Author: Amxking
Vulnerability system: win Series
Vulnerability Type: Extension Spoofing Vulnerability
Vulnerability Description: uses the extension spoofing vulnerability to spread Trojans and virus programs in disguise.
This day, I learned how to send a rar.txt file to me. The suffix is a TXT file, which is actually a rarfile. I analyzed the vulnerability that exploits the WIN extension. If this vulnerability is exploited to spread Trojans, netizens with low security awareness receive jpg Icon files and the file name suffix is also jpg. It is very likely that I want to be clicked to run them, hackers can exploit this vulnerability to spread EXE Trojans or virus programs!
Vulnerability exploitation: Add a 3F extension before the extension and a disguised extension (it seems that this is not a problem)
Vulnerability Analysis: reverse the file name. WIN First reads the suffix and then discards the suffix to play a spoofing effect.
Amxking: The real file name is named aktxt.rar! Thank you for your suggestions!
Using animations: html "> http://hi.baidu.com/qhack8/blog/item/2cd7da6cc5664ad781cb4ad7.html