[Dshield] Incredible spam obfuscation (from MIMEDefang maillist)

John Hardin johnh at aproposretail.com
Thu Feb 19 21:01:40 GMT 2004


On Thu, 2004-02-19 at 10:26, Jon R. Kibler wrote:
> Well, again I find myself violating my policy of not cross-posting
> information from other lists, but this new trickery is such a security
> threat, I thought that everyone on DShield should be made aware of it.
> 
> Although this particular email is rather innocuous, this technique
> could EASILY be exploited to propagate any type of malware.

If your mail server's security system blocks or mangles active HTML
(SCRIPT and similar tags), this attack is defused.

--
John Hardin  KA7OHZ                           
Internal Systems Administrator/Guru               voice: (425) 672-1304
Apropos Retail Management Systems, Inc.             fax: (425) 672-0192
-----------------------------------------------------------------------
  Failure to plan ahead on someone else's part does not constitute an
  emergency on my part.
                                  - David W. Barts in a.s.r
-----------------------------------------------------------------------
 11 days until ICQ Corp goes away - have you installed Jabber yet?




More information about the list mailing list