Re: [Exim] Nimda Worm

Top Page
Delete this message
Reply to this message
Author: Richard Welty
Date:  
To: John W Baxter
CC: exim-users
Subject: Re: [Exim] Nimda Worm
On Wed, 19 Sep 2001 19:20:47 -0700, John W Baxter wrote:

>We're talking specifically about Outlook (and Outlook Express?) (see "half
>decent MUA" above). And we're talking about files inside an audio/x-wav
>part, but which are .exe. They get executed, without the user having an
>opportunity to decide about saving to disk, executing, or discarding.


keep in mind that a major part of this is that micro$oft did some
really evil things in Outlook/Outlook Express. specifically, they
ignored the mime specifications and attempt to sniff out what is in
the various mime parts, and will cheerfully recognize, for example,
that there is a .exe file in that there audio/x-wave part.

problem is that they really should raise some sort of exception when
the parts mismatch, but instead, they just go ahead and let it be
executed.

gack,
richard