Advertisement
Promo

Security threats Toolkit

Microsoft Futures

Experts: Windows 7 at risk from legacy flaw

Tom Espiner ZDNet.co.uk

Published: 06 May 2009 12:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has failed to remove a long-recognised Windows Explorer security risk from Windows 7, according to security company F-Secure.

The 'hide extensions' feature, which was present in Windows NT, 2000, XP and Vista, is included in the Windows 7 release candidate, F-Secure's chief research officer, Mikko Hyppönen, said. The feature could allow virus writers to trick users into opening and running malicious files, he added.

"In Windows NT, 2000, XP and Vista, Explorer used to Hide extensions for known file types," Hyppönen wrote in a blog post on Tuesday. "And virus writers used this 'feature' to make people mistake executables for stuff such as document files."

For example, malicious code writers could name a 'virus.exe' file as 'virus.txt.exe' or 'virus.jpg.exe', he said. Windows Explorer would then hide the .exe part of the filename, meaning that the user would only see 'virus.txt' or 'virus.jpg'. Additionally, virus writers would change the icon displayed with the file in Windows Explorer so it looked like the icon of a text file or an image. Users might then click on the disguised file.

The blog post appeared on the same day that Microsoft had been scheduled to make the Windows 7 RC1 available for download to the public, although the OS release did in fact arrive early. Microsoft made its Windows 7 release candidate available to MSDN and TechNet subscribers on 30 April.

Microsoft had not responded to a request for comment at the time of writing.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
3 out of 3 people found this useful


More in this Special Report

Windows 7 — as good as it gets

Windows 7 — as good as it gets

Microsoft's latest version of Windows looks solid and useful. But it's no guide to the future of IT — or Microsoft more

Windows 7 RC1 made available for download

Windows 7 RC1 made available for download

Some features have been dropped since the beta version, but Microsoft has decided to allow the release candidate version to stay functional for more than a year more

Internet Explorer 8: screenshot gallery

Internet Explorer 8: screenshot gallery

Internet Explorer 8 is now available for download. Here's a gallery showing some of its new features more

Leader: Microsoft's mobile strategy has gone missing

Leader: Microsoft's mobile strategy has gone missing

Enterprise mobile technology advances on all fronts, except one. Microsoft needs to make its strategy plain more

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Many businesses have given Vista a wide berth. Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner more

Ozzie: Success of Azure comes down to trust

Ozzie: Success of Azure comes down to trust

In an interview, Ray Ozzie says businesses will be taking a risk by placing core operations in Microsoft's datacentre, but that the software giant has more to lose if things go bad more

Photos: A screenshot tour of Microsoft's Windows 7 RC1

Photos: A screenshot tour of Microsoft's Windows 7 RC1

A look at the release candidate of Windows 7 that was released to the public by Microsoft on Thursday more

Microsoft: Many Windows 7 features can be disabled

Microsoft: Many Windows 7 features can be disabled

Customers will have the option of disabling a number of features of the operating system, should they so choose more

Microsoft's secret deals on open source

Microsoft's secret deals on open source

Microsoft has been building a portfolio of open-source licence deals. It still prefers secrecy more

Microsoft unveils Office apps in the browser

Microsoft unveils Office apps in the browser

At the Professional Developers Conference, the software maker gave a preview of its newly confirmed browser-based Office apps more

Microsoft offers details on forthcoming app store

Microsoft offers details on forthcoming app store

The software maker says developers who want to sell via the Windows Marketplace for Mobile will pay $99 a year and get to keep 70 percent of the proceeds more

Microsoft: No second beta of Windows 7

Microsoft: No second beta of Windows 7

The first beta version of the successor to Windows Vista is available more

Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters