Outlook 2007 Read Receipt Security Hole?!

Outlook 2007 Read Receipt Security Hole?!

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Outlook 2007 Read Receipt Security Hole?! Tyurin, Andrey 09-30-2008
Posted by =?Utf-8?B?VHl1cmluLCBBbmRyZXk= on September 30, 2008, 8:12 am
If you were  Registered and logged in, you could reply and use other advanced thread options


I have discovered that Read Receipt feature in Outlook 2007 contain security
hole that doesn't appear to be fixed or even described.

In "Options\E-mail Options\Tracking Options" I've feature named Read Receipt
set to "Never send a response".

Recently I received a few messages with titles "Undeliverable mail: Read:
...". After inspecting this mail messages I've found that their mime-headers
is OK and it looks like Outlook sent mail messages (without any
notifications) titled "Read: ..." to a few SPAM messages in my inbox (IMAP4
account). Of course these spam-messages have Read Receipt option set.

I've made simple test to determine is that really bug by undeleting
spam-messages in my inbox (stroked through), marking them unread and finally
deleting without reading it. Read receipts have arrived.

I think this is a huge security hole in Outlook 2007 because people sending
spam could find out who've active e-mail addresses.

--
Have a nice day!

Similar ThreadsPosted
How to get Digital Certificate for Outlook 2007? January 24, 2008, 4:56 pm
Cannot access Smarcard through outlook 2003/2007 October 26, 2007, 8:58 am
Digital Certificate for Outlook 2007 Email encryption and signing October 9, 2007, 7:33 pm
Read vs Write/Read Access Rights November 15, 2005, 3:52 pm
Read only NTFS not allowing Read of MS Access October 8, 2008, 11:17 am
Re: New IE security hole June 17, 2005, 3:51 pm
Need help plugging a hole in my security October 19, 2005, 10:28 am
Why is a network printer a security hole? March 14, 2008, 7:45 pm
Confusing GP text can open IE security hole November 13, 2007, 3:11 pm
Revealed: The Internet's Biggest Security Hole August 28, 2008, 12:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy