[PLUG] Effect of a specific mail filter

Carla Schroder pluglist at bratgrrl.com
Wed Aug 20 19:45:02 UTC 2003


On Wednesday 20 August 2003 7:00 pm, Michael C. Robinson wrote:
> Don't know if this is possible, but what if you opened
> suspicious email in a virtual environment insulated from
> your real one and evaluated the effect, if any, on that
> environment?  This way you can catch improper behavior
> and allow other html email through.  As long as the
> virtual environment when infected can't take down the
> host or leak out worms, etc., your set.

A nice, isolated test box would be very educational. As long as it's not 
connected to anything else, it's safe. If you're asking about something like 
VMWare or WINE, I wouldn't consider either one safe. 

<snip>
>
> HTML emails are just text programs, why can't they
> be opened by something that won't execute them for
> scanning purposes?  Isn't html language finite
> enough to where you can create a filter that
> looks for obvious things like file creation and
> deletion directives, etc.?  Just why is it that
> programs like Outlook Express that crave html
> formatted email and attachments are so worm and
> virus friendly?
>

 Oh, let us resist the temptation to rail on about the many and infinite 
weaknesses of Outlook and Outlook Express... the short answer is, I suppose 
programs could be created to scan and evaluate HTML. I'm not sure how 
effective they would be, however. If you've looked at the code in spams, 
you've noticed the many ways HTML tags and character codes are used to break 
up the wording; to dodge filters, to obscure redirects and hidden formfields, 
and for obscuring javascript and VBscript. Also there are many different ways 
to write scripts to do the same actions. I'm not a programmer, so I don't 
know how difficult it would be to write something to evaluate all these 
things. 

Also, even in non-malicious mail, marketingdroids are completely incapable of 
resisting the temptation to bestow upon recipients a "rich multimedia 
experience." Think of all the annoying things that happen on Web pages- 
popups, popunders, Flash, redirects, disabled back buttons, Web bugs, 
fetching images and content from widely-scattered, rude sounds, slow servers- 
all of this can be done in HTML email.

And even when it's not spam, or a virus/trojan/other malware, or a "rich 
multimedia experience", you can bet money that someday the tools will be 
avaiable for your friends and family to easily create their own "rich 
multimedia" messages to send you.

Which is my longwinded way of saying I think it would be easier, and better, 
to create an ornamental display format for email that cannot contain any 
executables. People want pretty email, it's not going away. So it makes more 
sense to me to create a format that cannot be exploited for evil.


-- 
~~~~~~~~~~~~~~~~~~~~~~~~~
Carla Schroder
www.tuxcomputing.com
this message brought to you
by Libranet 2.7 and Kmail
~~~~~~~~~~~~~~~~~~~~~~~~~




More information about the PLUG mailing list