Full Disclosure mailing list archives

Re: .hta virus analysys


From: Gary Flynn <flynngn () jmu edu>
Date: Thu, 20 Nov 2003 15:50:47 -0500

Lets not all get in a tizzy about HTA. They're meant for platform
application development, not web development. They're treated just
like .exe files by IE (assuming a lack of defects - no snide
remarks necessary).

They would seem to make a nice rapid development environment for
tools for end users because of their web interface and support for
the full WSH/WMI scripting model. Kind of like TCL/tk in that respect.

Yes, that makes it easier for bad people to do bad things...but so
does the Internet, email, HTML, and perl.

Just when windows starts shipping with half-way decent tools
(WSH/WMI/HTA) like unix (sh/perl/tcl/tk) everyone runs amok about
how insecure they are. Maybe that kind of power and programmability
shouldn't be available on unmaintained, consumer computers but that
argument could be extended to cover programmable computers in
general in the same hands. People click .scr, .pif, .exe, and
all manner of other attachments every day.

The same power can be used for good too. Several organizations
wrote quick scripts to clean Blaster infections. Wrapping a browser
interface around them can make them easier for end users to use.

Whether the file in question is an HTA, exe, sh, or an unknown
type until the OS translates the MAGIC number, operators have to
learn not to click them from untrusted sources.

One wonders if everyone would yell about perl's ability to
exec system commands if we had a population of a couple hundred
million consumers running unix as root instead of windows
as administrator.

If there is an argument against HTAs other than that they create
one more less complex way to create powerful executables (for good
or bad), I'll readily admit my error. (No fair bringing up
IE defects that allow them to run in error. I believe similar
defects have allowed .exe to run too. The source of the problem
in those cases is obvious and its not in the language/script
engine.)

My politically incorrect $0.02 worth.

--
Gary Flynn
Security Engineer - Technical Services
James Madison University


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: