Full Disclosure mailing list archives
RE: Re: Internet Explorer URL parsing vulnerability
From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Wed, 10 Dec 2003 16:51:18 -0600
-----Original Message----- From: full-disclosure-admin () lists netsys com [mailto:full-disclosure-admin () lists netsys com] On Behalf Of S G Masood Sent: Wednesday, December 10, 2003 12:01 PM To: full-disclosure () lists netsys com Subject: Re: [Full-disclosure] Re: Internet Explorer URL parsing vulnerability Hey, to be very honest, if this was 0day and the spoof was well constructed, even you and me would probably fall for it. ;D
Really? I kind of doubt it, since I would never click on a link in an email message that had anything to do with financial matters. I doubt that you would either - 0day or not. The point isn't that the URL obfuscates the true source. The point is that people shouldn't be clicking on URLs in email, if they have to do with financial matters, in the first place. Sure, if someone sends you an email that says "1000 killed in earthquake" and provides a link, you *might* click on it and get some malware, but who in their right mind would click on a link that says "Update your banking information here"? (Yes, I know plenty of doofuses do this, but they're the same people who would travel to Nigeria to pick up their check. No amount of education can overcome terminal stupidity.) Paul Schmehl (pauls () utdallas edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/~pauls/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Re: Internet Explorer URL parsing vulnerability, (continued)
- Re: Re: Internet Explorer URL parsing vulnerability John Sage (Dec 10)
- Re: Re: Internet Explorer URL parsing vulnerability Daniel H. Renner (Dec 10)
- Re: Re: Internet Explorer URL parsing vulnerability petard (Dec 10)
- Re: Re: Internet Explorer URL parsing vulnerability Jedi/Sector One (Dec 10)
- Re: Re: Internet Explorer URL parsing vulnerability Valdis . Kletnieks (Dec 10)
- Re: Re: Internet Explorer URL parsing vulnerability Georgi Guninski (Dec 11)
- Re: Re: Internet Explorer URL parsing vulnerability Dark Avenger (Dec 12)
- Re: Re: Internet Explorer URL parsing vulnerability Georgi Guninski (Dec 12)
- Re: RE:Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 10)
- RE: Re: Internet Explorer URL parsing vulnerability S G Masood (Dec 11)
- RE: Re: Internet Explorer URL parsing vulnerability S G Masood (Dec 12)
- RE: Re: Internet Explorer URL parsing vulnerability Jarkko Turkulainen (Dec 11)
- Re: Re: Internet Explorer URL parsing vulnerability petard (Dec 11)
- Re: Re: Internet Explorer URL parsing vulnerability petard (Dec 11)
- Re: Re: Internet Explorer URL parsing vulnerability John Sage (Dec 11)
- Re: Re: Internet Explorer URL parsing vulnerability Erik van Straten (Dec 12)