funsec mailing list archives

Re: Format of embedded graphics


From: Gadi Evron <ge () linuxbox org>
Date: Thu, 29 Dec 2005 07:43:37 -0600 (CST)

On Thu, 29 Dec 2005, Larry Seltzer wrote:
Most of you, I suspect, read e-mail as plain text. For experimental purposes
this message is sent as HTML with a graphic embedded with a question



The list doesn't allow HTML to come through.
:)

 
<outbind://218-000000005384F517C8AD9748884180DED30A6CDAA4615401/http://www.l
arryseltzer.com/testimage.gif> 

This graphic was a non-malicious WMF file that I renamed .GIF and embedded. 
 
So what happens to the format of such a graphic when embedded in an HTML
e-mail? Is it forced to GIF or JPG, or is it perhaps still a WMF and
potentially malicious?

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.ziffdavis.com/seltzer
Contributing Editor, PC Magazine
larryseltzer () ziffdavis com



_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: