FYI: malignant mail (II)

Eugene Leitl (eugene@liposome.genebee.msu.su)
Tue, 31 Mar 1998 14:55:48 +0400 (MSD)


--ov1V1S+/Yv
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Beware of too powerful mail clients. Orelse, suffer.

--ov1V1S+/Yv
Content-Type: message/rfc822
Content-Transfer-Encoding: 7bit

Return-Path: <owner-pigdog-l@arlington.com>
Received: from kiki.arlington.com (kiki.arlington.com [140.174.170.5])
by liposome.genebee.msu.su (8.8.5/8.8.5) with ESMTP id AAA02976
for <eugene@liposome.genebee.msu.su>; Tue, 31 Mar 1998 00:15:31 +0400
Received: from localhost (daemon@localhost)
by kiki.arlington.com (8.8.8/8.8.5) with SMTP id MAA07488;
Mon, 30 Mar 1998 12:14:43 -0800 (PST)
Received: by kiki.arlington.com (bulk_mailer v1.6); Mon, 30 Mar 1998 12:14:41 -0800
Received: (from majordom@localhost)
by kiki.arlington.com (8.8.8/8.8.5) id MAA07467;
Mon, 30 Mar 1998 12:14:39 -0800 (PST)
Received: from beryllium.cobaltgroup.com (beryllium.cobaltgroup.com [207.149.72.4])
by kiki.arlington.com (8.8.8/8.8.5) with ESMTP id MAA07462
for <pigdog-l@arlington.com>; Mon, 30 Mar 1998 12:14:37 -0800 (PST)
Received: from interzone.cobaltgroup.com (cblt-fw-91.cobaltgroup.com [192.168.1.91]) by beryllium.cobaltgroup.com (8.8.5/8.6.9) with SMTP id MAA10974 for <pigdog-l@arlington.com>; Mon, 30 Mar 1998 12:15:07 -0800
Message-Id: <199803302015.MAA10974@beryllium.cobaltgroup.com>
X-Sender: dans@mail.cobaltgroup.com (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.0
In-Reply-To: <199803302002.MAA15832@decimate.diablo.net>
References: <3.0.3.32.19980328200042.0078f910@idiom.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Reply-To: pigdog-l@arlington.com
From: Dan Sneddon <liquor.pig@pigdog.org>
Sender: owner-pigdog-l@arlington.com
To: pigdog-l@arlington.com
Subject: Re: [Pigdog] Flesh, please do my homework for me
Date: Mon, 30 Mar 1998 12:16:50 -0800

Ewwww. You turned on the "Use Microsoft's Viewer" option under "Viewing
Mail", didn't you? Or maybe you never turned it off.

That uses OLE IE 4.0 to display your mail. This means that I could embed a
src tag into an email message that would crash Eudora, ruin your stack, and
make your day suck.

The offending tag is:
<EMBED SRC=file://C|/A.ABOUT_200_CHARACTERS_HERE___________________

I kindly left off the end bracket so that you could actually see this
message. I could crash Eudora, but you might never figure out WHY you
couldn't look at my message without fucking up your computer.

If you don't use IE 4.0 embedding, everything is peachy. Now, turn off that
option or suffer later.

-LiquorPig

At 12:04 PM 3/30/98 , you wrote:
>This also works in Eudora 4.....
>
>--
>Bill Plein Home Page: http://www.diablo.net/
>bill@diablo.net PGP Key: http://www.diablo.net/pubkey/bill.html
>

--ov1V1S+/Yv--