North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: EMAIL != FTP

  • From: Valdis.Kletnieks
  • Date: Sat May 26 16:42:46 2001

On Sat, 26 May 2001 15:46:56 EDT, Mitch Halmu said:

> Hmmm, I'm looking at an encoded snowhite message body right now. midgets.scr
> encoded in base64, and transmitted as an attachment. Can provide you a
> copy in private if you want to take it apart (but not on a PC, or you'll
> get a *huge* surprise ;)

Notice the surprise isn't when your broken MUA decodes it from base64 to
binary.  The surprise is when your broken MUA then takes that binary and
does something stupid with it.

> All others in that family that I looked at were also encoded. Did anyone 
> get a raw binary via regular email?

And if you pay any attention - it's *NOT* the base64 decoding that protects
you from these things - it's HAVING AN MUA THAT ISN'T STUPID ABOUT RUNNING
EXTERNAL CODE.

-- 
				Valdis Kletnieks
				Operating Systems Analyst
				Virginia Tech


Attachment: pgp00078.pgp
Description: PGP signature