OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: [Full-Disclosure] Trojan Horse for Mac OS X

From: Larry Seltzer (larrylarryseltzer.com)
Date: Fri Apr 09 2004 - 17:53:09 CDT


>> This technique wouldn't work now because Mail.app, and probably all
>> modern mail client. Will not let you execute code from within the mail
>> client.

>Completely untrue. Mail.app will ask you if you want to open the app just like Outlook
Express on Windows does.

Actually, Outlook Express and Outlook will (by default) strip all executable attachments
before you even get them. They've done this for some time.

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.ziffdavis.com/seltzer
larryseltzerziffdavis.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html