Vulnerability Development mailing list archives

Re: Problem in IE's File Type Recognition


From: pgut001 () cs auckland ac nz (Peter Gutmann)
Date: Wed, 26 Jul 2006 16:32:30 +1200

knight4vn () yahoo com writes:

I found out one way to make Internet Explorer ver 6.0 recognize incorrectly
type of any particular files. E.g one file named "abcd.exe" is Application
type but we can force the IE browser to understand that file is "Image/JPG"
or "Image/Gif" and so on ..

Isn't this well-known?  Because so many sites incorrectly identify content, MS
made IE able to dig into content to recognise the true type in order to make
broken sites "work".  There's a config option buried somewhere deep down where
you can turn this "intelligence" off ("Open files based on content, not file
extension"), but it's enabled by default.

Peter.


Current thread: