Re: Email webbugs

From: ezat_t (ezyt@optushome.com.au)
Date: 08/28/01


Message-ID: <006a01c12f49$1ee58180$0c14a8c0@co3007101a>
From: "ezat_t" <ezyt@optushome.com.au>
To: "abuse" <postmaster@getinfo.org>, "Focus-MS" <focus-ms@securityfocus.com>
Subject: Re: Email webbugs
Date: Tue, 28 Aug 2001 08:39:23 +1000

Does your test work?"

Im very interested in this but getting

----- Original Message -----
From: "abuse" <postmaster@getinfo.org>
To: "Focus-MS" <focus-ms@securityfocus.com>
Cc: "VULN-DEV@SECURITYFOCUS. COM" <VULN-DEV@SECURITYFOCUS.COM>;
"BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ@SECURITYFOCUS.COM>;
<win2ksecadvice@LISTSERV.NTSECURITY.NET>
Sent: Monday, August 27, 2001 10:12 PM
Subject: Email webbugs

> One of the things that has always bothered me about Outlook Express and
> Outlook is that they are susceptable to webbugs. Basically there are no
> options to block confirmation of your reading an email so any spammer can
> verify that your address is active as long as they can get you to just
view
> an email.
>
> A lot of people have difficulty understanding exactly what this means so I
> set up a demonstration page at http://www.nthelp.com/OEtest/oe.htm in an
> attempt to raise awareness of this nonsense and get MS to do something
about
> it. I don't know if other email programs like Eudora and Netscape are
> vulnerable to email webbugs so if anyone tests those please let me know
the
> results.
>
> Anyway, I've made the test site available to the public now so if you want
> to check your email reader, feel free.
>
> Geo.
>



Relevant Pages

  • RE: Email webbugs
    ... Subject: Email webbugs ... U have an option to avoid send a confirmation in: ... This sequence in Outlook 2000 but in OE and in other versions is very ... Esta secuencia es para Outlook 2000, ...
    (Vuln-Dev)
  • RE: Email webbugs
    ... Subject: Email webbugs ... None of that addresses the point which is that outlook and outlook express ... How about I do a mailing to you, and set a cookie which identifies you by ... > I've created Eudora rules that look for image tags with height ...
    (Focus-Microsoft)
  • Re: Email webbugs
    ... In Outlook Express - Have you tried configuring this through Tools - ... Options - Receipts - Returning Read Receipts? ... vulnerable to email webbugs so if anyone tests those please let me know ... I've made the test site available to the public now so if you want ...
    (Vuln-Dev)
  • RE: Email webbugs
    ... Subject: Email webbugs ... > outlook express can not be set to avoid the exploit. ... > How about I do a mailing to you, and set a cookie which identifies you by ...
    (Focus-Microsoft)
  • Re: Email webbugs
    ... Subject: Email webbugs ... Spammer X sends you an HTML mail with an invisible image from his site ... When you read this email in Outlook, the image is downloaded from ... If the image is generated by a CGI script he can log the time you read your ...
    (Vuln-Dev)