The Register® — Biting the hand that feeds IT

Eudora e-mail hole discovered

Clever exploit hides the attachment

Tune into our application security webcast, click here

A malicious attachment in Eudora mail which could allow a miscreant to execute code on a victim's machine can be completely concealed and activated by clicking on a hyperlink, Peacefire.org Webmaster Bennett Haselton has discovered. When a recipient clicks the link, the code is executed. The exploit conceals the attachment and bypasses the warning that an attached file is about to be executed. In this case, the .exe extension is changed to .lnk, which Eudora does not by default warn about. To make the exploit more effective, the command to execute it can be embedded in a hyperlink, which can also be devised to prevent Eudora from indicating that an attachment is present. Qualcomm recommends that users edit their Eudora.ini file and insert the following: WarnLaunchExtensions=exe|com|bat|cmd|pif|htm|do|xl|reg|lnk| Full details are available on the Peacefire Web site here. ®

Join our expert panel in discussing application security

Don’t Miss

Win a Samsung C6625!

Reg Lucky Draw Windows Mobile handsets up for grabs

Palm_Pre_001_SMIs your cameraphone an oxymoron?

Pic Review iPhone 3G v iPhone 3GS v Palm Pre

Reg black vulture logoReg Mobile and Wireless newsletter is go! go! go!

Site news Email-tasm

Sign up, sign up for The Register IT security newsletter

Narrowcasting for the email classes