Security Basics mailing list archives

Re: Possible Payload inside PDF or HTML files


From: krymson () gmail com
Date: 13 Jun 2007 19:43:51 -0000

Some emails can be sent that require notification when the email is received, read, or deleted. I don't know what this 
is called, but I know some companies use it (usually internally) as a process for verifying email delivery. Typically 
this pops up in Outlook and asks if you want to send the requested response.

Second, if your email is displaying the HTML files directly or you are otherwise looking at them, they could easily 
include code that references an outside side. If there is an imagin in the HTML that is housed on their server, they 
know when you see it. It is trivial to make this unique for every email missive sent, so you can tell who read it (or 
at least had Outlook open it, for instance). 

You might want to fire up a sniffer on your system after receiving the next mail and see what happens. Is something 
making connections?


<- snip ->
Is there a way to know if exist a payload inside a PDF or HTML File,

Let me explain the problem, i marketing company is sending me emails
and is able to know if i open, delete, sent to spam or forward the
message so i think there is a payload inside that files.

Let me tell you that the HTML file looks like a normal one without
javascript or obfuscation or another malicious payload, only links and
images,

Is there a tool to look inside PDF files?
Or a Steganos tool to test the images from HTML file?

What you think?


Current thread: