Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Solving the Problem of HTML Mail
Shane Coursen, 2002-02-04

Now there are options for screening potentially dangerous messages, or even eliminating HTML email from your life.

Comments Mode:
Three things to make HTML email bearable 2002-02-04
TL (2 replies)
How about RTF as a format instead of HTML? 2002-02-10
LA Walsh (1 replies)
I end up using HTML in mail messages because so few
mailers understand Rich-Text-Format -- maybe that's
a MS-only thing...( :-( ). But, often, all I want is
some very primitive things like *bold*, _italics_,
and _UNDERLINE_(?).

Even the ability to use auto-text wrapping -- I like GUI editors, but to my limited knowledge, most of them don't
have primitive features like 'reformat paragraph'. For
example. I edit my email after composition and move, delete, or shorten a sentence. Now in a plain text world, I'm going to have one line that is going to be out of alignment.

Even in little compose windows like this one -- did I press
at the end of some lines by habit or did I allow them to flow to the next line.

I think the main security threats are any components that try to set cookies, require external (to the email) references, and any scripting, no? Isn't it possible to come up with a standard subset of 'safe' HTML?

Even things like -- I'd like to choose whether or not to
display my text in fixed, or proportional. Nothing worse than to have a user compose a table in fixed, then a
reader views in proportional.

Anyway -- it really would be nice if there was a defined and filterable subset just to allow text lay out without all the risks of full HTML.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/58/10454#10454
Solving the Problem of HTML Mail 2002-02-04
Roland <r s m i t h AT x s 4 a l l . n l >
Don't use Outlook 2002-02-04
Anonymous (2 replies)
Don't use Outlook 2002-02-06
Anonymous (2 replies)
Don't use Outlook 2002-02-08
Anonymous (2 replies)
Don't use Outlook 2002-02-16
Anonymous
Don't use Outlook 2002-02-16
Anonymous
Don't use Outlook 2002-02-07
trowe
Solving the Problem of HTML Mail 2002-02-04
Tony Turner
Solving the Problem of HTML Mail 2002-02-05
Dr. Gerry Hecht
Solving the Problem of HTML Mail 2002-02-06
Anonymous
users 2002-02-06
Stefan Caunter
HTML mail is for Teletubbies 2002-02-07
lala@po.com
this comment page... 2002-02-08
WetBlanket
Procmail on the Mail Server is a Real Solution 2002-02-12
Analysis and Solutions
consumers love text/html 2002-02-12
Anonymous
Solving the Problem of HTML Mail 2002-02-13
Anonymous
Solving the Problem of HTML Mail 2002-02-14
Old Fogie (aeaton@fdic.gov)
We nead assambly... Order is dump 2002-02-16
Anonymous
Solving the Problem of HTML Mail 2002-02-19
Daniel Spiljar <dspiljar+www@bofhlet.net>
Solving the Problem of HTML Mail 2007-10-04
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus