[Full-Disclosure] Outlook "cid:" handling - Request for Information

From: James Tucker (jftucker_at_gmail.com)
Date: 10/15/04

  • Next message: Luke Macken: "[ GLSA 200410-10 ] gettext: Insecure temporary file handling"
    To: Disclosure Full <full-disclosure@lists.netsys.com>
    Date: Fri, 15 Oct 2004 00:19:29 +0100
    
    

    Outline:
    ======
    It has recently come to my attention that it is possible to circumvent
    functions inside of Microsoft Outlook 2003 and some other MUA's by
    using href tags containing "cid:". By default such MUAs no longer
    download web referenced images and objects, however images referenced
    by "cid:" strings are embedded (as attachments with special names)
    within the e-mail.

    Contrary to the policy of not downloading images, it would seem that
    these are packaged with the mail (decentralised) AND are displayed
    despite non-image download policies.

    Some limited details of the "Compatible ID" processing in MS Outlook
    is detailed by the vendor here:
    http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q270922

    Request:
    =======
    If anyone knows of a configurations which can be set to disable ALL
    image processing in affected MUAs such information would be very
    valuable to me.

    Potential Impact:
    =============
    It is true that many updates for the affected software groups (office,
    windows) remove currently known vulnerabilities that could be
    exploited using this method. New vulnerabilities of the nature we have
    seen recently would be very easy to mass produce with decentralised
    (non-server based) attacks utilising this method.

    At this time there is no reason why this has not been used more
    extensively (best I can tell support for this method has been
    available for quite some time ( as early as 2001 and possibly much
    longer )).

    During the early days of the recent jpeg GDI exploit I am surprised
    this method of infection was not further abused. Spread of such a
    thing would have been rapid, as the "user stupidity" requirement for
    infection is near eradicated when using this method. The only savior
    would have been in the AV companies rapid deployment of a pattern to
    match infected images.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Luke Macken: "[ GLSA 200410-10 ] gettext: Insecure temporary file handling"

    Relevant Pages

    • Re: Image Quality
      ... adjustment for download speed/picture quality. ... >> Zone Alarm Pro can block Images in IE ... >> Pictures Are Not Displayed on Web Sites in Internet Explorer ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: images
      ... There should be a "Download Pictures" button that appears in a light-yellow ... such cases usually quitting and re-launching Entourage will fix the problem. ... Protection) to make sure that the images display automatically. ... make sure these preferences are checked: ...
      (microsoft.public.mac.office.entourage)
    • Re: Printing pages from web sites.
      ... understand why people might like to download and print copies. ... my audience to those users who are using at least a resolution of 1024 ... x 768 and a display that is not smaller than 15 inches. ... resolution images are available for a payment and access to their work ...
      (microsoft.public.frontpage)
    • Re: Child rape pics on teens site
      ... sites to distribute MILLIONS of vile child-rape images. ... download MP3 songs are fully aware of how Limewire works, ... offers illegal images and note the IP of people who download the ... If you recall, your stash of porn, music whatever was automatically placed in someone elses share directory, encrpted so that that person would be unaware whether it was porn or music or whatever. ...
      (uk.legal)
    • Re: LOC releases online historic newspapers
      ... A FREE viewer that works with JP2 images is IrfanView. ... download it and download all of the available plug-ins. ...
      (rec.music.ragtime)

  • Quantcast