 |
Tracking and Detecting Valid Mailboxes Through HTML Emails
Back in the days when Windows 98 was the latest Microsoft operating system, HTML email messages accounted for a large number of infected Windows-based systems. Surprisingly, things have not changed much nowadays either. Accepting and displaying HTML email messages still pose a great deal of threats for email users, regardless of what operating system they are using, or if the latter is actually immune to an attack based on vulnerabilities of other systems.
To illustrate, here are some of the possible threats posed by the use of HMTL messages; including, but not limited to virus or other malware infections, which still account for a high degree of risk. Threats posed by the use of html emails Based on HTML email, a malicious person is able to perform different scams and phishing attacks. These types of attacks consist in fooling the targeted email address user into giving out personal information such as: name, address, email address, personal bank account information. Such attacks involve impersonating a legitimate website to which the user may have previously registered and created an account.
Some scammers may go as far as impersonating banks or other financial institutions such as PayPal, in order to obtain credit card information or other personal details that can later be used to purchase goods, or even to empty a bank account. Many bank account frauds are made this way. As a countermeasure, if HTML emails are filtered at server level in a way that causes only text to be displayed such fraud attempts can be blocked and prevented.
Email clients have different approaches to HTML email. Mozilla Thunderbird, for example, does not display HTML content by default, as opposed to Outlook Express which displays HTML content by default. This does not mean that scams cannot be performed using simple text as well, but the probability for someone to believe a text message is lower in comparison to seeing an exact replica of their bank's website requesting their personal details.
As compared to these attempts some of our peers make with the purpose to scam people for their personal information, viruses and worms do not use the same techniques. Their goal may be infecting the operating system, but the infection mechanism may be hidden behind a special offer for a free product, that may actually cost the user a lot more than if they had bought a similar product for real money.
Another commonly encountered threat consists in the simple viewing of a HTML message that can further trigger the delivery of more spam to the user's mailbox.
How is that possible? You may ask. For instance, the spammer sends HTML messages that contain a different image filename link in each of the sent out messages. He also has an association between each image filename link and the email address that the message is sent to. When the message is displayed on the user's computer, if HTML viewing is enabled, the respective image file will be automatically requested from the spammer's server. At this point, the spammer knows that the message has been viewed on a computer and, based on the requested filename and using the association created, he now knows that the respective e-email address is in use. As a result, the spammer has found an active email user that he can convince to buy some of the products he advertises for. Another source of income for the spammer is selling a database of verified addresses, which is even more valuable than a database that contains 3 quarters of bouncing addresses.
This concludes some of the most important scenarios and consequences of using HTML in an email application.
For the original story, please check: http://www.mailradar.com/articles/Security/Tracking-and-detecting-valid-mailboxes-through-HTML-emails-41/page1.html
|
 |
Computer Outlook and FOX News Radio Launch New Sunday Technology Show ? Java with John
Computer Outlook Radio Talk Show and FOX News Radio today announced the addition of a new Sunday technology show, ?Java with John.? Produced in front of a live audience in Las Vegas? ReJAVAnate Coffee Lounge, host John Iasiuolo is bringing it back to the neighborhood every Sunday, LIVE from 10:00 am to 11:00 am Pacific Time on FOX?s KDOX 1280 AM as well as via live internet broadcast on computeroutlook.com and techoutlookcentral.com. Launching June 15, 2008, the new show will give listeners the latest inside information about the companies, technologies and trends that are shaping the computer industry in a relaxed, coffee chat atmosphere.
Cisco CCNA Certification Exam Tutorial: Access List Details You Must Know!
To pass the CCNA exam, you have to be able to write and troubleshoot access lists. As you climb the ladder toward the CCNP and CCIE, you'll see more and more uses for ACLs. Therefore, you had better know the basics!
Microsoft Great Plains SOP: Sales Order Processing
Microsoft Business Solutions Great Plains is marketed for mid-size companies as well as Navision (which has very good positions in Europe and emerging markets where it can be easily localized).Great Plains Sales Order Processing (SOP) module forms a third of the core Inventory and Order Processing part of Great Plains.
Dish Network Offers A Variety Of Programming Packages
Dish Network offers a variety of programming packages for everyone's wants, needs, and budgets. Even the entry level package- America's Top 60 Entertainment Package- comes with sixty channels including favorites like ESPN, the Beauty & Fashion Channel, USA Network, the Sci-Fi Channel, Comedy Central, Headline News, and The Learning Channel. If you happen to be a hard core sports fan, you can sign up for Dish Network's Top 60 Plus which has all of the great programming of America's Top 60 Entertainment Package with the addition of regional sports networks. Dish Network's America's Top 120 Entertainment Package has 120 of your favorite channels like the Independent Film Channel, MSNBC, WGN, tech TV, Univision, Fuse, BBC America, American Movi...
Abel Solutions to Deliver Custom Microsoft Office SharePoint Server Solution in Support of CARE Strategic Plan
Atlanta-based humanitarian relief organization will use SharePoint solution to meet organizational objectives for measuring worldwide impact.
15 Good Programming Habits
1. Before sitting down for coding, you must have formal or a paper-napkin design of the solution to be coded.
Microsoft CEO Reveals Business Mentoring at MBA-Business-Schools.com
CEO Steve Ballmer dropped out of a Stanford MBA program to help start Microsoft. But the skills he learned at his degree program and his company helped him rise to the top of his profession. For students and professionals looking to learn from Ballmer's success, MBA-Business-Schools.com offers articles and mentoring tips from key business authorities.
First Product to Connect Microsoft Office Users with SAP R/3 & SAP BW Data via Performance Dashboards and Scorecards Is Launched by ERP-Link and D
SAP Business Intelligence has been associated with high cost and large projects. Using Microsoft Business Intelligence and Collaboration technologies DSPanel and ERP-link jointly launches a new powerful way of taking SAP R/3 and Business Warehouse data into the Microsoft Office System, the preferred workplace of business people. The new product, iNet.BI, is already SAP certified integration and certified for SAP Net Weaver and brings Performance Dashboards and Scorecards based on SAP data to the screens of regular users within days instead of months.
Merchandising Technologies Inc. Selects Iteration2 and Microsoft Dynamics AX as their Integrated Enterprise Solution
Retail merchandising solution provider selects Iteration2 over competitors Oracle and Epicor.
eStore Advantage – Extending Microsoft eConnect for MBS Great Plains
eStore Advantage allows front-office applications to communicate with back-office business environments. It has a built-in support for electronic payment processing, and serves as a core integration platform for Nodus Technologies front-to-back office connectivity suites including RMS and CRM Advantage.
|