[Mimedefang] Danger of .vcs files?
Jeff Rife
mimedefang at nabs.net
Fri Oct 1 01:19:01 EDT 2004
On 30 Sep 2004 at 12:45, Jim McCullars wrote:
> Well, at the risk of exposing by backside:
>
> $bad_exts = '(bat|cmd|com|cpl|exe|hta|lnk|pif|reg|scr|shs|vb|vbe|vbs|zi)';
Ouch...there's far too many that are just as bad as those:
.INS:
Internet Settings file...can change your IE setup to use a proxy,
change to a different dial-out number, etc.
.CHM:
Compliled Help file...can have scripting, embedded EXEs, and any
number of bad things.
.ASX, .ASF:
These are *script* files for Windows Media player. They normally
just load a few .WMV (or similar) files in a row, but they can do a
*lot* more.
--
Jeff Rife |
SPAM bait: |
http://www.nabs.net/Cartoons/OverTheHedge/SlowInternet.jpg
AskDOJ at usdoj.gov |
spam at ftc.gov |
More information about the MIMEDefang
mailing list