Experts: Windows 7 at risk from legacy flaw

By Tom Espiner, ZDNet UK
Thursday, May 07, 2009 01:07 PM

Microsoft has failed to remove a long-recognized Windows Explorer security risk from Windows 7, according to security company F-Secure.

The 'hide extensions' feature, which was present in Windows NT, 2000, XP and Vista, is included in the Windows 7 release candidate, F-Secure's chief research officer, Mikko Hyppönen, said. The feature could allow virus writers to trick users into opening and running malicious files, he added.

"In Windows NT, 2000, XP and Vista, Explorer used to Hide extensions for known file types," Hyppönen wrote in a blog post on Tuesday. "And virus writers used this 'feature' to make people mistake executables for stuff such as document files."

For example, malicious code writers could name a 'virus.exe' file as 'virus.txt.exe' or 'virus.jpg.exe', he said. Windows Explorer would then hide the .exe part of the filename, meaning that the user would only see 'virus.txt' or 'virus.jpg'. Additionally, virus writers would change the icon displayed with the file in Windows Explorer so it looked like the icon of a text file or an image. Users might then click on the disguised file.

The blog post appeared on the same day that Microsoft had been scheduled to make the Windows 7 RC1 available for download to the public, although the OS release did in fact arrive early. Microsoft made its Windows 7 release candidate available to MSDN and TechNet subscribers on 30 April.

Microsoft had not responded to a request for comment at the time of writing.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Release management: Unnecessary evil or Holy Grail?

Tech Management

Though organizations may dread these words, release management is an integral step throughout the software development process. Erica Henson explains more.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web