Re: This one got me...watch out for this trick

From: George Hester (hesterloli_at_hotmail.com)
Date: 03/20/04


Date: Fri, 19 Mar 2004 19:23:34 -0500

I probably should do that. Since I rarely open email I fugured I was smarter then the average bear. Time to rethink that I spz.

-- 
George Hester
__________________________________
"N. Miller" <nsm@blackhole.aosake.net> wrote in message news:MPG.1abc6de79dcff5b6989de0@msnews.microsoft.com...
> In article <um7R58HCEHA.2404@TK2MSFTNGP11.phx.gbl>, hesterloli@hotmail.com 
> says...
> 
> > Actually it is not Attachements that are the worry here.  This has nothing to do with attachments.  The issue is ActiveX retrieved in HTML mail by code such as this:
> 
> > [object code="http;\\thespammer.com"][\object] or [iframe src=""][\iframe]
> 
> > But thanks anyway.  Outlook Express 5.5 has solved these issues but the trick is still there.
> 
> Lock down MSIE against running scripts in the Internet zone. Put MSOE in the  
> Restricted sites zone, and lock that zone down against everything.
> 
> Personally, I can't see the advantage of MSOE 5.5 over MSOE 6.0. If you are 
> going to run MSOE at all, you might as well go with the latest. But what 
> does someone who relies on Pegasus Mail for email and Gravity for news know, 
> eh? I guess I am just not too bright!    ;)
> 
> {Too lazy to insert that snippet of HTML into a faux message for MSOE 6 to 
> chew on. I wonder how unpatched MSOE news readers will react to it? 
> Hopefully my edit defanged that lil' snake.}
> 
> -- 
> Norman
> ~Win dain a lotica, En vai tu ri, Si lo ta
> ~Fin dein a loluca, En dragu a sei lain
> ~Vi fa-ru les shutai am, En riga-lint


Relevant Pages

  • Re: This one got me...watch out for this trick
    ... Restricted sites zone, and lock that zone down against everything. ... I can't see the advantage of MSOE 5.5 over MSOE 6.0. ... I wonder how unpatched MSOE news readers will react to it? ...
    (microsoft.public.security)
  • Re: sender question
    ... I can't block sender 'cause the system thinks it's ... apparently to evade filters by taking advantage ... MSOE should _not_ be allowed to run scripts ... zone, so that should not have happened. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: sender question
    ... I can't block sender 'cause the system thinks it's my ... apparently to evade filters by taking advantage ... MSOE should _not_ be allowed to run scripts ... zone, so that should not have happened. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)