IMHO, never view the blocked file types as a security measure. It israther simple to rename an exe with a doc extension, then upload it,then rename it back to an exe extension and viola - you've just bypassed the blocked file types rule.