lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <200405121938.53937.arutha@gmx.de>
From: arutha at gmx.de (Alexander Gretencord)
Subject: leaking

On Wednesday 12 May 2004 17:01, Alerta Redsegura wrote:
> Are you going to tell me you didn't see this ad in your MUA?
> Then, it doesn?t render HTML!

In fact yes I will tell you that. My MUA renders HTML (if you tell it to 
render it globally or if you tell it exokicitly for a specific mail). but 
does not load external references.

So if I get a html only mail I can read it rendered but any pictures (ads, web 
bugs, whatever) are not loaded at all. The Client? Look at my headers.

You can enable loading external references in the config though but it's 
disabled by default.

> Since the ignomious "web bug" is only a simple plain vainilla ad contained
> in all messages sent from Rediffmail, a web based mail service.

Yes but to be useful it has to be an url referring to a server under control 
of the sender. Something my KMail won't load even when redenring a html mail 
with pictures and and other stuff in it. As long as pictures are embedded in 
the mail they are displayed when html is redenred but not if they are 
external URLs.


Alex


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ