Sep 6, 2011

How to easily Bypass Email Attachment File Filtering, send ANYTHING by Email?

Hey guys, I just wanted to notify you of a cool and not so cool bug that ALL email hosters have regarding file attachments. Please use this for educational purposes only.

Lets say I have just coded a .exe in VB and want to send it to a friend for test run. The email host will block the .exe with a file extension filter, until my method came around the block. Today you will learn how to send an .exe over the internet, such as Yahoo, Gmail, AOL and live email hosting servers. We're not modding the filter, but the file Hehe. All common sense.

Now Good News:
You Can Now Send Any Type Of File Extension by Email


Now Bad News:
Pretty self explanatory why this could be bad, if the hacker is smart enough they can maneuver around and send a virus to someone, if that someone is willing to participate with the hacker.


Very simple, tutorial. I will be teaching you the ways of the LOGIC.

First step, get your .exe file. Next, Download iHide.exe
Here.


Next, Go onto iHide and pass UAC, then go to the ComboBox and select Show File Extensions and hit the button below it, refresh desktop by right click options or hitting the F5 key on keyboard, file extensions are revealed.

Next hit the button "select an option in the combobox". Then refresh your Desktop.



Nt I want you to find your .exe file, and rename it to any file extension, then hit enter. Doesn't matter. Do this by deleting the "exe" part and replace the "exe" part with a new file extension. If you open it, the file will act corrupted because its being opened by the wrong file extension. As long as it you think it would be a legit file to go through an email hosting attachment filter such as a portable network graphic file, .PNG or .JPEG.


[Image: s3.png]

[Image: s4.png]

[Image: th_s5.png?t=1287338314]

After that its pretty self explanatory. Select the ".PNG" disquised as your .exe file, and attach it. Write your subj, and body msg, and you send the mail to your friend, explaining to them how to change the file extension to a .exe file after getting it downloaded somewhere convenient and BOOM!

[Image: s6.png]

We bypassed the Attachment Filtering Service built into your email and the receiver got the .exe file successfully. I hope you learned something today :D Enjoy. Feel free to reply!

No comments:

Post a Comment