OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] The best hacker ever !

Valdis.Kletnieksvt.edu
Date: Wed May 04 2005 - 11:36:51 CDT


On Wed, 04 May 2005 12:39:14 +1000, "cozadc/Cozad, Chris" said:
> Just out of curiosity....
>
> Why do all your messages come through as a text attachment?

The short version: Because you're using:
X-mailer: Internet Mail Service (5.5.2658.3)

The long version: Because they're PGP-signed as per RFC3156, and some vendors
don't understand how to deal with multipart/signed mail correctly, and decide
that the main text/plain is an attachment rather than a main bodypart (and the
last time I tested, even providing an explicit "Content-Disposition: inline"
didn't help any). What your MUA *should* be doing if it follows the standards
is say "this is a signed mail, but I don't understand the signature format".
(And incidentally, the main offenders for this should be *doubly* embarrassed,
because they *do* in fact understand multipart/signed, so it isn't even a
broken dropback to multipart/mixed - they get stupid when they don't understand
the signature type).

Complain to your vendor, or use a standards-compliant mail package. I'm told
that even Mutt and Pine manage to get it right.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFCePoicC3lWbTT17ARAiGeAKDCGfDKVZk25yGlZcxE9x/Wa3tA9gCg2zls
Tqp1Dov6XzTs3WBxWknw0bU=
=AUqf
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/