Re: Automatic MIME type detection in Internet Explorer 6.x allowed

Denis Jedig <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
Thor Larholm wrote:
> Denis Jedig wrote:
> 
>> If you change file headers to JPEGs, it's not an executable file any 
>> more - that simple. 
> 
> When the file headers are JPEG it's no longer an executable file - for 
> that specific HTTP session of that specific IEXPLORE instance.

Well, it will carry on having JPEG headers for every instance of 
IEXPLORE regardless of the HTTP sessions currently open. So how can this 
be a security problem?

> Outside 
> those constraints, you have still managed to plant an EXE file in a 
> known/predictable location on the target system.

A file named EXE but not a valid executable in itself, right? I remember 
there was some interesting work some months ago on header ambiguity but 
I can't find the reference right now.

Regards,

Denis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.