Great Circle Associates Firewalls
(August 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: browserphobia
From: "Marcus J. Ranum" <mjr @ iwi . com>
Organization: Information Works! Inc, Baltimore, MD
Date: Sat, 12 Aug 1995 21:03:29 -0400 (EDT)
To: long-morrow @ CS . YALE . EDU
Cc: firewalls @ GreatCircle . COM, fsenter @ mail . more . net
Coredump: Infocalypse Now!!!
In-reply-to: <199508122302 . TAA15722 @ SPARKY . CF . CS . YALE . EDU> from "long-morrow @ CS . YALE . EDU" at Aug 12, 95 07:02:24 pm
Phone: 410-889-8569
Reply-to: mjr @ iwi . com
Url: <A HREF="http://iwi.com/mjr/mjr-top.html">mjr's web page</A>

>Another problem is with unsafe PostScript interpreters, since many 
>people set up their browser to invoke a PostScript viewer automatically
>on downloaded PostScript files ( ie. <A HREF=virus.ps>View Report</A> )

	...Or just about anything that is a higher-level language.
You can pull down MS-Word .doc files via Netscape on a PC and it
will invoke Word on them. There's a pop-up that says, "Warning,
this may be an unsafe interpreter..." win a check box saying, "don't
bother me with this again."  -- I'm sure a lot of people check that
off. The problem is that you can't *TELL* if it's an unsafe document
or an OK one until you RUN it. For those that don't use Word, it
contains a complete BASIC interpreter, with file operations and the
whole bit.

	Let's keep perspective, though: there are many more avenues
by which such nonsense can get to you, than simply over the 'net.
Solving this kind of attack is a difficult problem with potentially
intrusive solutions. [Before one of the "B1 is GREAT" crowd chimes
in and comments that if everyone ran B1 we wouldn't have this
problem: Give me a break.]

mjr.


Follow-Ups:
References:
Indexed By Date Previous: The Australian crypto paper that is causing the fuss
From: Craig Bishop <csb @ connect . com . au>
Next: IP Filter update.
From: Darren Reed <avalon @ coombs . anu . edu . au>
Indexed By Thread Previous: Re: browserphobia
From: long-morrow @ CS . YALE . EDU
Next: Re: browserphobia
From: "Frank K. Senter" <fsenter @ mail . more . net>

Google
 
Search Internet Search www.greatcircle.com