Advertisement
Promo

Security threats Toolkit

Story: Experts: Windows 7 at risk from legacy flaw

  • Previous comment

Posted by: Chris Rankin (Thursday 7 May 2009, 1:32 PM)

  • Reply

I saw the whole extension because I use GNU/Linux

"This sort of proves my point, you saw the whole extension."

So the point I've really demonstrated is that seeing the whole file name is a really Good Idea and that hiding the extension is a Bad Thing. (GNU/Linux boxes don't hide file extensions, of course.) I only mentioned this at all because it was a genuine piece of malware that I had received recently that was actively trying to leverage this odious feature of Windows.

"The virus writers believe that by sticking .pdf somewhere in the file name is good enough."

Only if the true .HTM extension gets hidden...

"There are are a heck of a lot of users out there who understand a little bit about extensions, spot pdf and think "oh thats alright it's a pdf" and don't understand the significance of the following extension."

Rubbish. Have you ever seen a malware file named xxxpdf.exe, pdf.xxx.exe or xxxpdfxxx.exe? These files are consistently named xxx.pdf.exe in order to leverage Windows "extension hiding" capabilities.

"I haven't read Adrian Kingsley-Hughes blog"

It's not a long blog, and I did provide the link...

Private message disabled

Chris Rankin

Chris Rankin
Applications Development, UK
Member since: October 2006

Site Activity Rating:

4

This member is ranked #30 in our top 100


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Security Videos by Industry Leaders

The Academy Pro presents vendor and open source security products in video format. The 500+ free videos cover everything from firewalls, penetration testing, IDS/IPS to NAC and anti-spam.... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters