• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Ethical Hacking

Wade Mackey

Ethical Hacking

MIS 5211.001 ■ Fall 2019 ■ Wade Mackey
  • Home
  • About
  • Syllabus
  • Gradebook

Microsoft to block 38 additional file extensions in Outlook for Web

September 27, 2019 by Andrew P. Sardaro Leave a Comment

I have always been a proponent for using web-based Outlook instead of the local thick client for performance, data consistency, and troubleshooting reasons. Security is another reason to make the switch. Microsoft Outlook for Web will now block an additional 38 file extensions in email attachments. Blocking these extensions protect its email users from becoming a victim of malicious scripts or executables attached or embedded in emails.

Some common extensions currently blocked in the list of 104 include .exe, .url, .com, .cmd, .asp, .lnk, .js, .jar, .tmp, .app, .isp, .hlp, .pif, .msi, .msh.

The new 38 blacklisted extensions are affiliated with the following programs:

  • Python scripting language: “.py”, “.pyc”, “.pyo”, “.pyw”, “.pyz”, “.pyzw”
  • PowerShell scripting language: “.ps1”, “.ps1xml”, “.ps2”, “.ps2xml”, “.psc1”, “.psc2”, “.psd1”, “.psdm1”, “.psd1”, “.psdm1”
  • Digital certificates: “.cer”, “.crt”, “.der”
  • Java programming language: “.jar”, “.jnlp”
  • Various applications: “.appcontent-ms”, “.settingcontent-ms”, “.cnt”, “.hpj”, “.website”, “.webpnp”, “.mcf”, “.printerexport”, “.pl”, “.theme”, “.vbp”, “.xbap”, “.xll”, “.xnk”, “.msu”, “.diagcab”, “.grp”

These are not extensions I see a normal end user sending as part of their daily operations, this blacklisting change should be transparent to users. For any reason, the Exchange admin can whitelist a blacklisted extension.

https://thehackernews.com/2019/09/email-attachment-malware.html

Filed Under: Week 05: Metasploit Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (55)
  • Week 01: Overview (6)
  • Week 02: TCP/IP and Network Architecture (2)
  • Week 03: Reconnaisance (7)
  • Week 04: Network Mapping and Vulnerability Scanning (4)
  • Week 05: Metasploit (9)
  • Week 06: More Metasploit (8)
  • Week 07: Social Engineering (11)
  • Week 08: Malware (19)
  • Week 09: Web Application Hacking (14)
  • Week 10: SecuritySheperd (12)
  • Week 11: Intro to Dark Web and Intro to Cloud (10)
  • Week 12: Introduction to Wireless Security with WEP and WPA2 PSK (6)
  • Week 13: WPA2 Enterprise and Beyond WiFi (11)
  • Week 14: Jack the Ripper, Cain and Able, and Ettercap (9)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in