Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
testeronious@lemmy.world to Security@programming.devEnglish · 1 year ago

Kobold letters – Why HTML emails are a risk to your organization

lutrasecurity.com

external-link
message-square
6
fedilink
  • cross-posted to:
  • protonprivacy@lemmy.world
  • hackernews@lemmy.smeargle.fans
  • netsec@lemmy.world
25
external-link

Kobold letters – Why HTML emails are a risk to your organization

lutrasecurity.com

testeronious@lemmy.world to Security@programming.devEnglish · 1 year ago
message-square
6
fedilink
  • cross-posted to:
  • protonprivacy@lemmy.world
  • hackernews@lemmy.smeargle.fans
  • netsec@lemmy.world
Kobold letters – Lutra Security
lutrasecurity.com
external-link
Anyone who has had to deal with HTML emails on a technical level has probably reached the point where they wanted to quit their job or just set fire to all the mail clients due to their inconsistent implementations. But HTML emails are not just a source of frustration, they can also be a serious security risk.
alert-triangle
You must log in or # to comment.
  • cerement@slrpnk.net
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago
    • Thunderbird: “Possible mitigations have been discussed but will not be implemented until a later date.”
    • Outlook: “The report was marked as closed by Microsoft on 26.03.204 after deciding not to take any immediate action.”
    • Gmail: “…”
    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 year ago

      on 26.03.204

      Man, the year 204 is so long ago

      • venonat@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Seems like just yesterday

      • Konstantin Weddige@gruene.social
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        @Kissaki @cerement thanks! It’s fixed now.

  • Kissaki@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    Unfortunately no mention of Outlook desktop

    • Konstantin Weddige@gruene.social
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      @jtig reproduced it on the desktop version of Outlook: https://infosec.exchange/@jtig/112212659232428604

Security@programming.dev

security@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !security@programming.dev

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don’t be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 238 users / 6 months
  • 4 local subscribers
  • 1.3K subscribers
  • 89 Posts
  • 153 Comments
  • Modlog
  • mods:
  • LinearArray@programming.dev
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org