[CrackMonkey] Apropos broken windows MUA:s; Eudora file
leakage problem
Dave Ely
ely at dijas.com
Tue Jan 29 00:48:26 PST 2002
Magnus Bodin said:
> While were at it with exploiting Windows MUA:s.
> It got me thinking of this old Bugtraq post that actuallt _still_holds_.
>
> Note, that you have to start the line with 'Attachment Converted: ' and
> then have the path enclosed in '"'. I originally found this in like '97 and
> Qualcomm have not responded on any of my reports.
This is a much older problem / feature that Steve Dorner was aware of
before Eudora was sold to Qualcomm (or lets quibble and say shortly
after). Either way, at that point it in time it was mainly a Mac app
(the problem exists in all versions) and it's still not anything like
the current 'begin ' problem which finally made me subscribe (it's
easier to watch this way than plowing through the www pages).
More information about the Crackmonkey
mailing list