OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] .hta virus analysys

From: Nick FitzGerald (nickvirus-l.demon.co.uk)
Date: Wed Nov 19 2003 - 22:28:46 CST


bryce <lord_phcomcast.net> wrote:

> I'm new to this list, and sorta new to security on a computer. But can
> someone tell me what program runs a .hta file??

If you have to ask that then you really shouldn't even be thinking of
"playing with it" should you?

I suggest that this is an example of a very good reason to _not_ allow
messages with such attachments (though having the mail server
distinguish them from other "possibly acceptable" atatchments such as C
or PERL PoCs and the like would be non-trivial...).

Regards,

Nick FitzGerald

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html