[VulnWatch] Security issue in Microsoft Outlook

From: Bakchodiya (bakchodiya_at_yahoo.com)
Date: 05/19/05

  • Next message: ZATAZ.net: "[VulnWatch] shtool insecure temporary file creation"
    Date: Thu, 19 May 2005 05:08:48 -0700 (PDT)
    To: ntbugtraq@listserv.ntbugtraq.com
    
    

    An issue has been discovered in MS Outlook (All
    Versions) where anyone can fake a URL & send it
    across.

    How does it work:

    Lets compose an email in MS Outlook, lets type

    http://www.cybertrion.com & put a space after it to
    make it a link. Now put your cursor just before
    cybertrion & type any URL for eg:
    http://www.foo-labs.info now send it to anyone. The
    receiver will see the URL as http://www.foo-labs.info
    but when he clicks on it it will directly take him to
    http://www.cybertrion.com

    I am not sure how critical this is but it can fool
    alot of people & result in download of a virus.

    For more Visit:
    http://www.cybertrion.com

    Discovered by:
    Cybertrion Systems
    http://www.cybertrion.com

                    
    Discover Yahoo!
    Find restaurants, movies, travel and more fun for the weekend. Check it out!
    http://discover.yahoo.com/weekend.html


  • Next message: ZATAZ.net: "[VulnWatch] shtool insecure temporary file creation"

    Relevant Pages

    • Slow Slow
      ... XP Office Pro with Outlook 2002. ... What I did discover by carefully studying Task ... I Killed MSN Messenger and opened ...
      (microsoft.public.outlook.general)
    • Re: Need to recover data from Outlook but program wont stay open.
      ... Turns out the hard drive was intact but some components ... I was relieved to discover that my data was ... the PST file in Outlook for me. ... re-install the program, but when I tested the back-up PST file on another ...
      (microsoft.public.office.misc)
    • Re: Need to recover data from Outlook but program wont stay open...
      ... Turns out the hard drive was intact but some ... I was relieved to discover that my data was ... the PST file in Outlook for me. ... re-install the program, but when I tested the back-up PST file on another ...
      (microsoft.public.office.misc)
    • Re: Need to recover data from Outlook but program wont stay open...
      ... Turns out the hard drive was intact but some components ... I was relieved to discover that my data was ... the PST file in Outlook for me. ... re-install the program, but when I tested the back-up PST file on another ...
      (microsoft.public.office.misc)
    • Outlook 2003 program glitch
      ... Who can I talk to about a program glitch that I just discovered with Outlook ... after spending several evenings creating a custom Contact ... form with extra critical fields for my business, I was shocked to discover ...
      (microsoft.public.outlook.contacts)