Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors


/
Send to a friend Feedback

Guninski: IE, Windows can mask dangerous files

Related linksToday's breaking news
Send to a friendFeedback


Microsoft's Windows Explorer and Web browser Internet Explorer can be tricked into masking dangerous files as innocent ones, a security specialist said Monday.

Hackers can exploit the flaw to have unknowing computer users run arbitrary programs on their PCs, potentially ruining the systems, according to Bulgarian bug hunter Georgi Guninski, a well-known Microsoft gadfly (see his advisory).

By adding a certain Class Identifier (CLSID) to a file name Windows Explorer and IE will show the file extension given to the file by the creator, instead of the actual file extension, Guninski said. CLSIDs consist of a string of numbers between curly brackets.

A file may appear to be an innocent ".txt" (text) file, but could in fact be a ".hta" (HTML Application) file, which can execute programs on the PC. The damage is done when the user double clicks the file to open it. The malicious file could also be portraying as any other file type, like various graphics formats.

Guninski rates the problem as "high risk" and recommends Windows users not to double click on files in Windows Explorer or IE.

A masked file can be identified, a quick test showed. Windows Explorer and IE won't associate the appropriate program icon with the file. The ".txt" file made by Guninski for test purposes did not have the icon for the Windows Notepad program. Also the file's properties - displayed by right clicking and selecting "Properties" from the menu - will show the actual file type.

Exploit scenarios include leaving malicious files on shared system resources or sending them by e-mail.

Guninski said he informed Microsoft on April 11. Nobody at Microsoft was available for comment.

The IDG News Service is a Network World affiliate.

Related Links

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.