RE: Security Note: File extensions spoofable in MSIE download dia log

From: Brian Cervenka (focus-ms@zerobelow.org)
Date: 12/12/01


Date: Wed, 12 Dec 2001 13:23:00 -0800 (PST)
From: Brian Cervenka <focus-ms@zerobelow.org>
To: focus-ms@securityfocus.com

Well, on a similar note, that type of thing can be done in older versions
of outlook:

Pine gives me a line where I can select a file name:
Attchmnt: 1. /home/blah/test.bat (22 B) "test.txt"

If I send this to an outlook client, the client refers to the file as
test.txt everywhere (clicking the paperclip, to open it, and such)...but,
when I click "Open this" it will actually run the batch file.

The headers when they show up at oulook are:
--1363184398-182022148-1008191960=:7769
Content-Type: TEXT/PLAIN; charset=US-ASCII; name="test.bat"
Content-Transfer-Encoding: BASE64
Content-Description: test.txt
Content-Disposition: attachment; filename="test.bat"

Now, on a fully patched version of outlook, I can no longer open the
attachment, but instead get the message:
Outlook blocked access to the following potentially unsafe attachments:
test.txt

(And this also works on .exe files, etc too)

--brian



Relevant Pages

  • Re: Read Email
    ... Outlook clients is still disappear as Unread. ... This is a known issue if you install some antivirus software on Exchange ... If this issue may related to the 3rd-party software on Outlook client ... click to check the "Hide All Microsoft Services" ...
    (microsoft.public.windows.server.sbs)
  • Re: Choose sender address through OWA
    ... You _can_ achieve this on a Outlook client (no need for ... The way I solved this is by setting up an Outlook profile with an ... profile I've added X numbers of pop accounts that really represents ... server, but you could just as well put in a fake pop server but I ...
    (microsoft.public.exchange.admin)
  • Re: public calendar not showing same results for each user...
    ... I have seen problems with numbers of events that appear before and it was a ... > I created a shared calendar in the Public Folders area for all employees ... > Outlook client for myself. ... > My outlook client displayed several more events as well (in fact the same ...
    (microsoft.public.exchange.admin)
  • Re: mail and contact sychronisation ???
    ... I'm not aware of any way to accept a meeting request other than from an Outlook client. ... >> have created ne contact and calendar entries for meeting from my>> laptop ... >>> Now open Outlook and in the Folder List, ...
    (microsoft.public.windows.server.sbs)
  • public calendar not showing same results for each user...
    ... We are using Exchange 2000 on a Windows 2000 SBS machine. ... I created a shared calendar in the Public Folders area for all employees to ... Most users are all running the Outlook 2002 cleint and she ... My outlook client displayed several more events as well (in fact the same ...
    (microsoft.public.exchange.admin)

Quantcast