3 ms·
Hiding file extensions is uniquely dangerous on Windows as the file extension is the canonical reference of what type something is. Change the .doc to .exe and
by anexprogrammer 10y ago
Hiding file extensions is uniquely dangerous on Windows as the file extension is the canonical reference of what type something is. Change the .doc to .exe and the system will try to treat it as an executable. At least on other systems it's a convenience and the system identifies type and executable bit in somewhat more robust ways.
- TeMPOraL 10y agoYes, that's true too. It's a common Windows malware distribution vector - bad actors send files with names like "photo.jpg.exe" or even "photo.exe", with the icon resource in executable's metadata set to look like default image icon, or even a thumbnail of some real photo.
- pjmlp 10y agoNot only on Windows, on other OSes as well. Many developers don't rely on the OS API to check the file contents and use a simple extension checking.
- curt15 10y agoCountless words have been written about this, but does MS see it as a problem?