Gmail dangerous attachment type bypass

0
70

Posted by WooYun on Oct 29

Hi

Someone report this on wooyun

http://www.wooyun.org/bugs/wooyun-2010-03139

Just use

Content-Disposition: attachment;
filename="trojan.exe."

can bypass gmail security check

🙂

Source: Gmail dangerous attachment type bypass