Full Disclosure mailing list archives
Re: Security issue in Microsoft Outlook
From: Tom Gallagher <tom () SecurityBugHunter com>
Date: Wed, 18 May 2005 21:00:06 -0400
How is this any different than having the text of a link say something other than the URL? This is possible in HTML (in any application) and Microsoft Office application. For example, go into Word and type "some text" then highlight it, and press Ctrl+K. Then type in the URL you want. This is now a hyperlink. Also note that the tool tip should show the correct link. This is essentially the same as the following HTML: <A HREF="http://evil">http://safe</A> Tom Quoting Bakchodiya <bakchodiya () yahoo com>:
An issue has been discovered in MS Outlook (All Versions) where anyone can fake a URL & send it across. How does it work: Lets compose an email in MS Outlook, lets type http://www.cybertrion.com & put a space after it to make it a link. Now put your cursor just before cybertrion & type any URL for eg: http://www.foo-labs.info now send it to anyone. The receiver will see the URL as http://www.foo-labs.info but when he clicks on it it will directly take him to http://www.cybertrion.com I am not sure how critical this is but it can fool alot of people & result in download of a virus. For more details and Discovered by: Cybertrion Systems, http://www.cybertrion.com __________________________________ Do you Yahoo!? Yahoo! Mail - Find what you need with new enhanced search. http://info.mail.yahoo.com/mail_250
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Security issue in Microsoft Outlook Bakchodiya (May 18)
- Re: Security issue in Microsoft Outlook Andy Brezinsky (May 18)
- Re: Security issue in Microsoft Outlook Nick FitzGerald (May 18)
- Re: Security issue in Microsoft Outlook Raoul Nakhmanson-Kulish (May 18)
- RE: Security issue in Microsoft Outlook Domingos Bruges (May 19)
- Re: Security issue in Microsoft Outlook Jesse Morgan (May 19)
- Re: Security issue in Microsoft Outlook Tom Gallagher (May 19)
- RE: Security issue in Microsoft Outlook Simon Dever (May 19)
- Re: Security issue in Microsoft Outlook Jens Becker (May 19)
- Re: Security issue in Microsoft Outlook Kevin Martin (May 19)
- Re: Security issue in Microsoft Outlook Dan Margolis (May 20)
- RE: Security issue in Microsoft Outlook Keenan Smith (May 23)
- Re: RE: Security issue in Microsoft Outlook Micheal Espinola Jr (May 23)
- <Possible follow-ups>
- RE: Security issue in Microsoft Outlook Scovetta, Michael V (May 19)
- Re: Security issue in Microsoft Outlook Harshad (May 19)
- Re: Re: Security issue in Microsoft Outlook Joachim Schipper (May 19)
- RE: Security issue in Microsoft Outlook Steve Bostedor (May 19)
(Thread continues...)
