Vulnerability Development: Problem in IE's File Type Recognition
Problem in IE's File Type Recognition
('binary' encoding is not supported, stored as-is)
I found out one way to make Internet Explorer ver 6.0 recognize incorrectly type of any particular files.
E.g one file named "abcd.exe" is Application type but we can force the IE browser to understand that
file is "Image/JPG" or "Image/Gif" and so on ..
Currently, I'm still working to find the solution allowed us to exploit IE based on this bug.
Does any one have any suggestions?
Received on Jul 25 2006
|