• Malix@sopuli.xyz
    link
    fedilink
    arrow-up
    23
    ·
    2 days ago

    heh, ofc. Apparently something to do with file:// and such uri handling, apparently executing local files? Yikes.

    • thethunderwolf@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      2 days ago

      not just local files

      if you click a link to file:///123.45.67.89:69420/files-download/virus.exe it will download and run virus.exe from that IP address

      it still works, but now there is a “Dangerous Link Location: This is not a web link and may lead to the execution of malicious code” warning, but previously it would silently run the file.

      • Malix@sopuli.xyz
        link
        fedilink
        arrow-up
        3
        ·
        1 day ago

        kinda wild a file-link ever went straight to executing it after download - which on it’s own could be dangerous as well.

        I guess the “the s in IOT stands for security” also applies to notepad: “the s in vibecoding stands for security”