w.e w.e Internet Explorer Does What It Wants

No ratings

Presented at GrrCon2018 2018 by

So you think you’re safe because you set Notepad to Open HTA documents? An IE application bypass method will reveal a hole in your network defense. Internet Explorer can download and execute files in ways that do no respect the File Associations configured in Windows. I’ll explain how threat actors are able to leverage the bypass. I will also explain how defenders can harden their environment to disable the bypass.