Feeds

No-HTML plug-in for Outlook available

Halleluiah, almost

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

I've always believed that if the US Government were ever to get really serious about Internet security, the top players in Microsoft's management hierarchy would find themselves handcuffed, blindfolded, led onto a tarmac within some obscure Air Force base, and shot.

Witness if you will Microsoft Outlook and Outlook Express, the two most efficient virus propagation utilities ever devised by human intellectual failure.

Among the more ostentatious security pitfalls deliberately coded into Outlook is its determination to accommodate the mighty Direct Marketing Association (DMA) spam lobby by refusing to allow users to shut off HTML (which exposes us to myriad forms of malicious code in received messages), as this would have a devastating impact on advert click-throughs for hot, wet teens, scientific studies have shown.

You can decline to send HTML messages, as any decent Netizen does; but you can't decline to receive them. No, that would be downright hostile to the spam establishment, and Microsoft knows better than tangle with one of the few industries which dwarfs it.

However, some of us now have a nifty tool called NoHTML to disable HTML displays in Outlook, thanks to Russ Cooper of NTBugtraq. In Outlook 2000, NoHTML supposedly converts HTML to RTF. In Outlook 2002, it converts HTML to plain text. Pretty neat.

In NT, 2K or XP, just install the file (a DLL) in: Documents and Settings\(user)\Application Data\Microsoft\Addins. Finish the installation as described below, re-boot, and all should be well.

If you're running 9x, you might try installing it in: Windows\Application Data\Microsoft\AddInsWindows\Local and/or in Settings\Application Data\Microsoft\Outlook.

Finish the installation thus: within Outlook, go to Tools, Options, Other, Advanced Options, COM Add-ins, Add. Find NoHTML.dll and select it. Re-boot.

Thus far it's worked for me with Outlook 2000 on 'XP and '98. I can hardly describe the thrill of blocking scripts in Outlook for once in my life. In '98, an HTML message's preview pane is blank, as is the whole message when opened manually; in 'XP it all shows up as text, as it should.

It's important to set Outlook to reply in plain text, however (if you can). While the plugin will defeat HTML on incoming messages, if you've elected to reply in the sender's format you could possibly activate a script when you launch a reply. In older versions of Outlook it was possible to force replies into plain text, but in later versions one is only permitted to select his own default settings for new messages.

The plugin, regrettably, won't work with Outlook Express, whose users tend to be those most in need of this sort of protection.

But once it's adapted to OE and its little glitches are sorted out, I'd say we have a winner here. Too bad Microsoft couldn't manage something like this on its own, simply as a setup option. Heavens, had they done so, they might not now have to whine so piteously about devastating bug disclosures. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
Google opens Inbox – email for people too stupid to use email
Print this article out and give it to someone techy if you get stuck
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Redmond top man Satya Nadella: 'Microsoft LOVES Linux'
Open-source 'love' fairly runneth over at cloud event
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.