[Mimedefang] Danger of .vcs files?

Jeff Rife mimedefang at nabs.net
Fri Oct 1 01:19:01 EDT 2004


On 30 Sep 2004 at 12:45, Jim McCullars wrote:

>    Well, at the risk of exposing by backside:
> 
> $bad_exts = '(bat|cmd|com|cpl|exe|hta|lnk|pif|reg|scr|shs|vb|vbe|vbs|zi)';

Ouch...there's far too many that are just as bad as those:

.INS:
  Internet Settings file...can change your IE setup to use a proxy,
  change to a different dial-out number, etc.

.CHM:
  Compliled Help file...can have scripting, embedded EXEs, and any
  number of bad things.

.ASX, .ASF:
  These are *script* files for Windows Media player.  They normally
  just load a few .WMV (or similar) files in a row, but they can do a
  *lot* more.



--
Jeff Rife        |  
SPAM bait:       | 
http://www.nabs.net/Cartoons/OverTheHedge/SlowInternet.jpg 
AskDOJ at usdoj.gov |  
spam at ftc.gov     |  




More information about the MIMEDefang mailing list