Naziv
|
Adding a Space to a File Extension
|
Sažetak
|
An adversary adds a space character to the end of a file extension and takes advantage of an application that does not properly neutralize trailing special elements in file names. This extra space, which can be difficult for a user to notice, affects which default application is used to operate on the file and can be leveraged by the adversary to control execution.
|
Preduvjeti
|
The use of the file must be controlled by the file extension.
|
Rješenja
|
File extensions should be checked to see if non-visible characters are being included.
|