Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Knock, Knock, Knock
Kelly Martin, 2004-02-20

If hundreds of thousands of people are still blindly clicking on attachments in their email, is there any hope of mitigating the threat of hundreds of thousands of compromised systems with open backdoors?

Comments Mode:
Knock, Knock, Knock 2004-02-20
Dmitriy (1 replies)
Knock, Knock, Knock 2004-02-24
Keith (4 replies)
Knock, Knock, Knock 2004-02-26
Anonymous
Knock, Knock, Knock 2004-02-27
Farzad
Knock, Knock, Knock 2004-03-01
Anonymous
Knock, Knock, Knock 2004-03-01
www.mobasoft.com
Knock, Knock, Knock 2004-02-20
Anonymous (2 replies)
Knock, Knock, Knock 2004-02-25
Anonymous (1 replies)
HTML/MIME vulnerability (and avoidance) 2004-02-26
Anonymous
Nope - MIME provides just a transport, as does SMTP headers.

Reasonably sane programming handles that.

HTML interpreters are truly horrible things to debug. Avoiding HTML flat out avoids:

a. javascript interpreters
b. image loaders
c. additional network connections
d. other interpreters (PDF, Postscript, ... though these might remain vulnerability points if MIME interpreters are allowed)
e. Active X
f. general browser vulnerabilities.

These have ALL been known failure points ever since about 1990, and the web started to exist. MIME vulnerability points have been known ever since the standard was created. Even then, the warning was "don't use an interpreter that you don't trust".

Guess what. I don't trust any of them.

I would much prever a plain jane text viewer -- such as Pine

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/221/25198#25198
Knock, Knock, Knock 2004-03-03
Anonymous
Knock, Knock, Knock 2004-02-21
Anonymous
Ok Double Sided Swords 2004-02-21
Anonymous
Knock, Knock, Knock 2004-02-24
Jack (1 replies)
Knock, Knock, Knock 2004-02-28
Anonymous
Knock, Knock, Knock 2004-02-25
Anonymous
Knock, Knock, Knock 2004-02-26
fndude@hotmail.com
Knock, Knock, Knock 2004-02-27
Anonymous
Pretty easy solution 2004-02-27
Potato Head
Knock, Knock, Knock 2004-03-01
Robert Townley







 

Privacy Statement
Copyright 2007, SecurityFocus