Advertisement
Promo

Security threats Toolkit

Story: Experts: Windows 7 at risk from legacy flaw

  • Previous comment

Posted by: knapper (Saturday 9 May 2009, 2:50 PM)

  • Reply

Your missing the point

-----
"This sort of proves my point, you saw the whole extension."

So the point I've really demonstrated is that seeing the whole file name is a really Good Idea and that hiding the extension is a Bad Thing. (GNU/Linux boxes don't hide file extensions, of course.) I only mentioned this at all because it was a genuine piece of malware that I had received recently that was actively trying to leverage this odious feature of Windows.
----

What you've demenstrated is that someone who is techincally savy spotted the extension and understood it's meaning, I'm not saying that's not the case.

-----
"There are are a heck of a lot of users out there who understand a little bit about extensions, spot pdf and think "oh thats alright it's a pdf" and don't understand the significance of the following extension."

Rubbish. Have you ever seen a malware file named xxxpdf.exe, pdf.xxx.exe or xxxpdfxxx.exe? These files are consistently named xxx.pdf.exe in order to leverage Windows "extension hiding" capabilities.
-----

Chris, this is not rubbish, it's a fact that I have experience of. I don't appreciate being called a liar. If you want to have a debate we can, but only if you can maintain it sensibly. My point is that many users understand that an extension is a dot followed by something else, they don't really have a good understanding of it though, hence my point about phishing.

knapper

knapper
IT Consultant, Wear Valley, County Durham
Member since: January 2004

Site Activity Rating:

1

 


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters