[Esd-l] Mangle Extensions

John D. Hardin jhardin at impsec.org
Thu Jun 13 13:39:00 PDT 2002

On Thu, 13 Jun 2002, Scott Taylor wrote:

> So, my question is this: if I take out the 's' from this line (beautiful 
> RegEx) of the html-trap but leave it on the only other line (L# 951) I can 
> see with 'xl', it won't get mangled, but will it still go through the macro 
> check or am I just going to break the mime type?
> MANGLE_EXTENSIONS='...|xl[swt]|...'

Change it to ...|xt[wt]|...

xls wont' get mangled, but it will still get macro-scanned and will
still be subject to filename poisoning. Office files are "special"
that way.

 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org                        pgpk -a jhardin at impsec.org
  768: 0x41EA94F5 - A3 0C 5B C2 EF 0D 2C E5  E9 BF C8 33 A7 A9 CE 76 
 1024: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
 "To disable the Internet to save EMI and Disney is the moral
  equivalent of burning down the library of Alexandria to ensure the
  livelihood of monastic scribes."
                                    -- John Ippolito of the Guggenheim
   344 days until The Matrix Reloaded

More information about the esd-l mailing list