Bugtraq mailing list archives

Re: Outlook 98 allows spoofing internal users


From: peter () ATTIC VUURWERK NL (Peter van Dijk)
Date: Sun, 25 Apr 1999 18:36:11 +0200


On Tue, Apr 20, 1999 at 03:10:05PM -0700, Nate Lawson wrote:

Suggested Fix: always show the full email address of any recipient that is
not local (i.e. username () example com would be hidden but any instance of
user () hotmail com would be shown)

Yeah, like: I am user () aol com and I'd like outlook to hide evilhacker () aol com.

Outlook should not be hiding anything..

Greetz, Peter
--
| 'He broke my heart,    |                              Peter van Dijk |
     I broke his neck'   |                     peter () attic vuurwerk nl |
   nognixz - As the sun  |        Hardbeat@ircnet - #cistron/#linux.nl |
                         | Hardbeat@undernet - #groningen/#kinkfm/#vdh |



Current thread: