Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: CSS in E-Mails possible E-Mail-Validity Check for Spammers?

Re: CSS in E-Mails possible E-Mail-Validity Check for Spammers?

From: Andrew Clover <and-bugtraq_at_doxdesk.com>
Date: Wed, 03 Nov 2004 09:52:51 +0100

plonk_at_datenritter.de wrote:

> Mozilla Mail 1.7.1 (W98) and 1.7.3 (W98) (didn't check different
> versions) automatically load CSS-files which are linked from within an
> html-page sent in an e-mail

Yes. There have been other ways to force an HTTP request from HTML mail
too (eg. background images, bug 239954) so this is not unexpected.

The "block loading of remote images in mail messages" option isn't
waterproof from a privacy point of view. It would be nice if it was, but
I'm not sure this is actually Mozilla's goal; perhaps worth filing a bug
to force the issue?

> - turn off HTML in E-Mails (not possible in Mozilla?)

Should be possible - it is in Thunderbird (View->Message Body as->Plain
Text) and I highly recommend doing so.

-- 
Andrew Clover
mailto:and_at_doxdesk.com
http://www.doxdesk.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Nov 03 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]