Vulnerability Development mailing list archives

Re: netscape 4.61 recognizes file.changed-doc/xls


From: dimitry () ANDRIC COM (Dimitry Andric)
Date: Thu, 25 May 2000 11:42:08 +0200


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 2000/05/23 at 11:54 Chad Thunberg wrote:

Do to the increasing threat of viruses, I have added procmail
filters to mangle the .ext of attachments so users would have to
rename the file after saving the file to disk.  This gives our
antivirus a chance to scan the file and allows users 30secs to think
about what they are doing.  What I have noticed is, netscape mail
(ver 4.61) recognizes attachments that have been renamed.  We sent
two seperate emails with attachments, one with test.doc and one with
test.xls.  Upon receiving the email, the attachment's name was
changed to test.1234DEFACED-DOC and test.1234DEFACED-XLS.  After
double clicking the attachments, netscape mail gives the user the
option of opening the file with winword.exe and excel.exe.  We also
tested with .bat and various other .ext but only winword and excel
associated files were
recognized.  Can anyone else confirm or deny this?

I think Netscape looks at the MIME types which are embedded in the
mail message headers, ie "application/msword" for doc files, and
"application/vnd.ms-excel" for xls files. It then uses the Windows
registry to look for the application which handles a specific MIME
type, and prompts the user with it.

You could try to modify your procmail filters to also mangle the MIME
types of these attachments. Just make it "application/octet-stream"
or "application/x-unknown-content-type".

Cheers,
- --
Dimitry Andric <dimitry () andric com>
PGP key: http://www.xs4all.nl/~dim/dim.asc
KeyID: 4096/1024-0x2E2096A3
Fingerprint: 7AB4 62D2 CE35 FC6D 4239 4FCD B05E A30A 2E20 96A3

-----BEGIN PGP SIGNATURE-----
Version: Encrypted with PGP Plugin for Calypso

iQA/AwUBOSznYbBeowouIJajEQJ6DgCeI5xsv20nqZbKl/wNIgCO0dhcc9sAoM3q
kvJFTYxUb4reQIPWt63QnXmD
=0FmQ
-----END PGP SIGNATURE-----


Current thread: