lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <012301c3bf42$25b17740$a800a8c0@cryo>
From: clint at secureconsulting.com (Clint Bodungen)
Subject: RE: FWD: Internet Explorer URL parsing vulnerability

I've been getting spam accusation bouncebacks from about 4 people now on this thread.  Seems like the entire City of Ft. Worth, TX has a nice big brother in place:

The City of Fort Worth has implemented a spam filter.
If you are receiving this message the original e-mail was
determined to be spam and not delivered to its destination.

If this mail is not spam please contact postmaster@...tworthgov.org.

Why the filter thinks this is SPAM:
Message scored 5.5 out of a required 5.0 positive tests.

 3.1 USERPASS               URI: URL contains username and (optional) password
 2.4 HTTP_ESCAPED_HOST      URI: Uses %-escapes inside a URL's hostname

  ----- Original Message ----- 
  From: Exibar 
  To: full-disclosure@...ts.netsys.com 
  Sent: Wednesday, December 10, 2003 10:32 AM
  Subject: Re: RE:Re: [Full-Disclosure] RE: FWD: Internet Explorer URL parsing vulnerability


  I'll bet that this guy doesn't get half of the e-mail he's expecting.....
    ----- Original Message ----- 
    From: AntiSpam UOL 
    To: exibar 
    Sent: Wednesday, December 10, 2003 11:24 AM
    Subject: RE:Re: [Full-Disclosure] RE: FWD: Internet Explorer URL parsing vulnerability


           
                   
                Ol?,

                Voc? enviou uma mensagem para igorcarboni@....com.br
                Para que sua mensagem seja encaminhada, por favor, clique aqui

                 
                Esta confirma??o ? necess?ria porque igorcarboni@....com.br usa o Antispam UOL, um programa que elimina mensagens enviadas por rob?s, como pornografia, propaganda e correntes.

                As pr?ximas mensagens enviadas para igorcarboni@....com.br n?o precisar?o ser confirmadas*.
                *Caso voc? receba outro pedido de confirma??o, por favor, pe?a para igorcarboni@....com.br inclu?-lo em sua lista de autorizados.

                      Aten??o! Se voc? n?o conseguir clicar no atalho acima, acesse este endere?o:
                      http://tira-teima.as.uol.com.br/challengeSender.html?data=0C%2BUJvHozYJSDqZeA8HoOXNcbzbyiHEE3QzKqhfTF1HUOTBn1aqyyGwiKIDeJjPbp0yF0rvLLtZ6%0AsFFiP8xdcyjr4oCMD52UFgokem8uLA2kizdJ9sULFX2k6qEGIpi9M9tWre91YYEGWxvTFakHfCXx%0AeHSlqe1A81RX54%2B4dtQ7lvqbPrYbrDL05uyupFnrKCrmLQ3YFLlWOhxOWFK6nw%3D%3D 
               
         

----------------------------------------------------------------------
         
                   
                Hi,

                You?ve just sent a message to igorcarboni@....com.br
                In order to confirm the sent message, please click here

                 
                This confirmation is necessary because igorcarboni@....com.br uses Antispam UOL, a service that avoids unwanted messages like advertising, pornography, viruses, and spams.

                Other messages sent to igorcarboni@....com.br won't need to be confirmed*.
                *If you receive another confirmation request, please ask igorcarboni@....com.br to include you in his/her authorized e-mail list.

                      Warning! If the link doesn?t work, please copy the address below and paste it on your browser:
                      http://tira-teima.as.uol.com.br/challengeSender.html?data=0C%2BUJvHozYJSDqZeA8HoOXNcbzbyiHEE3QzKqhfTF1HUOTBn1aqyyGwiKIDeJjPbp0yF0rvLLtZ6%0AsFFiP8xdcyjr4oCMD52UFgokem8uLA2kizdJ9sULFX2k6qEGIpi9M9tWre91YYEGWxvTFakHfCXx%0AeHSlqe1A81RX54%2B4dtQ7lvqbPrYbrDL05uyupFnrKCrmLQ3YFLlWOhxOWFK6nw%3D%3D 
               

         
          Use o AntiSpam UOL e proteja sua caixa postal 
         
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20031210/834e2bcd/attachment.html

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ