Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Problem in IE's File Type Recognition

Re: Problem in IE's File Type Recognition

From: Peter Gutmann <pgut001_at_cs.auckland.ac.nz>
Date: Wed, 26 Jul 2006 16:32:30 +1200

knight4vn_at_yahoo.com writes:

>I found out one way to make Internet Explorer ver 6.0 recognize incorrectly
>type of any particular files. E.g one file named "abcd.exe" is Application
>type but we can force the IE browser to understand that file is "Image/JPG"
>or "Image/Gif" and so on ..

Isn't this well-known? Because so many sites incorrectly identify content, MS
made IE able to dig into content to recognise the true type in order to make
broken sites "work". There's a config option buried somewhere deep down where
you can turn this "intelligence" off ("Open files based on content, not file
extension"), but it's enabled by default.

Peter.
Received on Jul 26 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos