4.9 • 696 Ratings
🗓️ 25 June 2020
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, June 25th, 2020 edition of the Sandtonet Stormsterners Stormcast. My name is Johannes Ulrich. |
0:09.1 | And then I'm recording from Jacksonville, Florida again. |
0:12.9 | In today's diary, we have Jan again introducing us to an interesting little Windows bug or behavior, and that's around link files. |
0:25.8 | Now, link files and Windows are, of course, vastly different from sim links or hardlinks on |
0:31.4 | Unix in that there are actual files and there are multiple parameters that you can list within the file. |
0:40.2 | One of them is the location of the icon to display for the particular file. |
0:47.0 | So, okay, what can you do with this? |
0:48.8 | Well, it turns out that the location can also be a URL. |
0:53.1 | So you can point it to a remote file and that file will be downloaded. |
0:59.9 | The only limitation is that the end of the URL has to be dot ICO, the short for icon. |
1:07.2 | But that's the end of the URL, not the end of the file name that you are downloading. |
1:14.5 | So all you have to do to hit an arbitrary URL is just add question mark, some parameters. |
1:21.5 | Dot ICO, and yes, it will work. |
1:24.0 | It will download the file. |
1:26.3 | And Jan is going over a couple of scenarios how this could potentially be used maliciously. |
1:32.7 | In order to trigger this issue, the user just has to look at a directory listing that contains the malicious link file. |
1:41.8 | So one way how Jan suggests this could be exploited is if the user receives a link file. So one way how Jan suggests this could be exploited is if the user receives |
1:48.1 | an email with a zip file as an attachment unsips it and then just within that zip file, |
1:54.7 | there is the malicious link file that would trigger this particular problem. |
2:00.4 | And we've got a number of vulnerabilities and patches to talk about. |
2:05.6 | First of all, on Monday, Google released an update for Chrome fixing two vulnerabilities. |
2:12.6 | Secondly, QNAP released an update for its network storage devices, in particular the Helpdesk application |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.