Windows 7 Users Warned Over Filename Security Risk
Would-be Windows 7 users have been warned to change a default setting which could leave them vulnerable to attack via bogus files. As a result, Microsoft is taking flak for failing to correct a problem found in previous editions of Windows.
Hidden File Extensions by Default
The issue involves the way Windows Explorer displays filenames.
In all editions of Windows after Windows 98, the default setting hides the filename extension (which identifies what type of file it is). This means that a Word file titled 'partyinvite.doc' will show up in Windows Explorer as simply 'partyinvite'. The only exception to this rule is if Windows does not recognize the file type.
The reason for this setting is that it makes for a less cluttered look and avoids filling the screen with redundant detail. However, a flaw in the way it works leaves it liable to exploitation by hackers. They can take an executable file (which can do much more damage to a computer when opened) and disguise it by calling it 'partyinvite.doc.exe'.
Executable File Icon Appearance Ambiguous
Windows will see this, treat it as a Word document file, and simply display it as 'partyinvite'. Because executable files can be set up to appear with any icon (usually one specific to the program concerned), anyone could set this file to appear with the Word icon. This means that unless the user has the 'Details' view switched on and notices that the file is listed as an 'Application', they would have little chance of realizing it was not a legitimate Word file. (Source: computerworld.com)
Security firm F-Secure has noted this option is still the default setting in Windows 7, despite the problem. It's possible Microsoft could still change this in Windows 7, but it seems unlikely now that the system is at the Release Candidate stage. (Source: f-secure.com)
Users More Easily Fooled
It's worth remembering that you should never open any file unless you are 100% certain it is legitimate and comes from a trusted source. However, most users are much more likely to be fooled by a document file than an executable program file, particularly when it is spread through an email virus. A rogue executable file can do much more damage, as it can attack Windows directly rather than have to exploit a specific problem in an application.
Windows Explorer's settings can be changed so that the legitimate file extension is always visible, regardless of what view mode you have selected. To make the change, open a folder in Windows Explorer, select Folder Options from the Tools menu, and then choose the View tab. From here, un-select the options 'Hide extensions for known file types'.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.