lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20040320105433.GK327@ngolde.de>
From: nion at gmx.net (Nico Golde)
Subject: NEVER open attachments

Hallo VB,

* VB <vb@...smart.com> [2004-03-20 11:03]:
> Isnt this what we have been taught? haven't we tried to pound this simple
> rule into the heads of our users? Do we not practice what we preach? then
> why do several users of this list only send messages and replies as
> attachments?

because this is when you sign you message with gpg and you don't use
inline signing.

> I'm sure
> Valdis.Kletnieks@...edu <Valdis.Kletnieks@...edu>, Nico Golde, Frank Knobbe,
> et al have wonderful things to say and contribute great things to this list,
> but i have never read anything they post because they post as attachments.

i hope you can read the message, if i don't sign it.
but i think it depends on your mailer.
i never heard about this problem from people who don't use outlook(like
you too).

> Yes, granted, they are .txt attachments but that is no excuse as it's just a
> matter of time before they are exploited. In fact, they have been exploited,
> one can pad spaces after the .txt to hide the true extension of a malicious
> file. more .txt exploits are probably just around teh corner.

oh god, you never used gpg.

> So, why do these folks post attachments? Why is this even permitted? I would
> love to hear what these people have to say, but i cannot break my own rule
> to find out.

try to use another mailer.
if many people here have the same problem i will not sign my mails in
the future to this mailinglist in the hope that all can read my mails.
regards nico
-- 
Nico Golde                | nico@...lde.de      | 310777820@ICQ | nion@....net
http://www.ngolde.de      | GnuPG Key: http://www.ngolde.de/gpg/nico_golde.gpg
Fingerprint               | FF46 E565 5CC1 E2E5 3F69  C739 1D87 E549 7364 7CFF 
echo             "[q]sa[ln0=aln256%Pln256/snlbx]sb729901041524823122snlbxq"|dc


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ