Outlook Express becomes attack platform, of sorts

Friday, 13 September 2002, 3:24 PM EST

For the last couple of years Outlook (Lookout) Express failings have been exploited to infect users. So why not take advantage of its features to send viruses in such a way that they might fool detection by AV and content checking tools?

Well that's the gist of a new method of bypassing many SMTP-based content filter engines, unearthed by researchers at Beyond Security.

Using a rarely used feature called 'message fragmentation and re-assembly' (MFR), an attacker can send emails that will "bypass most SMTP filtering engines", Beyond Security reports.

This MFR feature, which allows Internet users to split up sent messages, helping surfers with slow connections to send smaller segments of a larger email in multiple emails, is supported by Internet standards (RFC 2046) but easily enabled on only one client - Outlook Express.

[ Read more ]




Spotlight

OpenBSD team forks OpenSSL to create safer SSL/TLS library

Posted on 22 April 2014.  |  Members of the OpenBSD project have begun working on a free version of the SSL/TLS protocol. They are not starting from scratch, but have forked OpenSSL to create a new, more secure option which they have dubbed LibreSSL.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Tue, Apr 22nd
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //