Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: .com

Re: .com

From: Nexus <nexus_at_patrol.i-way.co.uk>
Date: Tue, 2 Oct 2001 17:30:20 +0100

Possibly if the level of stupidity were high enough that attachments are
blindly clicked on ;-)
Explorer will still use the icon for an com file which may be noticed, the
MZ tag in the exe will still flag is as an executable for anything what is
watching (AV/Content Filtering/Sandboxing) since they are usually(;-) smart
enough to look at the file header, not the extension. I know that a true
old-fashioned .COM file has no such header as the ORG is set at 0x100, hence
no real loader as it doesn't have to adjust the segements, but chances of
getting that to run on a Win32 system ?
By clients I am assuming that you mean email clients and the like, or do you
mean people ?
Your attachment has zero length and so does nothing, not quite sure what you
are saying....
Could you explain a bit more ?

Cheers.

----- Original Message -----
From: "Pauli Ojanperä" <pasaojan_at_cc.jyu.fi>
To: <vuln-dev_at_securityfocus.com>
Sent: Tuesday, October 02, 2001 8:10 AM
Subject: .com

> dunno if this has already occurred in people's mind but
> as there is the nice similarity between the ancient .com
> executable file extension and the tld .com ignorant
> clients could be fooled by sending executables that
> are named after popular .com www-sites. clear enough?-)
>
Received on Oct 02 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos