[Esd-l] Important vulnerability to watch for in e-mail scanners/sanitizers

John D. Hardin jhardin at impsec.org
Tue Apr 2 19:47:00 PST 2002

On Tue, 2 Apr 2002, Brett Glass wrote:

> >The MS-Windows operating system on the
> >other hand disregards a dot at the end of a file name. When Windows is
> >given a file name ending with a dot, it will automatically remove the
> >dot from the file name extension. When Outlook or Outlook Express
> >receives a file name that ends with a dot, it will present the dot, but
> >will launch the appropriate application when the file is double-clicked,
> >as if the dot does not exist.

Sigh. Why does this not surprise me? I suppose it behaves the same way
with trailing spaces. Anyone care to wager?

I suppose I'll add the option to ignore or strip from filenames ANY
trailing punctuation marks or whitespace. Or rather, default to doing
so and an option to suppress that so that the sanitizer "fails

