6 ms·
> I’m no security person, so the reasoning felt a bit weird to me, as I guess the .zip TLD can’t hurt anybody; downloading a .zip might, which you can attach to
by TonyTrapp 2y ago
> I’m no security person, so the reasoning felt a bit weird to me, as I guess the .zip TLD can’t hurt anybody; downloading a .zip might, which you can attach to any link name? But in any case I wasn’t able to find any .zip URL with a purpose, but lots of Reddit posts of angry sysadmins who bemoaned the influx of terrible TLDs with mostly phishing use and vowed to block them all. So they probably have a point in downright blocking the whole TLD.
The problem is auto-linkification. It is extremely common in forum posts or emails to refer to attached filenames. Most forum softwares or email clients are helpful it automatically turning obvious URLs (doesn't start with a protocol:// but ends in a .tld) into clickable links. Anybody's reference to a zip filename is now a clickable link, only waiting to be registered for phishing attempts.
- n_plus_1_acc 2y agoThat's not a new problem tho. .TS and .CS are TLDs and Heck even .COM is also a file extension, should we block that too? What changed suddendly?
- deleted 2y ago[deleted]
- wlesieutre 2y agoThe type of user who has email conversations about .COM files is the same type of user who will realize that the link was automatically created by someone's email client and have a laugh about it. I don't know if you can say the same about zip files, an average user they might encounter someone mentioning a zip filename a handful of times in a year and they might click on the link expecting to get that zip file.
- chrisfosterelli 2y agoCOM files are a good point I hadn't considered.
- paranoidrobot 2y agoThe thing is '.com' is relatively unknown. When was the last time you had a genuine .com file you needed to use? And you're someone who's tech-savvy. Most people are going to see ".com" and think "Website" not "Program". So if suddenly a .com file is downloaded there's at least a chance they might stop and wonder what's going on. I run into this issue all the time - We get Bug bounty reports constantly because $SecurityResearcher put "example.com" into the "Company Name" field, and we sent them an email saying "Thanks for signing up. We hope you find $OurProduct useful at $CompanyName. " When the email turns up in their Gmail inbox, Gmail "helpfully" turns the plain text "example.com" into a link to https://example.com https://example.com - so $SecurityResearcher reports it to us as a vulnerability in our platform because "we" are linking to example.com - except we never did, and we have no way to tell Gmail, or Outlook, or any other platform to stop doing that. Services we pay for, directly, also do this - Notion and Slack are two I can think of immediately. I have to fight them to stop turning my mention of some file into a link to a random domain. (e: Maybe Slack has stopped doing this, perhaps - in testing it didn't do automatic linkifying for messages to myself) This was bad enough with .cs, .ts, .js., .json and so forth - but having a .zip link appear in the middle of documentation on how to do something with a zip file is a recipe for disaster. I've had a document saying "please download package.zip from the build artifacts site" - which was then auto linked to https://package.zip https://package.zip - and anyone not paying attention might expect that it was a link to the build artifacts site.
- _blk 2y agoGood point. I wonder what happens if i rename a malicious file into google.com and push it into ever AD user's desktop at a large corporation. Might not even make a difference that MS hides extensions by default.
- rprospero 2y agoThe COM file exploit worked because it is relatively unknown. I remember a worm going around when I was in grad school where you'd get an e-mail with a link to https://giftcard.customerservice.savemoneyonanew.tv/amazon.com https://giftcard.customerservice.savemoneyonanew.tv/amazon.c.... Users who had been through the phishing training would see the HTTPS at the beginning and the amazon.com at the end and know that this was a legitimate Amazon email. The e-mail instructed them to click the link and "open the PDF file". Users would click the link, down load the COM file, and the open the file, installing malware all over the machine and forwarding the worm to all their contacts.
- penteract 2y agoCOM files have been used maliciously due to confusion with urls [0]. I think I've heard of antivirus software preventing COM files from being run because of this. [0] https://en.wikipedia.org/wiki/COM_file#Malicious_usage_of_the_.com_extension https://en.wikipedia.org/wiki/COM_file#Malicious_usage_of_th...
- duskwuff 2y agoCan .COM files even run on modern 64-bit Windows systems? Surely they can't - hasn't the 16-bit subsystem been removed?
- TonyTrapp 2y agoWindows will run a regular MZ exe even if its name ends in .com.
- sqeaky 2y agoMZ exe, what do you mean?
- account42 2y agohttps://en.wikipedia.org/wiki/DOS_MZ_executable https://en.wikipedia.org/wiki/DOS_MZ_executable MZ is the magic number at the start of the file. Although gp probably meant a PE executable [0] which (typically) start with a stub MZ executable telling DOS users to run it under Windows. Because of this they still have a MZ magic number. [0] https://en.wikipedia.org/wiki/Portable_Executable https://en.wikipedia.org/wiki/Portable_Executable
- sqeaky 2y agoOK, thanks I thought I screwed up. I have recently been working on a command line tool and the windows version is called mz.exe. On Linux it is just 'mz', just a coincidence. I was concerned this name collision might cause problems, but that is fine.
- TonyTrapp 2y agoIt's not a new problem, but think about how many average computer users expect to be sent a ZIP file, vs how many of them expect to receive a TS, CS or COM file in their inbox.
- w-m 2y agoThat makes sense. Funnily enough I had kind of an inverse problem building the https://3dgs.zip/ https://3dgs.zip/ landing page, or linking to the project from elsewhere - I’d point a link to the compression survey with the link text “survey.3dgs.zip”. And had to have people point out to me that they don’t want to click on that, because they don’t want to download a big file.
- CydeWeys 2y ago> The problem is auto-linkification. Who's auto-linkifying .zip domains?
- TonyTrapp 2y agoI've seen it happening on GitHub, among others. Anyone that automatically imports an up-to-date list of all existing TLDs will fall into the same "trap".