republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Another IE Exploit » Scary!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
IE all the way »
« Great slashdot quotes  
AuthorAll Replies

tc17

join:2003-08-14
reply to bokamba
Re: Scary!

I must be missing something, because when I use IE to open this file, it opens it as an html file. When I use Mozilla Firebird, it wants to open it as an html file also.


Nam Vet
Premium
join:2001-12-03
Allentown, PA


2 edits
Click for full size
I E 6
Click for full size
FIREBIRD
I'll say your missing something!
yes it is a html file but you are led to believe its a pdf!

it's the download dialog box that is not letting you know the correct file type!
if you chose to open this file thinking its a pdf does acrobat reader open? NO!!!

Although if you download the file (at least in the case of this exploit demo) and then try to open it windows now thinks its a pdf because of its extension.

so after downloading it when you try to open it acrobat reader opens but you get an error message either because its zero bytes or because its an html file.

If the demo actually was not zero bytes and you did download an html file either windows explorer would append the correct extension to the file(maybe) or if it still said it was a pdf then acrobat would try to open it but you would get an error message (from acrobat reader) that the file was an invalid format.

using a zero byte file for this demo was not the right thing to do, however the demo is correct in pointing out that the IE download dialog box shows an incorrect extension or does not reveal (NOTE THE EMPTY "FILE TYPE" LINE) The correct file type

btw using firebird is not the same thing!
it's download dialog box lets you know its an html file!
--
H O W T R U E : If you want something done, ask a busy person to do it
Forums » Another IE ExploitIE all the way »
« Great slashdot quotes  


Saturday, 05-Dec 08:43:46 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [92] The Bandwidth Hog Does Not Exist
· [84] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· DNS options, what are YOU using? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· UPS - What do you people think happened? [General Questions]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· Road Runnner up to 50 mbps is ready ! [Road Runner]
· [Wireless] Linksys WMP54g v4.1 and Windows 7 x64 [Linksys]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]