Security message with opening an exe file...

imported_Somnus

Junior Member
May 15, 2004
9
0
0
Everytime I goto open an exe file after installing SP2 I get the following popup:

Screen Shot

Does anyone know how to get rid of it?

I have tried unclicking the little box, removed the security center via services, and looked in the security policy editor. Nothing seems to get rid of this thing.

Any help would be greatly appreciated.

 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
When you download a file from an untrusted zone using IE, it attaches an alternate data stream (a cool feature of NTFS) to the file, noting that the file came from an untrusted source. When you run the file using various apps (explorer, some SP2-aware apps), you get warned. There is some work going on to add support for this to Mozilla.

edit: And no, I don't know how to disable it .
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: CTho9305
When you download a file from an untrusted zone using IE, it attaches an alternate data stream (a cool feature of NTFS) to the file, noting that the file came from an untrusted source. When you run the file using various apps (explorer, some SP2-aware apps), you get warned. There is some work going on to add support for this to Mozilla.

edit: And no, I don't know how to disable it .

Add the sites you download from to your trusted zone (or write an app to set the zone id in the ads.. )

Bill
 

drag

Elite Member
Jul 4, 2002
8,708
0
0
Is it true that the ADS stuff was originally made to support HFS (apple filing system) files?

One of the nicer features of ADS, as I understand it, is that you can embed executable files and scripts into otherwise innocuious files... (like a normal text file), and it's not detectable by normal file system utilities..

Does SP2 do anything to fix this?
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Is it true that the ADS stuff was originally made to support HFS (apple filing system) files?

It was originally implemented to solve a number of issue, but yes, HFS compatibility (specifically MAC resource forks) where one of them.

One of the nicer features of ADS, as I understand it, is that you can embed executable files and scripts into otherwise innocuious files... (like a normal text file), and it's not detectable by normal file system utilities.. Does SP2 do anything to fix this?

There is nothing to fix, the file system is working like documented. Saying it's not detectable isn't really true, you have to enumerate the data streams not not presume that only the default data stream is the only present. For AV purposes, those streams are scanned if they are launched. Short of the user directly lauching them there needs to be some bootstrap code in the default data stream that would load and transfer control to the ADS. So, by scanning the default stream you can find those attacks.

People have used the ability to 'hide' data on the file system, but there are plenty of utilities that will show you what is really there.

Bill
 

Psych

Senior member
Feb 3, 2004
324
0
0
Several bugs were described with this new SP2 feature that could disable it, but who knows, Microsoft might actually fix the bugs.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |