Mumbai-Central.comWhere Mumbaikars meet |
----------------------------------------------------------------------------
Tip of the day: Smile!
----------------------------------------------------------------------------
Hi,
We are all familiar with the problems of HTML email (wasted bandwith
and storage space, slow loading times, bad appearance in text
interfaces among others) but here is a more serious problem.
Please configure your email programs to send only text (plain text)
messages.
Thanks, - 'shal
--- Forwarded message from the Privacy Foundation: ---
Hello,
The Privacy Foundation has issued a privacy advisory today
describing a serious problem with the Outlook, Outlook Express,
and Netscape 6 email readers. By adding a small bit
of JavaScript code to an HTML email message, the sender
of a message can listen in on comments added to the
message whenever the message is forwarded to anyone else
by the original receiver of the message.
We have nicknamed the problem "email wiretapping". The exploit
is not based on any security hole, but uses standard,
documented features of JavaScript to read the contents
of a email message. A Web bug or hidden form can
be used to transmit the contents of the message back to
the sender. The JavaScript code is copied each time
the message is forwarded or replied to by vulnerable
email readers.
Some of the possible uses of the exploit include:
- In a negotiation conducted by email, one side can
learn the bargaining position of the other side
- To extract off-the-record remarks from governmental
or company officials
- To harvest email addresses as a chain letter
is being circulated.
The complete advisory can be found at:
http://www.privacyfoundation.org/advisories/advemailwiretap.html
The problem was originally found by Carl Voth and his write-up can be
found at:
http://www.geocities.com/ResearchTriangle/Facility/8332/reaper-exploit-release.html
The New York Times also has a story about the problem
in today's paper. The story is available online at:
http://www.nytimes.com/2001/02/05/technology/05JAVA.html
Richard
PS. The message is not bugged! ;-)
--
http://www.mumbai-central.com : Where Mumbaikars meet
Send email to get-bse@mumbai-central.com for the latest BSE listings
and to get-nse@mumbai-central.com to get the latest NSE listings
------------------------------------------------------------------------------
To Subscribe [Unsubscribe] send a blank message to
nukkad-list-request@mumbai-central.com
with the word 'subscribe' ['unsubscribe'] (without quotes) in the Subject
of your message.
The list is archived at http://www.mumbai-central.com/nukkad/archive.html
Use the form below to subscribe or unsubscribe to the list.
|
Site directory
|
Today's news
|
Film reviews
|
likhaai
|
nukkad
|
Stocks
|
Discussion boards
|
Photos
|
Puzzles
Restaurant Guide | Train Guide | Bus Guide | Mumbai Information | Image Galleries About us | Advertise here! | Feedback Donate Sponsored Link: Are There Lucky Planets In Your Astrological Marriage House? | Articles on travel and USA-specific tips |
|
|
Get notified about site updates To get updates about the Mumbai-Central.com site via email (only 1-2 messages per month), sign up! |
|