Re: Outlook 98 allows spoofing internal users

From: Peter van Dijk (peterat_private)
Date: Sun Apr 25 1999 - 09:36:11 PDT

  • Next message: Jay R. Ashworth: "Re: stored credentials was: Netscape 4.5 vulnerability"

    On Tue, Apr 20, 1999 at 03:10:05PM -0700, Nate Lawson wrote:
    >
    > Suggested Fix: always show the full email address of any recipient that is
    > not local (i.e. usernameat_private would be hidden but any instance of
    > userat_private would be shown)
    
    Yeah, like: I am userat_private and I'd like outlook to hide evilhackerat_private
    
    Outlook should not be hiding anything..
    
    Greetz, Peter
    --
    | 'He broke my heart,    |                              Peter van Dijk |
         I broke his neck'   |                     peterat_private |
       nognixz - As the sun  |        Hardbeat@ircnet - #cistron/#linux.nl |
                             | Hardbeat@undernet - #groningen/#kinkfm/#vdh |
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:43:53 PDT