
Full Disclosure mailing list archives
Re : Outlook Express 6.0 : link destination obfuscation
From: "Romain Vergniol" <romain.vergniol () cegedim fr>
Date: Wed, 4 Jan 2006 14:30:15 +0100
or http://www.myBank.com+aWholeLottaJunk () badsite com
This example does not work anymore due to the recent desactivation of this syntax by Microsoft (for http:// only, it still works for ftp://). Romain
Romain Vergniol wrote: Hello FD readers, did anyone already noticed that on Outlook Express 6.0, when a link is longer than 512 bytes, the destination is not displayed at all in the status bar ?Tested on Outlook Express 6.0 on WinXP Pro SP2 FR, does not work on Outlook2003 Win XP SP2 FR. Ex : <a href="http://www.exemple.com/+(500 random chars)">www.bank.com</a>It could be used in phishing attacks for exemple to hide real link destination.Could it be considered as a security issue ? Kind regards, Romain Vergniol
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re : Outlook Express 6.0 : link destination obfuscation Romain Vergniol (Jan 04)