OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: thomas.rowebankofamerica.com
Date: Sat Aug 18 2001 - 22:10:36 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Alex Prestin wrote:
    snip
    > See it? A web bug. If I opened this mail in an HTML-capable browser,
    > that little image would've popped up and I would've been none the
    > wiser. My address would also have been verified by the sender, and stored
    > in a large database of valid recipients.

    snip

    And if you were running WinNT 4 and that referrer pointed to a server
    advertising a share, NT would send your username and password to try to log
    you on without your knowledge. It could be grabbed and sent back to your
    machine, logon, and the atttacker would have all rights to your machince and
    network that the ID you're using has.
    (as I've mentioned before, MS has known about this hole since before SP2)
    Cheers

    Thomas Rowe
    Systems Engineer, LDI
    Bank of America
    Atlanta, GA