"Security hole"?
Posted Oct 12, 2003 16:29 UTC (Sun) by
dsime (guest, #5764)
In reply to:
"Security hole"? by TwoTimeGrime
Parent article:
E-mail filters not fooled by signed spam (News.com)
Guess again.
Outlook will execute arbitrary commands, arbitrary to me but not to the sender, when the only action I take is to open the note.
In point-of-fact I don't even have to do that as the default configuration for Outlook is to display the inbox in such a way that it opens notes so you can see the "first few lines", just by having them highlighted on the list.
And the first one is always highlighted.
So in order for Lookout to execute arbitrary code all I have to do is start it.
THAT I would not think would classify as secure in anybody's book.
(
Log in to post comments)