Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Solving the Problem of HTML Mail
Shane Coursen, 2002-02-04

Now there are options for screening potentially dangerous messages, or even eliminating HTML email from your life.

Comments Mode:
Three things to make HTML email bearable 2002-02-04
TL (2 replies)
First, when composing HTML e-mail make sure there is
a plaintext part included for those non-HTML MUAs (lots
of sysadmins and engineers prefer not to use Outlook
Express), and that it shows up first when opening the message in plain text.

Secondly, include in all HTML aware MUAs the possibilit...

[ more ]  [ reply ]
ok, why did you even write this article? 2002-02-07
friend (1 replies)
who cares? its not even logical to read email over a webpage anyways. why would you even write an article like this? its useless.

another great securityfocus.com inside article i guess.

friend...

[ more ]  [ reply ]
ok, why did you even write this article? 2002-02-08
Anonymous
I agree...ironic how in the left hand side of the page, there is a signup sheet for the new "HTML" newsletters.

Um, didnt they just tell us that HTML email is not good?...

[ more ]  [ reply ]
How about RTF as a format instead of HTML? 2002-02-10
LA Walsh (1 replies)
I end up using HTML in mail messages because so few
mailers understand Rich-Text-Format -- maybe that's
a MS-only thing...( :-( ). But, often, all I want is
some very primitive things like *bold*, _italics_,
and _UNDERLINE_(?).

Even the ability to use auto-text wrapping -- I like GUI editor...

[ more ]  [ reply ]
How about RTF as a format instead of HTML? 2002-02-13
Ben
It's an email, not a g**d*** thesis! Save your fancy formatting and 80 pages of nothing for a real document.

Email is not a substitute for a word processor.
...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-04
Roland <r s m i t h AT x s 4 a l l . n l >
Use filting software.

About 1/3 of the spam I receive is 'Content-Type: text/html'.

I'm using a program called "mailfilter", that scans the headers of the messages on the POP server, and deletes those whose headers match any of a set of regular expressions from the server, even before you down...

[ more ]  [ reply ]
Why screen only HTML encoded e-mail? 2002-02-04
Anonymous
If one is going to go to all the trouble of screening HTML encoded e-mail, then you might as well screen all e-mail before transferring it from your ISP's mailserver. I have found the Windows 95/98/NT program, Email Remover, to be useful for this purpose. ...

[ more ]  [ reply ]
Don't use Outlook 2002-02-04
Anonymous (2 replies)
The biggest threat to security from e-mail is by reading it with Outlook. The best replacement I've found is Ximian's Evolution (written for Linux, but runnable in Windows with libraries like Cygwin). It's interface is very similar to Outlook, so it's an easy migration. It'll display HTML e-mails...

[ more ]  [ reply ]
Don't use Outlook 2002-02-06
Anonymous (2 replies)
You know, I've been running Outlook for at least 7 years now and I have NEVER, let me repeat that, NEVER had a virus. It's not Outlook. It's the stupid users who just click on anything without looking or thinking. If:

1. ISPs would install filters. We do this for our customers and the cost is...

[ more ]  [ reply ]
Don't use Outlook 2002-02-08
Anonymous (2 replies)
Agree! The problem is NOT Outlook. It is a given that
Microsoft will be bashed simply because they are that
nasty archdemon Big Business.

Outlook has the capability to transmit a great deal of
content in email, both active and passive. Why? Because
most users truly appreciate those featur...

[ more ]  [ reply ]
Use common sense when using Outlook 2002-02-10
LA Walsh
I have to agree with the previous posters. Outhouse^H^H^H^H^Hlook doesn't kill computers -- people do. :-)

I have and continue to use a variety of readers, but none that I have used, so far, have the overall usefullness of Outlook.

Also, in OL, you can choose what 'zone' to view email mess...

[ more ]  [ reply ]
Don't use Outlook 2002-02-16
Anonymous
Did you really use the word "armour" to describe outlook? Outlook armour is nothing but a sieve and the only reason to use outlook is that you have no choice....

[ more ]  [ reply ]
Don't use Outlook 2002-02-16
Anonymous
"People running around bashing MS and Outlook" have a reason for doing so.
Have you already forgotten the VBS worm plague of 2000/2001? What software did they use? Let me give you a hint -- Outlook. If Microsoft would not allow its clients to be automated to such an extent, and then ad...

[ more ]  [ reply ]
Don't use Outlook 2002-02-07
trowe
Really, I can't help but chuckle at the millions (billions?) of dollars that have been wasted, and will continue to be wasted, because people insist on using Outlook. I have more sympathy (which isn't alot) for people who continue to smoke after all the warnings. At least nicotine is physically addi...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-04
Tony Turner
I'd just like to comment upon this from a different direction. Too many people take the DEFAULT setup for their email and their newsgroup readers and use it AS IS, to send out email and newsgroup posts/replies. The problem is, most of the email/newsgroup tools out there (at least the players with ...

[ more ]  [ reply ]
Solving the Problem of HTML Mail - Procmail 2002-02-05
Anonymous
## HTML MAIL SUCKS

ORGMAIL=/var/spool/mail/$LOGNAME
MAILDIR=$HOME/
SENDMAIL=/usr/sbin/sendmail
LOGFILE=$HOME/proclog

:0
*!^From.*
{
:0 B
* ? egrep -is " "
{
EXITCODE=77
:0
! spam@yourdomain.com
...

[ more ]  [ reply ]
Spamming: The Problem of "Solving the Problem of HTML Mail" 2002-02-05
Fra. 219
The first several paragraphs of this article seem to be implying that spamming -- unsolicited "marketing" to a "target audience" by email -- is a tolerable practice. This is unfortunate and degrades Mr. Coursen's otherwise useful message. Spamming is a theft of service, and is recognized as a crim...

[ more ]  [ reply ]
PocoMail solves many security related email problems 2002-02-05
Anonymous
I've been using it and keeping up on it for a while, it's like Kmail for windows but only w/ a few more features such as junk mail filtering, spell checking etc. It will probably become largely popular over the next couple years or so....

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-05
Dr. Gerry Hecht
An option to dealing with this problem that I have found to be very satisfactory is a little app from Ultrafunk Software called Popcorn--here is the description in the authors own words:
What is Popcorn?
----------------
Popcorn is a freeware ultra-lightweight POP3/SMTP e-mail client, free from u...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-05
JT
I run a freeware product called Tiny Firewall and do not allow the program Outlook outbound access on port 80. This kills the html. I also don't allow it access to the NetBios UDP ports, so that any embedded attempts to get my system to log on to a remote server will fail. It takes a short while to ...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-06
Anonymous
While I agree that HTML is sick and wrong in its current form, that is not the point of this article. The point is, if we assume HTML mail is here to stay how do we deal with it. Really this should just be a application issue in that only certain tags would be allowed and scripting would be comple...

[ more ]  [ reply ]
Pegasus Mail is immune to HTML problems 2002-02-06
Angus S-F
Pegasus Mail 4.0 (http://www.pmail.com/) is immune to HTML problems -- although it will display HTML mail with embedded graphics fine, it will not fetch graphics from another computer and it doesn't execute any scripts (Javascript or VBS). This means users of PMail are free from web-bug tracking as...

[ more ]  [ reply ]
users 2002-02-06
Stefan Caunter
Smart users do not get viruses. They do not open problem mail, and they know how to use their mail client to prevent problems.
Relying on another piece of technology rather than on users continues to prevent users from acquiring the knowledge they need to deal with this stuff.
A company with av p...

[ more ]  [ reply ]
stripmime.pl - perl script to strip html tags for you 2002-02-07
Anonymous
www.phred.org/~alex/stripmime.html

Handy little perl script that strips out html tags and attachments.
...

[ more ]  [ reply ]
HTML mail is for Teletubbies 2002-02-07
lala@po.com

Please do not use HTML in your replies. HTML tags will be filtered.
...

[ more ]  [ reply ]
this comment page... 2002-02-08
WetBlanket
For those of us on dial-up, it is not clear why we need to load an entire page to read each comment. I suggest, for greater usability, that the first 512 characters of comments appear in wide tabular form, with Read More links for long diatribes.

As for HTML mail, I detest it, but use Outlook for...

[ more ]  [ reply ]
Eudora also filters out web images and executable content 2002-02-11
Anonymous
Check under Options-Display and Options-Viewing Mail...

[ more ]  [ reply ]
Procmail on the Mail Server is a Real Solution 2002-02-12
Analysis and Solutions
Hi Folks:

The way I've soved the HTML email problem using Procmail. If you're fortunate enough to have Procmail on your mail host, you can throw these two recipies into your rc files.

Both of these recipes are three lines each, plus a one line comment on the top. Please adjust line wrapping ...

[ more ]  [ reply ]
consumers love text/html 2002-02-12
Anonymous
Jesus God Almighty! Where did you get the crack you're smoking?

I don't know a single person who prefers html mail over text, with one notable exception. She uses AOL, and has a habit of sending lime-green-on-pink messages. I've never worked out if it's intentional or not.

HTML mail serves ...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-13
Anonymous
Mr Shane Coursen find out the solution not only for HTML mail but for a big percentage of virus propagation. Oh! Oh! Oh!

The problem, Mr Coursen, is that SMTP protocol was created under unprotected environment. So it alone do not have mechanism to save end users (innocent) to keep your postoffice...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-14
Old Fogie (aeaton@fdic.gov)
Actually, Mr./Ms. Walsh, Rich Text Format was never meant to be a "Microsoft thing." We old fogies remember the time when IBM (remember them?) introduced the first commercial version of .RTF. I have made RTF my standard e-mail format for years; it helps me put up with some of the other Outlook non...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-15
Anonymous (2 replies)
in outlook express to save my e-mail I have to select it. if i select it then it opens and thus it is to late to do any good. there is to my knowledge no way to turn that off....

[ more ]  [ reply ]
Solving the Problem of HTML Mail (in Outlook Express) 2002-02-15
Old Fogey
Dump outlook express and spring for Outlook, 9x or 2000. Personally, I use Outlook 97 with a preview-pane add-in from Microsoft and all relevant patches -- I can't view HTML in its full glory (?) in Outlook 97, but I can save it and view it with an external HTML viewer or editor, which is safe as h...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-18
Stakka Bo
Hide Preview Pane. Select message.
Go to Menu - > File - > Save As ... !...

[ more ]  [ reply ]
We nead assambly... Order is dump 2002-02-16
Anonymous
At the past time we use known only assambly virus... But modern time viruses are dump.... Maybe attachment executable... &#304; agree html virus is fast .... There attack is every one ... But debug ,,, U can c that code on left click... My favorit virus is executable every time...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2002-02-19
Daniel Spiljar <dspiljar+www@bofhlet.net>
The procmail rule below solved all my problems with incoming HTML cra^H^H^H mail. It also reduced the amount of spam in my mailbox by more than half.

:0
* ^Content-Type: .*(text/html|multipart/alternative)
{
EXITCODE = 65
:0 fw
| echo "571 No HTML junk here"
...

[ more ]  [ reply ]
The problem *is* Outlook, not HTML 2002-02-20
Rasputin (1 replies)
1) Microsoft is responsible for designing an easily exploitable mail client.

2) Blaming the users for not understanding the consequences of those design decisions is like blaming fish for crapping in the water.

3) Blaming the markup language is like blaming the water for the fish crapping in...

[ more ]  [ reply ]
...wrong Rasputin, the problem is the USER and HTML mail...not Outlook 2002-02-22
FudgeFactor7
?1) Microsoft is responsible for designing an easily exploitable mail client.?

No, Microsoft simply designed a client. The exploits are not ?easy? as you put it, but rather a result of the functionality that users (world-wide) demanded be added. The only reason it is exploited is because of Outlo...

[ more ]  [ reply ]
use a nice small txt only pop3 client 2002-02-25
Anonymous
http://www.ultrafunk.com/products/popcorn/

no nags / ads / spyware / whatever

it's free of course...

[ more ]  [ reply ]
Solving the Problem of HTML Mail 2007-10-04
Anonymous
All the problem is caused when you use email. to solve your problem. dont use email. use the good old fashion stamp and paper!...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus