bk99.de entertain the web since 1997

Another security hole in Internet Explorer

Summary

In January 2004 the security researcher “http-equiv” documented a hole in Internet Explorer on Full Disclosure through which files with fake extensions could be slipped to users. The browser did not check fake CLASSIDs, so that, for example, an HTML file disguised as a PDF was executed as HTML when opened. There was no patch yet; the only protection was to save files locally first.

Ideas

  • File extension and actual file type can differ.
  • The browser trusted a supplied class identifier instead of the content.
  • Automatically opening PDFs in the browser concealed the process.
  • Windows Explorer recognised the fake when the file was opened locally.

Insights

  • Decisions based on file extensions are a recurring point of entry.
  • Automatic convenience functions take away users’ chance to notice anything suspicious.

Facts

  • The pattern resembled a folder bug in Windows XP that had become known shortly before.
  • Microsoft offered no patch at the time of the report.

References

Critique

  • The recommended workaround of saving locally requires knowledge that average users hardly have.

Recommendations

  • Have file types checked by content rather than by extension, for example with file or protection against MIME sniffing.
  • Disable automatic opening of downloaded files in the browser.

Read the original article

Search the Web Archive