Win7/Vista e-mail malware - unicode tricks...
- http://www.theinquir...lename-trickery
May 13 2011 - "... Windows PC users have been warned about malware Trojans that camouflage malicious executable files using a fancy unicode trick*. Unicode is a computing industry standard that provides a unique number for every character you use, no matter what system you are using. With malicious trickery, criminals have worked out how to fiddle with unicode so that some characters in a Windows filename can be reversed. Security firm Norman* found malicious email attachments that appeared on the surface to have filenames with standard alphabetical characters, with unicode-capable viewers seeing nothing out of the ordinary. However, if you look at the file from a command prompt, it shows that the last bit of the filename has actually been reversed, and that this seemingly innocuous emailed file is actually an executable.
Norman tested other filenames, and found that the same unicode trick allowed files to hide the fact that they were executable in the email client Lotus Notes. The firm said that any filename could hide extensions like PDF and EXE using the trick.
The firm said that the issue only affects Windows Vista and Windows 7 users, as Windows XP users have to install support for right-to-left languages in order to be vulnerable..."
* http://norman.com/se...lo_unicode_hole
> http://www.h-online....iew=zoom;zoom=3
Edited by AplusWebMaster, 13 May 2011 - 03:39 PM.