Scripting Concerns in OutlooK+Ie4+? 
 Scripting Concerns in OutlooK+Ie4+?

Outlook Security Script Concerns
I think its a good thing to have the functionality of ie4 in a e-mail package but it is open to abuse from Malicious programmers wishing to drop viruses freeze browsers etc. presumably you can use active x as well which has numerous flaws in it (close operating systems,rename directorys,steal money from a quicken user etc, for a demonstration of what i mean click the buttons below (Note:this will freeze outlook express).

If you clicked them you would have seen the code and with a little tweaking
Vb script will do the same.

Solution would be plain text but this is not enabled at default or to only allow
flash or animated gifs.
as soon as you bring any sort of functionality into a application people abuse it!!!

Scripting is great fun and easy to learn and can give amazing effects but
security has to come before functionality eg. Hidden fields, Impossible
calculations,getting e-mail addresses,onload on unload commands,
infinite loops etc .
Some of these functions are incredibly useful but when abused are incredibly annoying!

responses to this thread would be appreciated

A Microsoft Luva :)

Tue, 14 Aug 2001 03:00:00 GMT  
 Scripting Concerns in OutlooK+Ie4+?
Yep, there is lot's of bad stuff that can be done from JavaScript inside
of Email messages.  Here is information about of some of the problems:


Tue, 14 Aug 2001 03:00:00 GMT  
