Bugtraq mailing list archives
Re: ZA Security Hole
From: Hugo van der Kooij <hvdkooij () vanderkooij org>
Date: Fri, 16 Apr 2004 07:55:17 +0200 (CEST)
On Wed, 14 Apr 2004, Damjan Kreft wrote:
I think, I discover some kind of security hole in ZoneAlaram - any version. The problem is hidding in E-mail Protection. Because I'm form Slovenia (not Slovakia), our alphabet does have some letters with roof (c - ?, s - š, z - ž). And when the name of e-mail attachment contain any of these three letters, it don't go to the qurarantine (if the attachment do have right extension of course). I think that can be security threat. From this reason I write to you. If this is mistake, I'm sorry to steal your time with this e-mail. And sorry for my bad english :) I write to ZA Labs too, but no answer.
Are these attachments passed through regardless of filter conditions? Or are they blocked/stripped now? Hugo. -- All email sent to me is bound to the rules described on my homepage. hvdkooij () vanderkooij org http://hvdkooij.xs4all.nl/ Don't meddle in the affairs of sysadmins, for they are subtle and quick to anger.
Current thread:
- ZA Security Hole Damjan Kreft (Apr 15)
- Re: ZA Security Hole Pablo G. Sabbatella (Apr 16)
- Re: ZA Security Hole Samps (Apr 16)
- Re: ZA Security Hole Patrick Brauch (Apr 21)
- Re: ZA Security Hole Hugo van der Kooij (Apr 16)
- Re: ZA Security Hole David Wilson (Apr 20)