Vulnerability Development mailing list archives

Re: Why not a changeling?


From: mrousseau () LABCAL COM (Maxime Rousseau)
Date: Thu, 25 May 2000 13:58:04 -0400


Hi all, hi echelon,

!  -----Original Message-----
!  From: White Vampire
!  Sent: Tuesday, May 23, 2000 1:17 PM
!
<snip>
!       Simply do not parse superfluous data.  My mail client does not
!  parse HTML or any other MIME types unless I /tell/ it to.  (And even
!  then, it would be doing it externally.)

Or better, remove HTML eMail alltogether. Can someone point out a good
reason to send an HTML eMail? Where is the function to have outlook
strip out all HTML codes in those emails and have them displayed as
plain text?

This would actually be pretty interesting... just take the mail and
remove all <tags> from it and display as plaintext. Wouldnt that be
great? Maybe this could be part of an eMail firewall or part of the mail
server (if it isnt Exchange, probly would work well on sendmail).

!       I do not really understand why so much debate, attention, and
!  concern is directed to things such as this.  They live and
!  depend upon stupid software, stupid lusers, and stupid
implementations.

I think the debate and attention on this issue is because of the
technical challenge of writing a polymorphic virus and to see how it
would be possible to prevent such things. I find this thread pretty
interesting, but thats just me.

M.
[big signature, logos and cute quotes here]


Current thread: