[22308] in bugtraq

home help back first fref pref prev next nref lref last post

Re: HTML email "bug", of sorts.

daemon@ATHENA.MIT.EDU (thomas.rowe@bankofamerica.com)
Sun Aug 19 14:53:21 2001

Date: Sat, 18 Aug 2001 23:10:36 -0400
From: thomas.rowe@bankofamerica.com
To: bugtraq@securityfocus.com
Message-id: <86256AAD.00116E61.00@notes.bankofamerica.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-disposition: inline
Content-transfer-encoding: 7BIT



Alex Prestin wrote:
snip
> See it?  A web bug.  If I opened this mail in an HTML-capable browser,
> that little image would've popped up and I would've been none the
> wiser.  My address would also have been verified by the sender, and stored
> in a large database of valid recipients.

snip

And if you were running WinNT 4 and that referrer pointed to a server
advertising a share, NT would send your username and password to try to log
you on without your knowledge. It could be grabbed and sent back to your
machine, logon, and the atttacker would have all rights to your machince and
network that the ID you're using has.
(as I've mentioned before, MS has known about this hole since before SP2)
Cheers

Thomas Rowe
Systems Engineer, LDI
Bank of America
Atlanta, GA



home help back first fref pref prev next nref lref last post