|
Catch Suspicious Extensions [January 11, 2009]
|
|
Apr. 21, 2008, 11:49 PM
Post: #1
|
|||
|
|||
|
Catch Suspicious Extensions [January 11, 2009]
Code: [HTTP headers]This will catch any attempt to download files with the following extensions: hta, eml, exe, hlp, jse, lnk, url, bas, bat, com, cmd, vb, vbe, vbs, scr, shs, pif, pcd, ade, adp, anr, chm, cpl, crt, ins, isp, mdb, mde, msc, msi, msp, mst, wsf, wsh, wsc I think this will prove valuable against malicious iframe advertisements and any other method of "drive-by downloads". Previously I did not have a Content-Disposition filter. Hopefully all methods of downloading a file are now detected and "caught" with the above two filters! ![]() Screenshots: filter.jpg (Size: 230.93 KB / Downloads: 1244)
Prompt for standard, direct-link downloads f2.jpg (Size: 45.75 KB / Downloads: 1190)
Prompt for "content-disposition"-redirected downloads |
|||
The following 1 user says Thank You to Kye-U for this post:TheScaryGuy |
|
« Next Oldest | Next Newest »
|

Search
Member List
Calendar
Help







![[-]](images/ONi/collapse.gif)