Re: [fw-wiz] HTML Emails and Firewall Security

From: Paul Robertson (proberts_at_patriot.net)
Date: 07/31/03

  • Next message: seclist_at_wiresec.net: "[fw-wiz] looking for some good docs on setting up service networks"
    To: Gary Flynn <flynngn@jmu.edu>
    Date: Thu, 31 Jul 2003 08:39:51 -0400 (EDT)
    
    

    On Thu, 31 Jul 2003, Gary Flynn wrote:

    > Consider if your email to the list was HTML and contained a link to
    > an image. When read with Microsoft's clients, web clients, and Navigator
    > in certain configurations, my computer would go fetch the link and
    > give you my IP address even if I don't reply to your e-mail. If I
    > forward the message, you'll have a trail of who I forwarded it too.
    > Nice recon tool in unNATed environments if you're looking for the
    > desktop IP addresses used by specific individuals or roles.

    It used to be worse than that- the server used to be able to get the
    client to attempt to send domain authentication information. I think
    this was fixed a while back though.

    > That said, we have no plans to ban HTML email.

    As for desktop IPs, Outlook Express hands them out, if exposing IPs is a
    significant issue, then you've likely got bigger problems. At my last
    employer, we had two routable /16's internally- I wasn't all that
    concerned about IP address "leakage."

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: seclist_at_wiresec.net: "[fw-wiz] looking for some good docs on setting up service networks"

    Relevant Pages

    • Re: FSMO roles transfer
      ... Paul Bergson ... MVP - Directory Services ... authentication (Other than the PDCe if there was a recent password ... In my case DC 1 failed so shouldn't the clients be resolving ...
      (microsoft.public.windows.server.active_directory)
    • Re: Lost Resources
      ... Hi Paul - See my reply to Weber? ... AT&T Network Client - IBM I did a Ipconfig /all and the DNS is different as ... the clients in site H point to dns services in site H and another site (If ...
      (microsoft.public.windows.server.active_directory)
    • Re: FTP Server could not create a client worker thread for user at host
      ... Paul - you're a genius! ... >>subnet try to login to the ftp server. ... Clients in the subnet do not have ... The Web server is using integrated authentication. ...
      (microsoft.public.inetserver.iis)
    • Re: Request - Can Advanced Clients Report as Member of Secondary Sites
      ... newsgroup is for questions relating to Microsoft Exchange Server. ... > This is Paul Keller. ... > Sites and Advanced Clients. ... > report as members of the secondary sites where they are ...
      (microsoft.public.exchange.misc)
    • Re: Sites and Services Subnets not working
      ... It's mostly VPN and wireless clients ... I'm not 100% sure DNS is working correctly. ... This should list all unlisted subnets where machines don't find a home in ... Paul Bergson ...
      (microsoft.public.windows.server.active_directory)