[Full-Disclosure] .hta virus analysys

Gadi Evron ge at egotistical.reprehensible.net
Fri Nov 21 02:02:01 GMT 2003


Jelmer wrote:
> .hta files is a proprietary concept, and only works in conjunction with Internet Explorer (specifically version 5 and above). basicly its much like a .html except it has no security restrictions
> 

If that's the case, there's only one thing not to do:
Do not enter websites that lead to you .hta files.

Some would even say use a better browser, but I wouldn't go that far.

-- 
       Gadi Evron,
       ge at linuxbox.org.

The Trojan Horses Research mailing list - http://ecompute.org/th-list

My resume (Hebrew) - http://www.math.org.il/resume.rtf

PGP key for ge at linuxbox.org -
http://vapid.reprehensible.net/~ge/Gadi_Evron.asc
Note: this key is used mainly for files and attachments, I sign email 
messages using:
http://vapid.reprehensible.net/~ge/Gadi_Evron_sign.asc





Full-Disclosure is hosted and sponsored by Secunia.