TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Rich
from: Geo.
date: 2004-05-29 16:50:32
subject: Re: Outlook Express flaw

From: "Geo." 

True, but then there is no setting to keep the browser from opening a new
window, there is a setting to keep outlook from doing this and this gets
around that setting.

Geo.

"Rich"  wrote in message news:40b80e29$1{at}w3.nls.net...
   I know the term.  Nothing here you can't also trick someone unsuspecting
when opening in a new window.

Rich

  "Geo."  wrote in message
news:40b7dea4$1{at}w3.nls.net...
  "Rich"  wrote in message news:40b7a4bf$1{at}w3.nls.net...

  >>If you get a user to click a link in an email you already bypass content
and
  spam filters along with much more.  The bug here is simply that you can have
  the linked content open in place instead of a new window.<<

  Do you know the term Phishing, I think that's what the concern is with this.
  It's not that the external references are loaded, it's that they can appear
to
  be loaded from one place while in fact they are coming from another. It's
very
  similar to the MS04-004 bug for incorrect parsing of URLs.

  Geo.

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270
@PATH: 379/45 1 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.