Vulnerability Development mailing list archives

Re: Email webbugs


From: "ezat_t" <ezyt () optushome com au>
Date: Tue, 28 Aug 2001 08:39:23 +1000

Does your test work?"

Im very interested in this but getting

----- Original Message -----
From: "abuse" <postmaster () getinfo org>
To: "Focus-MS" <focus-ms () securityfocus com>
Cc: "VULN-DEV@SECURITYFOCUS. COM" <VULN-DEV () SECURITYFOCUS COM>;
"BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ () SECURITYFOCUS COM>;
<win2ksecadvice () LISTSERV NTSECURITY NET>
Sent: Monday, August 27, 2001 10:12 PM
Subject: Email webbugs


One of the things that has always bothered me about Outlook Express and
Outlook is that they are susceptable to webbugs. Basically there are no
options to block confirmation of your reading an email so any spammer can
verify that your address is active as long as they can get you to just
view
an email.

A lot of people have difficulty understanding exactly what this means so I
set up a demonstration page at http://www.nthelp.com/OEtest/oe.htm in an
attempt to raise awareness of this nonsense and get MS to do something
about
it. I don't know if other email programs like Eudora and Netscape are
vulnerable to email webbugs so if anyone tests those please let me know
the
results.

Anyway, I've made the test site available to the public now so if you want
to check your email reader, feel free.

Geo.



Current thread: