Full Disclosure mailing list archives
Re: .hta virus analysys
From: Gary Flynn <flynngn () jmu edu>
Date: Thu, 20 Nov 2003 15:50:47 -0500
Lets not all get in a tizzy about HTA. They're meant for platform application development, not web development. They're treated just like .exe files by IE (assuming a lack of defects - no snide remarks necessary). They would seem to make a nice rapid development environment for tools for end users because of their web interface and support for the full WSH/WMI scripting model. Kind of like TCL/tk in that respect. Yes, that makes it easier for bad people to do bad things...but so does the Internet, email, HTML, and perl. Just when windows starts shipping with half-way decent tools (WSH/WMI/HTA) like unix (sh/perl/tcl/tk) everyone runs amok about how insecure they are. Maybe that kind of power and programmability shouldn't be available on unmaintained, consumer computers but that argument could be extended to cover programmable computers in general in the same hands. People click .scr, .pif, .exe, and all manner of other attachments every day. The same power can be used for good too. Several organizations wrote quick scripts to clean Blaster infections. Wrapping a browser interface around them can make them easier for end users to use. Whether the file in question is an HTA, exe, sh, or an unknown type until the OS translates the MAGIC number, operators have to learn not to click them from untrusted sources. One wonders if everyone would yell about perl's ability to exec system commands if we had a population of a couple hundred million consumers running unix as root instead of windows as administrator. If there is an argument against HTAs other than that they create one more less complex way to create powerful executables (for good or bad), I'll readily admit my error. (No fair bringing up IE defects that allow them to run in error. I believe similar defects have allowed .exe to run too. The source of the problem in those cases is obvious and its not in the language/script engine.) My politically incorrect $0.02 worth. -- Gary Flynn Security Engineer - Technical Services James Madison University _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- .hta virus analysys Jim Duggan (Nov 19)
- Re: .hta virus analysys bryce (Nov 19)
- Re: .hta virus analysys Nick FitzGerald (Nov 19)
- Re: .hta virus analysys madsaxon (Nov 19)
- Re: .hta virus analysys Valdis . Kletnieks (Nov 19)
- Re: .hta virus analysys listas (Nov 21)
- Re: .hta virus analysys Maxime Ducharme (Nov 20)
- Re: .hta virus analysys Scott Taylor (Nov 20)
- Re: .hta virus analysys Gary Flynn (Nov 20)
- Re: .hta virus analysys Jelmer (Nov 20)
- Re: .hta virus analysys Nick FitzGerald (Nov 20)
- Re: .hta virus analysys Nick FitzGerald (Nov 19)
- Re: .hta virus analysys bryce (Nov 19)
- Re: .hta virus analysys Gadi Evron (Nov 20)
- <Possible follow-ups>
- Re: .hta virus analysys Feher Tamas (Nov 20)
- Re: .hta virus analysys http-equiv () excite com (Nov 21)