Fuente:
http://www.secunia.com/advisories/10736/
Dentro de un rato intentare traducirlo, existe un enlace de
demostracion
De momento no hay solucion al respecto, se recomienda no abrir
directamente el archivo desde el enlace.
Microsoft Internet Explorer File Download Extension Spoofing
Secunia Advisory: SA10736
Release Date: 2004-01-28
Critical:
Moderately critical
Impact: Security Bypass
Where: From remote
Software: Microsoft Internet Explorer 6
Description:
http-equiv has identified a vulnerability in Internet Explorer,
allowing malicious web sites to spoof the file extension of
downloadable files.
The problem is that Internet Explorer can be tricked into opening a
file, with a different application than indicated by the file
extension. This can be done by embedding a CLSID in the file name.
This could be exploited to trick users into opening "trusted" file
types which are in fact malicious files.
Secunia has created an online test:
http://secunia.com/Internet_Explore...fing_Test/
This has been reported to affect Microsoft Internet Explorer 6.
NOTE: Prior versions may also be affected.
Solution:
Do not use "Open" file, always save files to a folder as this reveals
the suspicious filename.
Provided and/or discovered by:
http-equiv
Ille Corvus. Hic et Nunc.
Filtrado(s) (KillFile):
JM Tella Llop (25/10/2003)
Leer las respuestas