Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Politech: FC: Neulevel's PostMinder tracks email without recipient approval

FC: Neulevel's PostMinder tracks email without recipient approval

From: Declan McCullagh <declan_at_well.com>
Date: Fri, 24 May 2002 09:15:14 -0400

[How rude and annoying. From now on, I'm only going to use /usr/bin/Mail or
maybe tail -100 from the mail spool... --Declan]

---
Date: Fri, 24 May 2002 15:03:11 +0200
To: Declan McCullagh <declan_at_well.com>
From: [deleted --DBM]
Subject: Neulevel's PostMinder tracks e-mails without recipient approval
[If you use this, please omit my name! Thx.]
Neulevel's PostMinder tool (http://www.postminder.biz) sends out confirmations
to the sender that the recipient has read an e-mail even when the recipient
has disabled Return Receipts.
If your mail reader displays HTML, it will send a message back to Neulevel
to indicate that your message has been read. In addition, it displays a 
message
"The sender of this message requests confirmation when you read it. Click here
to confirm." No need to click -- it has already been confirmed.
If you dislike this, you can set your mail reader to Text-only/no HTML 
allowed.
Eudora users can disable "Use Microsoft's viewer" (Tools/Options/Viewing 
Mails).
PostMinder uses similar technology to track MS Word, Excel, PowerPoint and 
other
documents supporting OLE. They claim that it will "allow you to find out if 
they
were forwarded to others or viewed by a third party", e.g. if someone leaked
a document to a journalist.
This is how PostMinder-modified mails look like --
NNNNNNNNNNN is a tracking number, > and < replaced by ] and [
[x-html]
[HTML][DIV][/DIV][DIV]This is the text of the tracked email
[/DIV][DIV][br][br][br][center][a 
href="http://www.NNNNNNNNNNN.PostMinder.biz/confirm.asp?NNNNNNNNNNN"][IMG 
SRC="http://www.NNNNNNNNNNN.PostMinder.biz/nocache.pl/NNNNNNNNNNN/footer20.gif" 
border=0 height=40 width=400 alt=""][/A]
[iframe width=1 height=1 
src="http://www.NNNNNNNNNNN.PostMinder.biz/iframe.asp?NNNNNNNNNNN=2" 
frameborder=0 STYLE="width: 0; height: 0px; border:0px"][/iframe][table 
height=1 width=1 border=0][tr][td 
background="gopher://gopher.NNNNNNNNNNN.PostMinder.biz/gb.NNNNNNNNNNN.gif"][/td][/tr][/table][/center]
[/HTML]
[/x-html]
---
Date: Fri, 24 May 2002 15:10:25 +0200
To: Declan McCullagh <declan_at_well.com>
From: [deleted --DBM]
Subject: Fwd: Neulevel's PostMinder tracks e-mails without recipient
   approval
[If you use this, please omit my name! Thx.]
BTW, the tracking report send to the sender using PostMinder
includes date, time, user machine (IP-based), reader language
and email reader/browser.
-------------------------------------------------------------------------
POLITECH -- Declan McCullagh's politics and technology mailing list
You may redistribute this message freely if you include this notice.
To subscribe to Politech: http://www.politechbot.com/info/subscribe.html
This message is archived at http://www.politechbot.com/
Declan McCullagh's photographs are at http://www.mccullagh.org/
-------------------------------------------------------------------------
Like Politech? Make a donation here: http://www.politechbot.com/donate/
-------------------------------------------------------------------------
Received on May 24 2002
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos