Security Basics mailing list archives

Re: www.readnotify.com


From: Saqib Ali <docbook.xml () gmail com>
Date: Thu, 26 Jan 2006 18:40:19 -0800

        I mean correct me IF I'm mistaken, but don't the above methods require
that one is connected to The Net in order for 'em to work?
yes it does.


        And what about the other things that they claim that they can do?  Such
the "self-destructing" E-Mails, or the E-Mails that the sender can revoke?

For this, ReadNotify requires the recipient to click a URL to read the
email content. So the content is essentially at their site. They are
just notifying the intended recipient that a mail wait, and give them
the URL. The URL points to a ReadNotify webpage.

Or preventing the person who received the E-Mail from either forwarding an
E-Mail to another person, or printing said E-Mail out?  Wouldn't any of
This functionality does NOT work "most" of the. They are just adding
some JavaScript code along with the HTML that prevent printing. See
below for the Javascript code [function pdnp()]. This may work for
some primitive mail readers, But not for any of the mainstream mail
readers e.g. Lotus Notes / pine / Mozilla / Thunderbird etc.
------------------------------
<script><!--
function pdnp() {document.body.innerHTML='&nbsp;';return
0;}window.onbeforeprint=pdnp;
//--></script>
<!--_Warning_to_Hotmail_and_Yahoo_and_other_staff:_Before_taking_action_that_might_damage_the_functionality_of_this_service,_contact_tech@readnotify.com_and_provide_suitable_replacement_techniques.__Failure_to_do_this_will_be_considered_deliberate_anti-competitive_behavior_and_illegal_trade_baring:_Legal_action_from_us_will_result._--><font
color="#FFFFFF"><div id=hi></div>--<<base foo>Img
Src="javascript:eval(unescape('functi%6fn%20pdp()%20{d%6fcument.b%6fdy.innerHTML%3D%22&nbsp;%22;return%200;}wind%6fw.%6fnbef%6freprint=pdp;'));"
width=1
height=1 -><comment></comment>--></font></DIV></BODY></HTML>
----------------------------------


that further d/ls software that does what they claim?  And IF they do that,
then aren't they in violation of the computer use and abuse act?
nothing get d/l to the machine. just simple javascript.


--
Saqib Ali, CISSP
http://www.xml-dev.com/blog/
"I fear, if I rebel against my Lord, the retribution of an Awful Day
(The Day of Resurrection)" Al-Quran 6:15

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: