Likes Likes:  0
Resultaten 1 tot 12 van de 12
Geen
  1. #1
    http-equiv@excite.com
    TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")



    Friday, July 25, 2003

    Active Scripting and HTML in a plain text mail message:

    MIME-Version: 1.0
    Content-Type: text/plain;
    Content-Transfer-Encoding: 7bit
    X-Source: 25.07.03 http://www.malware.com

    <img dynsrc=javascript:alert()><font color=red>foo


    The above is a legitimate RFC822 mail message in plain text.
    Ordinarily one would require an html mail message [Content-Type:
    text/html;] to parse html and scripting. The above functions under a
    plain text mail message in Outlook Express 6.00 and Outlook Express
    5.5 [perhaps others]. Outlook Exprss 6 has restricted zone as default
    as well as an option to read messages in plain text [use it !]. Other
    versions do not.

    This was definitely fixed way back when:

    [see: http://www.securityfocus.com/bid/3334 ]

    And now appears to be back.

    It can be of interest to admins who filter based on content type at
    the gateway, as well as newsgroup operators who do the same [less so
    as comprehensive].

    Notes:

    1. We're working on html in the 'plain text' zone of OE6 next.
    2. None.


    End Call

    --
    http://www.malware.com






  2. #2
    Kee Hinckley
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    At 8:35 PM +0200 7/25/03, Denis Jedig wrote:
    >Internet Explorer seems to take no offense on Content-Types either -
    >text/plain from a web server is happily rendered as HTML, if it
    >contains valid tags.


    It has long been a standard assertion that programs should produce
    standard-complaint protocols, but be lenient in accepting data
    contrary to the standard. Microsoft has taken this one step further.
    In addition to attempting (not unreasonably) to try and guess what
    the user is trying to do, they've written code that tries to guess
    what a remote client or server is trying to do. I think a history of
    Microsoft security holes clearly shows that this is *not* an
    appropriate programming practice. The acceptance of incorrect data
    makes security scanning by intermediate parties extremely difficult.
    Attempting to "correct" for incorrect remote behavior benefits
    nobody. It encourages programs and people to generate incorrect
    code, and it opens up security holes when by the standard there ought
    to be none. We've seen this time after time in things like HTML code
    embedded in JPEG comments, decimal IP addresses using intentional
    overflows, and a plethora of other cases. Policies that make sense
    in dealing with end user actions can be deadly when used with remote
    standards and protocols.

    (Of course this policy also has the side effect of making it
    extremely difficult for smaller players to compete with the dominant
    one, since they have to be bug-for-bug compatible.)
    --
    Kee Hinckley
    http://www.messagefire.com/ Anti-Spam Service for your POP Account
    http://commons.somewhere.com/buzz/ Writings on Technology and Society

    I'm not sure which upsets me more: that people are so unwilling to accept
    responsibility for their own actions, or that they are so eager to regulate
    everyone else's.

  3. #3
    Denis Jedig
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    http-equiv@excite.com wrote:
    > Content-Type: text/plain;
    > [...]
    > <img dynsrc=javascript:alert()><font color=red>foo
    >
    > The above is a legitimate RFC822 mail message in plain text.
    > Ordinarily one would require an html mail message [Content-Type:
    > text/html;] to parse html and scripting.


    Internet Explorer seems to take no offense on Content-Types either -
    text/plain from a web server is happily rendered as HTML, if it contains
    valid tags.

    Denis Jedig
    syneticon GbR


  4. #4
    Fabio Pietrosanti
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")


    MIME Type Detection in Internet Explorer explained here:

    http://msdn.microsoft.com/workshop/n...appendix_a.asp

    On Fri, Jul 25, 2003 at 05:42:36PM -0000, http-equiv@excite.com wrote:
    > Friday, July 25, 2003
    >
    > Active Scripting and HTML in a plain text mail message:


    --
    Fabio Pietrosanti ( naif )
    E-mail: fabio@pietrosanti.it - naif@sikurezza.org
    PGP Key available on my homepage: http://fabio.pietrosanti.it/

  5. #5
    Kee Hinckley
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    At 8:35 PM +0200 7/25/03, Denis Jedig wrote:
    >Internet Explorer seems to take no offense on Content-Types either -
    >text/plain from a web server is happily rendered as HTML, if it
    >contains valid tags.


    It has long been a standard assertion that programs should produce
    standard-complaint protocols, but be lenient in accepting data
    contrary to the standard. Microsoft has taken this one step further.
    In addition to attempting (not unreasonably) to try and guess what
    the user is trying to do, they've written code that tries to guess
    what a remote client or server is trying to do. I think a history of
    Microsoft security holes clearly shows that this is *not* an
    appropriate programming practice. The acceptance of incorrect data
    makes security scanning by intermediate parties extremely difficult.
    Attempting to "correct" for incorrect remote behavior benefits
    nobody. It encourages programs and people to generate incorrect
    code, and it opens up security holes when by the standard there ought
    to be none. We've seen this time after time in things like HTML code
    embedded in JPEG comments, decimal IP addresses using intentional
    overflows, and a plethora of other cases. Policies that make sense
    in dealing with end user actions can be deadly when used with remote
    standards and protocols.

    (Of course this policy also has the side effect of making it
    extremely difficult for smaller players to compete with the dominant
    one, since they have to be bug-for-bug compatible.)
    --
    Kee Hinckley
    http://www.messagefire.com/ Anti-Spam Service for your POP Account
    http://commons.somewhere.com/buzz/ Writings on Technology and Society

    I'm not sure which upsets me more: that people are so unwilling to accept
    responsibility for their own actions, or that they are so eager to regulate
    everyone else's.

  6. #6
    pre
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    Quoting Denis Jedig <seclists@syneticon.de>:

    > http-equiv@excite.com wrote:
    > > Content-Type: text/plain;
    > > [...]
    > > <img dynsrc=javascript:alert()><font color=red>foo
    > >
    > > The above is a legitimate RFC822 mail message in plain text.
    > > Ordinarily one would require an html mail message [Content-Type:
    > > text/html;] to parse html and scripting.

    >
    > Internet Explorer seems to take no offense on Content-Types either -
    > text/plain from a web server is happily rendered as HTML, if it contains
    > valid tags.
    >


    Yes, it's a well known security hole that Microsoft has refused or is unable to fix.

    I (and others) have reported this issue over the last few years. MS acknowledge
    the problem but will not fix it.

    Advisory at: http://www.geekgang.co.uk/adv/gsa2002-01.txt

    I recommend against using IE and Outlook in any kind of sensitive environment.

    ..pre

  7. #7
    Stephen Cope
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    Denis Jedig wrote:
    > Internet Explorer seems to take no offense on Content-Types either -
    > text/plain from a web server is happily rendered as HTML, if it contains
    > valid tags.


    This has been its /modus operandi/ for over four years:
    http://support.microsoft.com/default...b;en-us;239750

    Microsoft Knowledge Base Article - 239750
    "Text/Plain" Content-Type Header Field Is Ignored

    SYMPTOMS
    Internet Explorer may not use the "Text/Plain" Content-Type header
    field to properly open a text file on a Web site. For example, if a
    text file has an extension commonly associated with an executable
    binary file, Internet Explorer may try to run the text file instead
    of opening it as text.

    ...

    STATUS
    Microsoft has confirmed that this is a problem in the Microsoft
    products that are listed at the beginning of this article.

    --
    Stephen Cope - http://sdc.org.nz/

  8. #8
    Fabio Pietrosanti
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")


    MIME Type Detection in Internet Explorer explained here:

    http://msdn.microsoft.com/workshop/n...appendix_a.asp

    On Fri, Jul 25, 2003 at 05:42:36PM -0000, http-equiv@excite.com wrote:
    > Friday, July 25, 2003
    >
    > Active Scripting and HTML in a plain text mail message:


    --
    Fabio Pietrosanti ( naif )
    E-mail: fabio@pietrosanti.it - naif@sikurezza.org
    PGP Key available on my homepage: http://fabio.pietrosanti.it/

  9. #9
    pre
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    Quoting Denis Jedig <seclists@syneticon.de>:

    > http-equiv@excite.com wrote:
    > > Content-Type: text/plain;
    > > [...]
    > > <img dynsrc=javascript:alert()><font color=red>foo
    > >
    > > The above is a legitimate RFC822 mail message in plain text.
    > > Ordinarily one would require an html mail message [Content-Type:
    > > text/html;] to parse html and scripting.

    >
    > Internet Explorer seems to take no offense on Content-Types either -
    > text/plain from a web server is happily rendered as HTML, if it contains
    > valid tags.
    >


    Yes, it's a well known security hole that Microsoft has refused or is unable to fix.

    I (and others) have reported this issue over the last few years. MS acknowledge
    the problem but will not fix it.

    Advisory at: http://www.geekgang.co.uk/adv/gsa2002-01.txt

    I recommend against using IE and Outlook in any kind of sensitive environment.

    ..pre

  10. #10
    Stephen Cope
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    Denis Jedig wrote:
    > Internet Explorer seems to take no offense on Content-Types either -
    > text/plain from a web server is happily rendered as HTML, if it contains
    > valid tags.


    This has been its /modus operandi/ for over four years:
    http://support.microsoft.com/default...b;en-us;239750

    Microsoft Knowledge Base Article - 239750
    "Text/Plain" Content-Type Header Field Is Ignored

    SYMPTOMS
    Internet Explorer may not use the "Text/Plain" Content-Type header
    field to properly open a text file on a Web site. For example, if a
    text file has an extension commonly associated with an executable
    binary file, Internet Explorer may try to run the text file instead
    of opening it as text.

    ...

    STATUS
    Microsoft has confirmed that this is a problem in the Microsoft
    products that are listed at the beginning of this article.

    --
    Stephen Cope - http://sdc.org.nz/

  11. #11
    pre
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    (replying to two postings in one reply)

    Quoting Stephen Cope <mail@nonsense.kimihia.org.nz>:
    >
    > This has been its /modus operandi/ for over four years:
    > http://support.microsoft.com/default...b;en-us;239750
    >
    > Microsoft Knowledge Base Article - 239750
    > "Text/Plain" Content-Type Header Field Is Ignored
    >


    That article is at best out of date. It doesn't list any products past NT4 or
    IE5, when in fact everything after NT4 and IE5 is still vulnerable, including a
    fully patched XP and IE6.

    I tested the registry entry mentioned in that article and it has no effect on
    XP/IE6. I'm not convinced they are even trying to address the same issue with
    that particular 'fix'.

    I've put up a page at the following URL you can use to test your browser:

    http://www.geekgang.co.uk/test/ietest.php


    On Mon, 2003-07-28 at 09:00, Fabio Pietrosanti (naif) wrote:
    > MIME Type Detection in Internet Explorer explained here:
    >
    > http://msdn.microsoft.com/workshop/n...appendix_a.asp
    >


    Yes, it is explained there, but that doesn't excuse MS refusing to fix this
    security hole. They should at a minimum ship their OS's in a secure state - and
    at the very very least provide an option for turning this off.

    As noted above, this has been known for four years - so much for the MS Secure
    Computing Initative - it's laughable.

    cheers,
    pre.

  12. #12
    pre
    TEXT/PLAIN: ALERT(&quot;OUTLOOK EXPRESS&quot;)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TEXT/PLAIN: ALERT("OUTLOOK EXPRESS")

    (replying to two postings in one reply)

    Quoting Stephen Cope <mail@nonsense.kimihia.org.nz>:
    >
    > This has been its /modus operandi/ for over four years:
    > http://support.microsoft.com/default...b;en-us;239750
    >
    > Microsoft Knowledge Base Article - 239750
    > "Text/Plain" Content-Type Header Field Is Ignored
    >


    That article is at best out of date. It doesn't list any products past NT4 or
    IE5, when in fact everything after NT4 and IE5 is still vulnerable, including a
    fully patched XP and IE6.

    I tested the registry entry mentioned in that article and it has no effect on
    XP/IE6. I'm not convinced they are even trying to address the same issue with
    that particular 'fix'.

    I've put up a page at the following URL you can use to test your browser:

    http://www.geekgang.co.uk/test/ietest.php


    On Mon, 2003-07-28 at 09:00, Fabio Pietrosanti (naif) wrote:
    > MIME Type Detection in Internet Explorer explained here:
    >
    > http://msdn.microsoft.com/workshop/n...appendix_a.asp
    >


    Yes, it is explained there, but that doesn't excuse MS refusing to fix this
    security hole. They should at a minimum ship their OS's in a secure state - and
    at the very very least provide an option for turning this off.

    As noted above, this has been known for four years - so much for the MS Secure
    Computing Initative - it's laughable.

    cheers,
    pre.

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics