Security Incidents mailing list archives
Re: Possible Intrusion Attempt?
From: Stewart <bdlists () snerk org>
Date: Mon, 26 May 2003 15:33:48 -0400
Rob Shein wrote:
I'm a little fuzzy about this part...how do you prevent people from accepting HTML mail, and considering how many mail clients out there send it by default, what do you do when all of a sudden a large percentage of people can't email you anymore?
Probably in a similar fashion that you would solve the problem of e-mail attachments [1]no longer accepted per default (about 90% of them are blocked) in the (arguably) most commonly used mail client, the Microsoft Outlook family. Microsoft seems to have removed the paragraph that was most interesting to me, in which they decreed that future versions of Outlook (Express) would completely disallow attachments altogether.
It's just one of those things that went horrifically wrong with e-mail, and changes need to be grandfathered in. Perhaps in answer to your question, an auto-response detailing the security problems inherrant to most HTML e-mail with references detailing how to change the default behaviour in most popular mail clients would be in order.
[1]: http://support.microsoft.com/default.aspx?scid=kb;en-us;q329570 -- http://www.snerk.org/ ---------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- Possible Intrusion Attempt? Matt LaFelero (May 22)
- Re: Possible Intrusion Attempt? Ryan Yagatich (May 23)
- Re: Possible Intrusion Attempt? Gary Flynn (May 23)
- RE: Possible Intrusion Attempt? Jerry Shenk (May 23)
- Re: Possible Intrusion Attempt? Anders Reed Mohn (May 23)
- <Possible follow-ups>
- RE: Possible Intrusion Attempt? Whiteside, Larry [contractor] (May 23)
- RE: Possible Intrusion Attempt? Rob Shein (May 25)
- Re: Possible Intrusion Attempt? Andersson (no email) (May 26)
- Re: Possible Intrusion Attempt? Thomas Zimmerman (May 26)
- Re: Possible Intrusion Attempt? Lars Duesing (May 27)
- Re: Possible Intrusion Attempt? Stewart (May 27)
- RE: Possible Intrusion Attempt? Rob Shein (May 25)
- RE: Possible Intrusion Attempt? Thomas, Frank (May 23)
- RE: Possible Intrusion Attempt? Whiteside, Larry [contractor] (May 25)
- RE: Possible Intrusion Attempt? FWAdmin (May 26)
- RE: Possible Intrusion Attempt? Brad Webb (May 27)
- Re: Possible Intrusion Attempt? Matt LaFelero (May 27)
- Re: Possible Intrusion Attempt? Keith Owens (May 28)
- Re: Possible Intrusion Attempt? Jeff (May 29)
- Re: Possible Intrusion Attempt? Keith Owens (May 28)