[PLUG] Effect of a specific mail filter
Carla Schroder
pluglist at bratgrrl.com
Wed Aug 20 19:45:02 UTC 2003
On Wednesday 20 August 2003 7:00 pm, Michael C. Robinson wrote:
> Don't know if this is possible, but what if you opened
> suspicious email in a virtual environment insulated from
> your real one and evaluated the effect, if any, on that
> environment? This way you can catch improper behavior
> and allow other html email through. As long as the
> virtual environment when infected can't take down the
> host or leak out worms, etc., your set.
A nice, isolated test box would be very educational. As long as it's not
connected to anything else, it's safe. If you're asking about something like
VMWare or WINE, I wouldn't consider either one safe.
<snip>
>
> HTML emails are just text programs, why can't they
> be opened by something that won't execute them for
> scanning purposes? Isn't html language finite
> enough to where you can create a filter that
> looks for obvious things like file creation and
> deletion directives, etc.? Just why is it that
> programs like Outlook Express that crave html
> formatted email and attachments are so worm and
> virus friendly?
>
Oh, let us resist the temptation to rail on about the many and infinite
weaknesses of Outlook and Outlook Express... the short answer is, I suppose
programs could be created to scan and evaluate HTML. I'm not sure how
effective they would be, however. If you've looked at the code in spams,
you've noticed the many ways HTML tags and character codes are used to break
up the wording; to dodge filters, to obscure redirects and hidden formfields,
and for obscuring javascript and VBscript. Also there are many different ways
to write scripts to do the same actions. I'm not a programmer, so I don't
know how difficult it would be to write something to evaluate all these
things.
Also, even in non-malicious mail, marketingdroids are completely incapable of
resisting the temptation to bestow upon recipients a "rich multimedia
experience." Think of all the annoying things that happen on Web pages-
popups, popunders, Flash, redirects, disabled back buttons, Web bugs,
fetching images and content from widely-scattered, rude sounds, slow servers-
all of this can be done in HTML email.
And even when it's not spam, or a virus/trojan/other malware, or a "rich
multimedia experience", you can bet money that someday the tools will be
avaiable for your friends and family to easily create their own "rich
multimedia" messages to send you.
Which is my longwinded way of saying I think it would be easier, and better,
to create an ornamental display format for email that cannot contain any
executables. People want pretty email, it's not going away. So it makes more
sense to me to create a format that cannot be exploited for evil.
--
~~~~~~~~~~~~~~~~~~~~~~~~~
Carla Schroder
www.tuxcomputing.com
this message brought to you
by Libranet 2.7 and Kmail
~~~~~~~~~~~~~~~~~~~~~~~~~
More information about the PLUG
mailing list