Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

DOS 8.3 Filename File Source Disclosure

Remediation Task

Filter out hazardous characters from user input

WASC Classification

Information Disclosure: Information Leakage

Affected Products

DOS Windows

Technical Description

Files can be accessed using the Automatic Short File Name Generation. All DOS and 16-bit Windows require the 8.3 filename creation, even 32-bit version sometimes need them.

Fix Recommendation

Do not allow DOS 8.3 filename creation. http://support.microsoft.com/kb/Q210638