Eudora e-mail hole discovered
Clever exploit hides the attachment
Posted in Business, 4th May 2000 17:17 GMT
Free whitepaper – PowerEdge M1000e, M600 and M605 spec sheet
A malicious attachment in Eudora mail which could allow a miscreant to execute code on a victim's machine can be completely concealed and activated by clicking on a hyperlink, Peacefire.org Webmaster Bennett Haselton has discovered. When a recipient clicks the link, the code is executed. The exploit conceals the attachment and bypasses the warning that an attached file is about to be executed. In this case, the .exe extension is changed to .lnk, which Eudora does not by default warn about. To make the exploit more effective, the command to execute it can be embedded in a hyperlink, which can also be devised to prevent Eudora from indicating that an attachment is present. Qualcomm recommends that users edit their Eudora.ini file and insert the following: WarnLaunchExtensions=exe|com|bat|cmd|pif|htm|do|xl|reg|lnk| Full details are available on the Peacefire Web site here. ®
Free whitepaper – Blade learning lab and technical community

Analyst Keynote: The Register Agile Data Center Summit
Automating the Acquisition Process with Enterprise Level CRM
Checklist: Midmarket ERP Solutions
Analyst Keynote: The Register Agile Data Center Summit
Hosted CRM Can Be Your Secret Weapon to Success!

Dirty, dirty PCs: The X-rated picture guide
Top 500 supers - rise of the Linux quad-cores
Early adopters bloodied by Ubuntu's Karmic Koala
Sign up, sign up for The Register IT security newsletter