[Esd-l] Triple extensions

Brett Glass brett at lariat.org
Tue Feb 4 18:48:43 PST 2003


At 02:44 PM 2/4/2003, John D. Hardin wrote:

>The attachment filename must be "carefully crafted" (your example
>above won't work). 

Any information on HOW it must be crafted? Given the bugginess
of Outlook, one might not need to be that careful. ;-)

My own sanitizer now handles any number of extensions and checks
every one of them for executability.

--Brett



More information about the esd-l mailing list