5 ms·
> Internet Explorer uses it to save whether a file was downloaded via IE. Wait, but why? Chromium (at least on Linux) uses extended attributes too, but to reco
by ymse 10y ago
> Internet Explorer uses it to save whether a file was downloaded via IE.
Wait, but why? Chromium (at least on Linux) uses extended attributes too, but to record the origin and referrer of downloaded files (which can be really useful, once you know about it).
- int_19h 10y agoTo be more specific, IE (and most browsers on Windows, actually) use alternate streams to record that the file originates from the network, in a certain standardized way. When such a file is an executable file, and the user attempts to launch it (via Explorer; I don't think this happens for command line), they will get a confirmation dialog from the OS telling them that it's unsafe. Other applications can perform similar checks on file formats that they handle, if the payload can be dangerous when untrusted. E.g. Visual Studio will give you a warning if you're trying to open a project file with this bit set.
- hug 10y agoChrome does it too. As does outlook, Firefox, possibly a bunch of other things. I think you'll find that the stream is zone-identifier. It can contain a value of 1 to 4, where each corresponds to a list of Windows' security zones. (Restricted sites, internet sites, local Intranet, and trusted sites from 4 to 1 respectively. There's a fifth option, zone 0, which is "local computer", but it's unused.) This is the source of the prompts in Windows that say "this file came from the Internet, are you sure you wish to run it?".