nautilus's clever anti-hax0r detection is really dumb
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| Nautilus |
Expired
|
High
|
|||
| nautilus (Ubuntu) |
Fix Released
|
Wishlist
|
Ubuntu Desktop Bugs | ||
Bug Description
Cannot open attachment.cgi.html
The filename "attachment.
page". The contents of the file indicate that the file is of type "differences
between files". If you open this file, the file might present a security risk to
your system.
Do not open the file unless you created the file yourself, or received the file
from a trusted source. To open the file, rename the file to the correct
extension for "differences between files", then open the file normally.
Alternatively, use the Open With menu to choose a specific application for the
file.
Can this error dialog please die now (or at least be special-cased to only apply
to situations where your computer is *actually* in danger)? It'd be great it
Nautilus just did the reasonable thing and opened the file in either ephy or
gedit. I can't really think of a case where opening a file like this could be a
security problem (except in the case where the file is explicitly marked
executable, and this could be handled as the special case). Certainly, in any
case where Nautilus is about to execute a script (rather than open it in an
editor) I'd like to be asked about it anyway.
For the record, Nautilus has the following preference:
Executable Text Files:
( ) Run executable text files when they are clicked.
( ) View executable text files when they are clicked.
(o) Ask each time. <-- default.
Even if I set this to "Run executable text files when they are clicked" and
double click on a shellscript that has the extension ".sh" it opens in gedit
because it lacks mode +x.
http://
| Changed in nautilus: | |
| status: | Unconfirmed → Confirmed |
| Changed in nautilus: | |
| status: | Confirmed → Triaged |
| Changed in nautilus: | |
| status: | Confirmed → Invalid |
| Changed in nautilus: | |
| importance: | Unknown → High |
| status: | Invalid → Expired |
Thanks for your bug, it's already known upstream: bugzilla. gnome.org/ show_bug. cgi?id= 309862, I've put your comment on it
http://