- Microsoft lays out SQL Server road map
- Credit card skimming
- Nortel's stock market capitalization plummets
- The Obama campaign's Search Engine to Nowhere
- Will Apple be forced to make more money?
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
Many people are sending HTML e-mail for no obvious reason or benefit. HTML e-mail can be recognized by colored backgrounds or typefaces. It sometimes has designs or other decorations in the messages. Unfortunately, HTML e-mail is a security risk.
HTML messages can easily contain unwanted, mislabeled links, Web bugs, harmful active content, and outright worms and viruses.
Richard Smith warned of emerging e-mail vulnerabilities in 1999, when he listed dozens of problems related to HTML e-mail.
A particularly detailed analysis showed how HTML code in e-mail could allow breaches of privacy using images and cookies:
http://www.computerbytesman.com/privacy/cookleak.htm
Invisible single-pixel images (called Web bugs) can enable this kind of user e-mail tracking without alerting the naïve user because most people don’t examine the HTML code underlying received e-mail messages.
Other vulnerabilities inherent in HTML e-mail include the ability to run Visual Basic scripts, ActiveX controls, and Macromedia flash, all of which can execute unauthorized and unsafe code.
Some organizations and individuals are blocking HTML messages outright. Blocking incoming HTML e-mail is easy because it always includes recognizable strings associated with the HTML underlying the fancy display.
I urge everyone to send plain text instead of HTML as the default format for outgoing e-mail.
If you need to send a message with features beyond text, you can always create a word-processing document and send that. However, you should be aware that when you send a Microsoft Word document, not only are you putting the recipient at risk from embedded macros, but the appearance of your document may be quite different on the recipient’s computer if you do not share the same set of fonts. RTF files typically do not carry macros (although the font problem still exists).
Some recipients prefer a platform-independent format such as an Adobe Acrobat PDF file rather than a platform-specific file such as a Word document; PDF files do not depend on the recipient’s fonts for proper display, and they do not carry Word macros.
So to repeat: set your default format for outbound e-mail from HTML to TEXT in your e-mail client. Here are some hints on how to do that:
* If you are using Netscape Messenger as your client, click Edit | Mail & Newsgroups | Formatting to reach the panel that allows the configuration. Then at the top of the page, in the section labeled, "Message formatting" you can select the lower option, "Use the plain text editor to compose messages." The other section is labeled, "When sending HTML messages to recipients who are not listed as being able to receive them." You can select the second option there, "Convert the message into plain text."
M. E. Kabay, PhD, CISSP-ISSMP, is Program Director of the Master of Science in Information Assurance program at Norwich University.

Ever since there have been stocks and shares there have been so called "pump 'n' dump" scams. This...
Spyware: Know Your EnemyLike Macavity, the fictional feline in T. S. Eliot's well-known poem, spyware may be considered to...
The Online Shadow Economy: A Billion Dollar Market For Malware AuthorsMalware, meaning computer viruses, trojans and spyware, is about money. The teenagers who wrote...

Microsoft SQL Server has enjoyed phenomenal success as a database server. Its relatively low cost,...
Minimizing the Risk of Information Security Breaches: Best Practices for SOA Governance and Compliance - Live October 21Today's enterprises face more information security risks and vulnerabilities than ever before....
Migrating to Windows Vista: Necessity and OpportunityThe Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...
The Evolution of Network SecurityWe have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment