Re: Malware Triangle

From: kurt wismer (kurtw_at_sympatico.ca)
Date: 11/25/04


Date: Wed, 24 Nov 2004 18:38:58 -0500

Jack wrote:
[snip]
> Email is safest with HTML rendition disabled.
>
> Do you disagree?

no disagreement here... but not because html is a threat, rather
because html rendering typically includes a bunch of other things
unrelated to pure html... if there were a rendering engine that *only*
rendered plain old html then it would be about big a security risk as
an xml parser (which are not totally safe, but what is)...

-- 
"maxwell can tell he's in hell
just wants you to visit him there
same old game that he's playin'
his rules are never fair"


Relevant Pages

  • Re: Malware Triangle
    ... >> the fault of the HTML document, it's the rendering application. ... and the whole thing is the threat. ... But I disagree, the HTML is not the problem, neither is the script, it's ...
    (alt.computer.security)
  • Re: How to use a messagebox in asp.net
    ... re-compile and re-release. ... Just put the code direct in the HTML. ... I disagree entirely!!! ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: tarah tarah tarah rah ra
    ... HTML, XHTML,& CSS ALL-IN-ONE For Dummies ... by Andy Harris ... Why I asked about the publishing date is because the HTML used today is a little different to the old way or doing it - if I'm wrong someone will let me know I'm sure;-) ... "To disagree, one doesn't have to be disagreeable." ...
    (uk.people.silversurfers)
  • Re: Send A Reply Message Or Forward A Message Containing Stationary
    ... I'll have to disagree. ... I send plain text only messages. ... If I get replies from people who are nasty enough to convert the reply to HTML, ... Information exchange is the entire idea behind email and stationery never contains substance, ...
    (microsoft.public.outlook.installation)
  • Re: CSS Absolute and Relative Positioning
    ... Martin Eyles wrote: ... > I disagree with this point. ... Now you've had problems with XHTML which don't exist in HTML:) ...
    (comp.infosystems.www.authoring.stylesheets)