Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Email Privacy is Lost
Scott Granneman, 2004-07-29

As if the common use of "web bugs" inside spam was not enough, companies are using new techniques to watch and track the private emails you read, forward, print, and more.

Comments Mode:
Email Privacy is Lost 2004-07-30
Clownface
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
Email Privacy is Lost 2004-08-03
Damon McMahon <inst_karma@hotmail.com>
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
Email Privacy is Lost 2004-08-04
Anonymous
Email Privacy is Lost 2004-07-30
Matthew Murphy (1 replies)
Scott,

Just FYI, you *can* block e-mail from loading an IFRAME, even with HTML rendering, in Outlook Express and Outlook (all versions).

If you set Outlook (Express) to open e-mail in "Restricted Sites" (default in Outlook 2000 and later, and Outlook Express 6.0 SP1), frames are disabled automatically.

This behavior occurs if MS02-023 or a later IE cumulative patch has been applied, as documented in that bulletin (http://www.microsoft.com/technet/security/bulletin/ms02-023
.mspx), and subsequently included in IE 6.0 SP1.

So, if you are using any combination of Outlook/Outlook Express with e-mail in Restricted Sites, and IE 5.01, IE 5.5, or IE 6.0 with MS02-023 or SP1 applied, this attack vector is already completely blocked.

You can quit holding your breath, in case you were wondering. :-)

Food For Thought,
Matt Murphy

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/258/27757#27757
Email Privacy is Lost 2004-08-04
Anonymous (1 replies)
Email Privacy is Lost 2004-08-11
Matthew Murphy
Email Privacy is Lost 2004-07-31
Anonymous
Email Privacy is Lost 2004-08-02
Anonymous
Email Privacy is Lost 2004-08-02
J.T.
Email Privacy is Lost 2004-08-03
Anonymous
[COMMENT] Email Privacy is Lost 2004-08-03
Bob Radvanovsky
Read/Delivery Receipts in Outlook/Exchange 2004-08-04
An Exchange admin (1 replies)
Email Privacy is Lost 2004-08-11
Anonymous
Email Privacy is Lost 2005-12-14
Anonymous (1 replies)
Re: Email Privacy is Lost 2006-10-08
Anonymous (1 replies)
Re: Re: Email Privacy is Lost 2008-03-05
Anonymous
Email Privacy is Lost 2006-11-25
CC
Email Privacy is Lost 2007-01-24
Anonymous
Email Privacy is Lost 2008-04-14
G2Realtor







 

Privacy Statement
Copyright 2009, SecurityFocus