Bug Hunter Claims Windows Flaw Can Hide Hazards
Can hackers trick Explorer into misrepresenting file types, disguising viruses?
Joris Evers, IDG News Service
Microsoft's Windows Explorer and Web browser Internet Explorer can be tricked into masking dangerous files as innocent ones, a security specialist says.
Hackers can exploit the flaw so unknowing PC users may run arbitrary programs, potentially ruining their systems, according to Bulgarian bug hunter Georgi Guninski, a well-known Microsoft gadfly.
By adding a certain CLSID (Class Identifier) to a file name, Windows Explorer and IE will show any file extension designated by the file's creator, instead of showing an extension that accurately reflects what kind of file it is, Guninski says. CLSIDs consist of a string of numbers between curly brackets.
A file may appear to be an innocent ".txt" (text) file, but could in fact be an "HTA" (HTML Application) file, which can run programs on a PC. The damage occurs when someone double-clicks the file to open it. The malicious file could also be portrayed as any other file type, such as various graphics formats.
Disguising a Virus
The flaw could also disguise Visual Basic Script files that contain viruses. Many recent viruses, including the far-reaching Love Letter, are VBS (Visual Basic) files. Warnings about the virus caution users to not open files with the .VBS extension--but by using a CLSID, a virus-spreader could disguise a VBS file as an apparently harmless .txt file.
Guninski said he informed Microsoft of his finding on April 11. Microsoft did not return repeated calls requesting comment.
The bug hunter rates the problem as "high risk" and suggests Windows users not double-click on files in Windows Explorer or IE.
However, there's a way to identify such a masked file, a quick test shows. Windows Explorer and IE won't associate the appropriate program icon with the file. The .txt file made by Guninski for test purposes did not carry the icon for the Windows Notepad program. Also, the file's properties--displayed by right-clicking on the file name and selecting Properties from the menu--will reveal the actual file type.
Acer Laptop Center
Perfect Print Solutions
- Great year-end deals

for small business! -
Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!
-
HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!
- *Other names and brands may be claimed as the property of others. ©2009 Intel Corporation. Intel, the Intel logo, vPro and Core trademarks of Intel Corporation in the United States and other countries. All rights reserved.
Dell End of Year Deals
-
Ring in the New Year with Huge Deals on Dell Computers
Up to 30% Popular Dell Laptops, up to 25% off Popular Dell Desktops. Sales ends 12/31 5AM EST.
People who read this also read:
Best Prices on System Utilities
Parallels Desktop 4.0 for Mac (Full Product)Price: $49.99
Fusion 3Price: $69.99
Norton Partition Magic 8.0 Rev1RetailPrice: $49.99
Disk Director Suite 10.0 (Full Product)Price: $24.76
Prosoft Drive Genius 2Price: $49.88
2009 ProfessionalPrice: $29.00
- Perfect Printing Solutions Find just the right All-in-One Printer for you from HP. Visit the HP Resource Center.
- Acer Laptop Center Forget the Mouse...check out the next generation multi-gesture touch screen technology from Acer.
- Dell Shopping Center Check out great deals from Dell!
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage







