Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. If I'm reading the disclosure correctly, the issue is:

If I'm reading the disclosure correctly, the issue is:

Scheduled Pinned Locked Moved Uncategorized
9 Posts 8 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ameliabr@front-end.socialA This user is from outside of this forum
    ameliabr@front-end.socialA This user is from outside of this forum
    ameliabr@front-end.social
    wrote last edited by
    #1

    RE: https://tech.lgbt/@solonovamax/116049115040950367

    If I'm reading the disclosure correctly, the issue is:

    - Windows Notepad is more than just a plain text editor now.
    - In particular, it has a markdown preview feature, including clickable links.
    - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

    So, don't open strange files & then click links. (And update Windows regularly.)

    earthshine@masto.hackers.townE drdrmc@mastodon.me.ukD rl761@social.vivaldi.netR jimjams@mastodon.artJ jernej__s@infosec.exchangeJ 7 Replies Last reply
    0
    • ameliabr@front-end.socialA ameliabr@front-end.social

      RE: https://tech.lgbt/@solonovamax/116049115040950367

      If I'm reading the disclosure correctly, the issue is:

      - Windows Notepad is more than just a plain text editor now.
      - In particular, it has a markdown preview feature, including clickable links.
      - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

      So, don't open strange files & then click links. (And update Windows regularly.)

      earthshine@masto.hackers.townE This user is from outside of this forum
      earthshine@masto.hackers.townE This user is from outside of this forum
      earthshine@masto.hackers.town
      wrote last edited by
      #2

      @AmeliaBR It took them 25 years, but Microsoft finally figured out how to add RCE to notepad.exe.

      1 Reply Last reply
      0
      • ameliabr@front-end.socialA ameliabr@front-end.social

        RE: https://tech.lgbt/@solonovamax/116049115040950367

        If I'm reading the disclosure correctly, the issue is:

        - Windows Notepad is more than just a plain text editor now.
        - In particular, it has a markdown preview feature, including clickable links.
        - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

        So, don't open strange files & then click links. (And update Windows regularly.)

        drdrmc@mastodon.me.ukD This user is from outside of this forum
        drdrmc@mastodon.me.ukD This user is from outside of this forum
        drdrmc@mastodon.me.uk
        wrote last edited by
        #3

        @AmeliaBR “So, don't open strange files & then click links.” Sage advice for all circumstances!

        1 Reply Last reply
        0
        • ameliabr@front-end.socialA ameliabr@front-end.social

          RE: https://tech.lgbt/@solonovamax/116049115040950367

          If I'm reading the disclosure correctly, the issue is:

          - Windows Notepad is more than just a plain text editor now.
          - In particular, it has a markdown preview feature, including clickable links.
          - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

          So, don't open strange files & then click links. (And update Windows regularly.)

          rl761@social.vivaldi.netR This user is from outside of this forum
          rl761@social.vivaldi.netR This user is from outside of this forum
          rl761@social.vivaldi.net
          wrote last edited by
          #4

          @AmeliaBR there was a 'phoning home' thing in Windows Notepad too if I remember correctly, don't have a source to hand. Possibly an unwanted OneDrive sync thing?

          1 Reply Last reply
          0
          • ameliabr@front-end.socialA ameliabr@front-end.social

            RE: https://tech.lgbt/@solonovamax/116049115040950367

            If I'm reading the disclosure correctly, the issue is:

            - Windows Notepad is more than just a plain text editor now.
            - In particular, it has a markdown preview feature, including clickable links.
            - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

            So, don't open strange files & then click links. (And update Windows regularly.)

            jimjams@mastodon.artJ This user is from outside of this forum
            jimjams@mastodon.artJ This user is from outside of this forum
            jimjams@mastodon.art
            wrote last edited by
            #5

            @AmeliaBR or remove notepad... Or Windows 😉

            1 Reply Last reply
            0
            • ameliabr@front-end.socialA ameliabr@front-end.social

              RE: https://tech.lgbt/@solonovamax/116049115040950367

              If I'm reading the disclosure correctly, the issue is:

              - Windows Notepad is more than just a plain text editor now.
              - In particular, it has a markdown preview feature, including clickable links.
              - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

              So, don't open strange files & then click links. (And update Windows regularly.)

              jernej__s@infosec.exchangeJ This user is from outside of this forum
              jernej__s@infosec.exchangeJ This user is from outside of this forum
              jernej__s@infosec.exchange
              wrote last edited by
              #6

              @AmeliaBR The new Notepad is so awful I uninstall it from my machines – that reverts to the classic Windows Notepad, which Microsoft crippled in Win11 by not allowing you to associate any files with. Luckily, there's a fix.

              ameliabr@front-end.socialA 1 Reply Last reply
              1
              0
              • R relay@relay.infosec.exchange shared this topic
              • jernej__s@infosec.exchangeJ jernej__s@infosec.exchange

                @AmeliaBR The new Notepad is so awful I uninstall it from my machines – that reverts to the classic Windows Notepad, which Microsoft crippled in Win11 by not allowing you to associate any files with. Luckily, there's a fix.

                ameliabr@front-end.socialA This user is from outside of this forum
                ameliabr@front-end.socialA This user is from outside of this forum
                ameliabr@front-end.social
                wrote last edited by
                #7

                @jernej__s Oh interesting, I didn't know the old version was still installed, just not accessible by default. I guess it's there for other apps that call it programmatically to display text output?

                I've been happy with Notepad after turning off a lot of settings (including the Markdown formatting one, for reasons unrelated to this bug). But I like the tabbed UI & that it persists drafts after a system reboot.

                1 Reply Last reply
                0
                • ameliabr@front-end.socialA ameliabr@front-end.social

                  RE: https://tech.lgbt/@solonovamax/116049115040950367

                  If I'm reading the disclosure correctly, the issue is:

                  - Windows Notepad is more than just a plain text editor now.
                  - In particular, it has a markdown preview feature, including clickable links.
                  - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

                  So, don't open strange files & then click links. (And update Windows regularly.)

                  odo@dustbuster.clubO This user is from outside of this forum
                  odo@dustbuster.clubO This user is from outside of this forum
                  odo@dustbuster.club
                  wrote last edited by
                  #8

                  @AmeliaBR I'm trying to understand this. Don't most markdown renderers have the same "vulnerability"? If I render the markdown [random link](mailto:chris@mystic.horse), a user will only see "random link". If they click the link, it'll open an external application and run as them, won't it? What is the difference? How is this remote code execution?

                  1 Reply Last reply
                  0
                  • ameliabr@front-end.socialA ameliabr@front-end.social

                    RE: https://tech.lgbt/@solonovamax/116049115040950367

                    If I'm reading the disclosure correctly, the issue is:

                    - Windows Notepad is more than just a plain text editor now.
                    - In particular, it has a markdown preview feature, including clickable links.
                    - But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.

                    So, don't open strange files & then click links. (And update Windows regularly.)

                    tony@toot.hoyle.me.ukT This user is from outside of this forum
                    tony@toot.hoyle.me.ukT This user is from outside of this forum
                    tony@toot.hoyle.me.uk
                    wrote last edited by
                    #9

                    @AmeliaBR I've been using notepad++ for so long I didn't realize notepad had actually changed.. I'm sure the last time I loaded it it was the same as ever..

                    But taking the simplest app on windows making it insecure takes dedication..

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.publicsquare.global shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups