Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re:[4] Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue |
|---|---|
| Date: | Wed, 29 Sep 2004 09:24:35 +0100 |
No. It is possible to write out a MIME message which cannot be interpreted ambiguously by software that correctly obeys the relevant RFCs.
You have simply changed the subject; this is quite different from your previous statement that it is possible to create a single canonical version by selecting a field from multiple choices.
If any possible MIME message can be ambiguous, as you imply, then the only safe action is to discard every single MIME message, period.
*May* be ambiguous, not *must* be ambiguous. The safe action is to detect and discard the ambiguous ones.
The reformatting *must* eliminate the attack vector, because it *must* force correctly-written software to interpret the message the same way as the security agent.
It does no such thing. The security product has no control over the client at all, so cannot force it to do anything. This model can only work if the client interprets the mailbody in the same way as the security agent, and more importantly does *not* interpret anything else. In the real world, this simply isn't the case. Regards, Martin O'Neal
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Diebold Global Election Management System (GEMS) Backdoor Acc ount Allows Authenticated Users to Modify Votes, Hugo van der Kooij |
|---|---|
| Next by Date: | RE: Diebold Global Election Management System (GEMS) Backdoor, Geoff Vass |
| Previous by Thread: | Samba Security Announcement -- Potential Arbitrary File Access, Gerald (Jerry) Carter |
| Next by Thread: | RE: Diebold Global Election Management System (GEMS) Backdoor, Geoff Vass |
| Indexes: | [Date] [Thread] [Top] [All Lists] |