Management
Technology
- Applications
- Business Intelligence
- Development
- Hardware
- Mobile & Wireless
- Networking
- Internet
- Operating Systems
- Security Products
- Servers & Datacentre
- Storage
Toolbox
Training
Books
White Papers
Webcast
Resource Centre
May 07, 2009
Windows 7 is 'insecure', warns F-Secure
Release candidate ignores file extension threat
By Gregg Keizer
Windows 7 Release Candidate (RC) continues a long-running Microsoft practice that puts users at risk, a security researcher said on Wednesday.
Advert
The new operating system's Windows Explorer file manager still misleads users about the true extension of a file, said Patrik Runald, chief research advisor at Helsinki-based F-Secure.
Rather than reveal the full extension for a filename, Windows Explorer hides the extension for known file types, giving hackers a way to disguise malware by using those file types' extensions and icons.
Windows Explorer, for example, will show the .txt icon and display 'attack.txt' as the filename for a Trojan horse that's actually been named 'attack.txt.exe' by the hacker. The practice goes back to at least Windows NT, and has been criticised in the still-popular Windows XP and the newer Windows Vista.
"People typically look at the icon to know what the file is," said Runald. "If it looks like a Word doc or a PDF file, there's an implicit trust in it, and users are more likely to click on those files, even if they are actually an executable."
Windows, Runald continued, is smart enough to know the true nature of the file, and will, for instance, run an .exe even if the filename shows as 'attack.txt' in Explorer.
"This has been used for years by virus writers - maybe less than it used to be, since most attacks now are drive-by downloads [using browser vulnerabilities], and not email attachments," Runald noted. "But you still see it."
Microsoft should show the true filename in Explorer, urged Runald. "Bottom line, it's a still bad idea not to."
Windows 7 RC launched yesterday, and will be available for download until at least through the end of July.
Follow highlights from ComputerworldUK on Twitter
Sign up for our Daily Newsletter
The UK IT News widget Get it for your site!
« prev article | more security news | next article »
Advert
Email this article to a friend or colleague:
PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.
- This article is now being printed.
What are your views on this subject? Use the form below to post a comment on this article up to 1000 characters.
Click below to add 'Windows 7 is 'insecure', warns F-Secure - Cybercrime & Hacking - ComputerworldUK' to your blog.
If you do not have a ComputerworldUK Account and would like to use this feature, please Register.
If you are a registered, logged-in user, this will post the title and first paragraph of this story to your blog to share with your readers.
Advert








































