Re: Windows XP Explorer Executes Arbitrary Code in Folders

From: Stuart Moore (smoore.bugtraq_at_securityglobal.net)
Date: 01/26/04

  • Next message: Peter Winter-Smith: "ProxyNow! 2.x Multiple Overflow Vulnerabilities"
    Date: Mon, 26 Jan 2004 15:09:55 -0500
    To: Thor Larholm <thor@pivx.com>, bugtraq@securityfocus.com
    
    

    Thor,

    >Why don't we call a spade a spade?

    You are rather humorous! But I can be humorous, too: why don't we call a folder a folder?

    Seriously, though, the interesting part is indeed not the self execution and not the HTML
    in Local zone. The more interesting part is the HTML file as folder. Considering that
    the typical Microsoft OS user has no clue what a MIME type is (and, for that matter, does
    not know what HTML is, and doesn't know about zones), do you think that having an HTML
    file be announced by the operating system's GUI as a folder is a Good Thing or a Bad
    Thing? I would suggest that it leans more towards Idiot Engineering (http-equiv's term)
    than Trustworthy Computing (MS term).

    Stuart


  • Next message: Peter Winter-Smith: "ProxyNow! 2.x Multiple Overflow Vulnerabilities"

    Relevant Pages

    • Re: New Kid on the Block -- Help!
      ... You'll need the images so save it as html and images (but save this stuff ... just import the folder you saved your stuff in on step 1. ... > I'm very new to FrontPage with no previous training. ... of ImageReady has two main components 1) an HTML file and 2) a folder with ...
      (microsoft.public.frontpage.client)
    • Re: Turner Audio website being re-furbished.
      ... > Before you fuck up again, Patrick, a) correct the spelling of Mozart's ... > single folder. ... Then i had a lot of other html pages linked off a folder called webpgs.html, ... > ISP where your site will be available to the public. ...
      (rec.audio.tubes)
    • Re: How do I Save from MHTML .mht to HTML format only
      ... The issue was the difference between html and htm on the index folder so I ... I also notice that your host says you have to use the .html extension for ... Double check that you did indeed upload to the ...
      (microsoft.public.publisher.webdesign)
    • Re: What are these??
      ... SetupHlp.cmd that copies altsvc to the Windows\System32 ... ntdll.dll file which should be in the Windows\System32 folder, ... Only open HTML documents with Notepad. ... > There has been no apparent effect of shifting both msthost and altsvc out ...
      (microsoft.public.windowsxp.general)
    • Re: What are these??
      ... SetupHlp.cmd that copies altsvc to the Windows\System32 ... ntdll.dll file which should be in the Windows\System32 folder, ... Only open HTML documents with Notepad. ... > There has been no apparent effect of shifting both msthost and altsvc out ...
      (microsoft.public.windowsxp.perform_maintain)