Full Disclosure mailing list archives
Re: Outlook Express - is this possible?
From: Steve Menard <smenard () nbnet nb ca>
Date: Mon, 26 Jan 2004 06:47:33 -0400
Gregh wrote: >I may just be confusing myself here so bear with me: > >I believe an exploit cropped up within the last 12 months or so for OE>(version unknown) where the user has preview pane OFF and receives an >email that he doesn't actually double click on to open. However, in >deleting it, the user either web bugs himself or puts some sort of >exploit in. I cant >remember whether I am confusing myself with more than one issue here >but can anyone help. Did that happen, was it possible at one stage or >possible now?
> >I believe the act of deleting something from the inbox is just a marker>change in OE to show it in deleted rather than inbox and not a program >run per se.
=-=-=-=-=-=-=-=--=-=- best guess option in preferences Reply to messages in format they were sent hence webbugs as follow-up to my earlier ... Unaware of any such exploit. but there are a few setting we should check. the mail would need to be processed and it's contents triggered something I'd suggest checking out the read receipt. since it grabs [our untrusted input] our return email addr not done any testing though Maybe it has something to do about auto - answering. ala Receipt-required flags I've seen when people had read, and allowed read receipt read, disallowed receipt deleted without reading. and sender got notified DOH Next I'll have to remember which others may apply if attachments are downloaded with email s ... my attachments directories were filled largeattachments smenard _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Outlook Express - is this possible? Gregh (Jan 24)
- Re: Outlook Express - is this possible? Nick FitzGerald (Jan 26)
- Re: Outlook Express - is this possible? Thor Larholm (Jan 26)
- <Possible follow-ups>
- Re: Outlook Express - is this possible? Steve Menard (Jan 26)
- Re: Outlook Express - is this possible? Nick FitzGerald (Jan 26)