Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 26, 2002

More Outlook Security Problems

RSS
Subscribe to Windows IT Pro | See More Jscript Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

As we approach the 2-year anniversary of the VBS.LoveLetter virus outbreak, which catapulted Outlook into the headlines, security problems continue to arise. Last week, Internet security and privacy expert Richard M. Smith posted a note to the Windows NTBugtraq mailing list that cited four problems with Outlook 2002—two security problems, one privacy problem, and one case of mixed messages from Microsoft—that Smith says probably affect earlier versions of Outlook as well.

According to Smith, the most significant security problem is that IFRAME tags in HTML messages can run files. IFRAME is an HTML element that Microsoft Internet Explorer (IE) uses to display a Web page or another document within a Web page or a mail message. If Windows considers an IFRAME source file "safe," the OS automatically launches the file when you view a Web page or mail message. But with bug hunters discovering a steady stream of ways in which supposedly safe files can execute harmful content, Smith recommends that Microsoft block all IFRAME content in HTML messages except HTML, image, and text files.

Another security problem Smith mentions is that although Outlook blocks JavaScript and VBScript in HTML messages, the application doesn't block the code in hyperlinks that use "javascript:" instead of "http: ". Because Outlook supports URLs of up to about 2000 characters—long enough to let malicious users exploit some known IE security holes—Smith recommends that you block "javascript:" and "about:" URLs in mail messages. This problem is less severe than the IFRAME problem because the JavaScript code doesn't run automatically—you must click the link before it will run. However, a malicious user can easily spoof a link in a mail message. Outlook 2002 doesn't give you a status bar that lets you view a link's target, as IE does, so the only way to confirm that a link points to a particular Web page is to read the entire message source. How many of you do that before you click a link in an HTML message?

Smith's third complaint about Outlook 2002 is a privacy problem that might return both a cookie and your email address to a Web site. The site's administrators could then match the address with the previously anonymous data associated with that cookie. You're at risk for this privacy flaw only if you already have a cookie for the Web site and you receive a mail message constructed individually for you with an image whose source URL sends your address back to the Web site.

Finally, Smith thinks that the Outlook and IE teams should agree on the safest way to send Internet links by email. I agree. IE 6.0 insists on inserting a .url file in messages you create when you choose File, Send, Link by E-mail from your browser. However, if you've installed the Email Security Update, Outlook blocks those files. A text link, rather than a file attachment, would be safe and accessible for everyone. Let's hope that Microsoft soon can fix this feature in IE and also make IFRAME safer to use in HTML mail messages.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Top 10 Email Security Challenges and Solutions

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing