Likes Likes:  0
Resultaten 1 tot 7 van de 7
Geen
  1. #1
    Richard M. Smith
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Email marketing company gives out questionable security advice

    Hi,

    Last week, I received an unsolicited email message from Mobil Travel
    Guide about their new online service. In the message, I was encouraged
    to turn back on ActiveX and scripting in Outlook in order to view a
    Flash movie embedded in the message. Needless to say, I thought this
    was a terrible idea. Instead, I wrote the company who created the ad,
    Digital Produce (http://www.digitalproduce.com), saying they were giving
    out bad security advice and they should stop doing this sort of thing
    in future mailings.

    I got a reply from the company this week basically saying that they
    agree with my concern, but not my solution. Instead they decided to put
    a little security warning on their "real media fix" page. This fixer
    page can be found here on their Web site:

    http://www.digitalproduce.com/site_r...fs/outlookfix/

    I think the warning message is pretty lame and misleading. Microsoft
    released the Outlook Security Update a few years back because anti-virus
    software wasn't stopping email worms. Turning back on ActiveX and
    scripting only encourages the virus writers.

    (As an aside, the Xbox division of Microsoft is also a customer of
    Digital Produce. I wonder if any Xbox ads gave out this same bad
    security advice?)

    OTOH, it's not too hard too understand where Digital Produce is coming
    from. According to a recent article in Internet News, only about 30% of
    email users can view rich media email. This percentage is declining as
    people upgrade Outlook and Outlook Express to newer versions with better
    security features. It's pretty obvious that Flash-enabled email is a
    dying market.

    Along these same lines, images in HTML email messages will be the next
    thing to go. The upcoming versions of Outlook and the AOL 9.0 email
    reader will no longer show images in HTML email messages by default.
    Hotmail offers this same feature as an option today. This feature is
    intend to make email more kid-friendly by blocking porno pictures in
    incoming spam messages. It also stops spammers for snooping on people
    using Web bugs.

    It will be interesting to see how email marketing companies and
    spammers adapt to these technical changes in HTML email.

    Richard M. Smith
    http://www.ComputerBytesMan.com



  2. #2
    stonewall
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    I am continually amazed at the number of web sites which are unusable when
    java and ActiveX are disabled. Generally, html geeks get paid to make cool
    web sites (and email) which use all the local/interactive "make your machine
    do things" features; most don't seem to be aware of (or care about) the
    security implications. Try blocking active content at your firewall and see
    how long it takes for clients to complain about not being able to use web
    sites (even medical practice / insurance company web sites), not being able
    to get emails/attachments, etc. Education efforts aside, this puts us in
    the position of having to field complaints about "the damn firewall". Does
    anyone else deal with this?

    - stonewall

    ----- Original Message -----
    From: "Richard M. Smith" <rms@computerbytesman.com>
    To: "BUGTRAQ@SECURITYFOCUS. COM" <BUGTRAQ@SECURITYFOCUS.COM>
    Sent: Wednesday, July 02, 2003 8:03 PM
    Subject: Email marketing company gives out questionable security advice


    > Hi,
    >
    > Last week, I received an unsolicited email message from Mobil Travel
    > Guide about their new online service. In the message, I was encouraged
    > to turn back on ActiveX and scripting in Outlook in order to view a
    > Flash movie embedded in the message. Needless to say, I thought this
    > was a terrible idea. Instead, I wrote the company who created the ad,
    > Digital Produce (http://www.digitalproduce.com), saying they were giving
    > out bad security advice and they should stop doing this sort of thing
    > in future mailings.
    >
    > I got a reply from the company this week basically saying that they
    > agree with my concern, but not my solution. Instead they decided to put
    > a little security warning on their "real media fix" page. This fixer
    > page can be found here on their Web site:
    >
    > http://www.digitalproduce.com/site_r...fs/outlookfix/
    >
    > I think the warning message is pretty lame and misleading. Microsoft
    > released the Outlook Security Update a few years back because anti-virus
    > software wasn't stopping email worms. Turning back on ActiveX and
    > scripting only encourages the virus writers.
    >
    > (As an aside, the Xbox division of Microsoft is also a customer of
    > Digital Produce. I wonder if any Xbox ads gave out this same bad
    > security advice?)
    >
    > OTOH, it's not too hard too understand where Digital Produce is coming
    > from. According to a recent article in Internet News, only about 30% of
    > email users can view rich media email. This percentage is declining as
    > people upgrade Outlook and Outlook Express to newer versions with better
    > security features. It's pretty obvious that Flash-enabled email is a
    > dying market.
    >
    > Along these same lines, images in HTML email messages will be the next
    > thing to go. The upcoming versions of Outlook and the AOL 9.0 email
    > reader will no longer show images in HTML email messages by default.
    > Hotmail offers this same feature as an option today. This feature is
    > intend to make email more kid-friendly by blocking porno pictures in
    > incoming spam messages. It also stops spammers for snooping on people
    > using Web bugs.
    >
    > It will be interesting to see how email marketing companies and
    > spammers adapt to these technical changes in HTML email.
    >
    > Richard M. Smith
    > http://www.ComputerBytesMan.com
    >
    >



  3. #3
    D. J. Bernstein
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    Richard M. Smith writes:
    [ mail readers disabling inline images ]
    > It will be interesting to see how email marketing companies and
    > spammers adapt to these technical changes in HTML email.


    ASCII porn, perhaps? Especially if the sender can control the color, and
    size, of text. I suppose those will be the next casualties in the war on
    spam.

    It's quite depressing that this is what people think of as ``security'':
    patch maniacally; install a scanner that checks for yesterday's attacks;
    don't view the pictures, don't drink the water, don't breathe the air.

    I've been playing with a radically different system design (I'm thinking
    of calling it ``UNIX'') where conceptually separate tasks are split into
    separate processes. If you want to gunzip a stream of data, for example,
    you run a gunzip program in its own chroot jail, under its own uid, with
    no way to read any interesting data except through a predefined IPC hook
    (I'm thinking of calling that a ``pipe'' on ``standard input'') and with
    no way to touch anything except through another predefined IPC hook. The
    only thing that an attacker can do by taking over this gunzip program is
    generate arbitrary output data, which he could have done anyway. Typical
    picture-generating programs can be isolated in the same way.

    ---D. J. Bernstein, Associate Professor, Department of Mathematics,
    Statistics, and Computer Science, University of Illinois at Chicago

    P.S. It's hard for a portable chroot tool to cut off a program's network
    access. Kernel designers should provide a disablenetwork() syscall, with
    the disabling inherited by children. Other kernel changes would be nice,
    but disablenetwork() is the only critical change.

  4. #4
    Gadgeteer
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    On Friday 04 July 2003 13:05, stonewall wrote:
    > Education efforts aside, this
    > puts us in the position of having to field complaints about "the damn
    > firewall". Does anyone else deal with this?


    We do considerable filtering/blocking for some of our customers. We have
    found that there is a significant reduction in complaints if the filter
    returns a friendly error message to inform the user that things are going
    according to plan rather then allowing an access attempt to fail silently.
    YMMV
    --
    Ken Dyke
    Chief Gadgeteer, Elegant Innovaions

  5. #5
    Richard Rager
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    On 4 Jul 2003, D. J. Bernstein wrote:

    > Richard M. Smith writes:
    >
    > P.S. It's hard for a portable chroot tool to cut off a program's network
    > access. Kernel designers should provide a disablenetwork() syscall, with
    > the disabling inherited by children. Other kernel changes would be nice,
    > but disablenetwork() is the only critical change.
    >

    Look at selinux. You can drop any privleges under selinux or Bull Dog
    or you can uses Linux Socket Filtering is user space with kernel 2.4.18+
    --

    Enjoy,

    Richard Rager




  6. #6
    Roland Dowdeswell
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    On 1057360640 seconds since the Beginning of the UNIX epoch
    "D. J. Bernstein" wrote:
    >


    >P.S. It's hard for a portable chroot tool to cut off a program's network
    >access. Kernel designers should provide a disablenetwork() syscall, with
    >the disabling inherited by children. Other kernel changes would be nice,
    >but disablenetwork() is the only critical change.


    There are tools such as systrace:

    http://www.citi.umich.edu/u/provos/systrace/

    which comes standard in NetBSD and OpenBSD and has been ported to
    various other UNIX platforms which can do what you want.

    --
    Roland Dowdeswell http://www.Imrryr.ORG/~elric/

  7. #7
    D. J. Bernstein
    Email marketing company gives out questionable security advice
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Email marketing company gives out questionable security advice

    I wrote:
    : P.S. It's hard for a portable chroot tool to cut off a program's network
    : access. Kernel designers should provide a disablenetwork() syscall, with
    : the disabling inherited by children.

    I've set up a web page http://cr.yp.to/unix/disablenetwork.html
    discussing this and surveying the system-specific suggestions that
    people have sent to me. Further contributions are welcome.

    ---D. J. Bernstein, Associate Professor, Department of Mathematics,
    Statistics, and Computer Science, University of Illinois at Chicago

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics