me administrator for a day, if so, take me right off since I won't be here to do anything, and don't know the slightest about the board, but it would be nice putting "served administrator osnn", if can do, THANKS

Been running around Quora lately, luv it there https://tinyurl.com/ycpxl
Electronic Punk wrote on Perris Calderon's profile.
All good still mate?
Hello, is there anybody in there? Just nod if you can hear me ...
Xie
What a long strange trip it's been. =)

Forum statistics

Threads
61,979
Messages
673,325
Members
89,020
Latest member
Amanda99