Microsoft's Outlook Express 6 "E-mail attachment security" Flawed

From: Arie Slob (arieat_private)
Date: Tue Dec 04 2001 - 15:46:00 PST

  • Next message: bugzillaat_private: "[RHSA-2001:161-08] Updated OpenSSH packages available"

    Hi,
    
    I was contacted by David McSpadden, a Network Administrator from the Indiana Members Credit Union who pointed out the following:
    
    ---------------------------
     
    I was wondering if you could replicate something I have found.
    I set up attachment blocking as per (Q291387) on my Windows 2000 Professional Sp2 workstation for testing.  Thinking we might implement this as policy on all of our workstations with Outlook Express 6.0.  It did correctly block the attachments of the extensions I specified.  However, if I simply try and forward the email the 'blocked' item appears and I can then save or open the attachment.  This creates a dilema.  Why should I even try and stop the attachments if I can get to them anyway.
      
    Please let me know if I am crazy or if I have found another hole in Outlook Express.
    ---------------------------
    
    Well, I think he's right. I tested it on XP, set OE to block attachments.... that works... until you press FORWARD.... then you have full access...........
    
    I contacted Microsoft (secureat_private) who wrote back with the attached email.
    
    I have published and article on our Web site about this:
    
    http://www.windows-help.net/microsoft/oe6-attach.html
    
    
    Regards,
    
    Arie Slob,
    VP Information Systems
    InfiniSource, Inc.
    <arieat_private>
    
    
    
    
    

    attached mail follows:





    This archive was generated by hypermail 2b30 : Wed Dec 05 2001 - 15:30:55 PST