lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <43B428EB.9070904@csuohio.edu> Date: Thu Dec 29 18:20:38 2005 From: michael.holstein at csuohio.edu (Michael Holstein) Subject: test this > Mix in a generous helping of 'type sniffing' by MS so that you can name > WMF files .gif or .jpg or some other random suffix and you have one hell > of a problem that can only really be completely fixed by MS releasing a > patch to kill execution of embedded executable code in WMF files. Has anyone tested the renamed .wmf -> .jpg trick and embedding the image in a HTML email (using Outlook, et.al) ? That'd make it even nastier. /mike.