resterm v1.10.2
resterm v1.10.2Resterm v1.10.2 hardens opening of response bodies: file extensions now derive from 2026-9-29 20:23:34 Author: kitploit.com(查看原文) 阅读量:4 收藏

resterm v1.10.2

Resterm v1.10.2 hardens opening of response bodies: file extensions now derive from content type, only safe types open, HTML/SVG/XML/Markdown open as text, executables and macro-capable Office files no longer open, and temp files are private and cleaned up.

Source excerpt (original language):

A body sent with filename="setup.exe" was written as resterm-2849.exe and handed to the default app. On Windows, this could e.g., run a program sent by the server.

HTML, SVG, XML, and Markdown open as .txt, so scripts inside them cannot run.

g Shift+E no longer opens executables, e.g., Office files that can hold macros (.doc, .xls, .ppt), or bodies with no known type.

https://github.com/unkn0wn-root/resterm/releases/tag/v1.10.2


文章来源: https://kitploit.com/en/posts/resterm-386ff414d5db835f
如有侵权请联系:admin#unsafe.sh