|
Brought to you by:
Suppliers of:
|
|
|
| |
| ZoneAlarm Pro contains a feature called MailSafe. This is an email attachment protection for the home and cooperate users, which automatically renames dangerous extensions to a harmless one (.zl*). A security vulnerability in the product allows attackers to bypass this protection by attaching a file with a very long name. |
| |
Credit:
The information has been provided by bacano.
|
| |
Vulnerable systems:
ZoneAlarm Pro version 2.6.84 and prior
MailSafe is a feature of ZoneAlarm Pro. MailSafe identifies potentially harmful files (for example: *.exe, *.com, *.reg, *.vbs or others that can be added in the configuration screen) in e-mail attachments and renames their extension to *.zl* in addition to showing an alarm box to inform the user about this.
The problem with this feature is that it does not work with long file names, for example:
<<zonetestzonetestzonetestzonetestzonetestzonetestzonetest zonetestzonetestzonetestzonetestzonetestzonetestzonetest zonetestzonetestzonetestzonetestzonetestzonetestzonetest zonetestzonetestzonetestzonetestzonetestzonetestzonetestzonetest.com>> (the same goes for other file types as .exe .reg or .vbs)
|
|
|
|
|