Imagine this:
I am subscribed to a mailing list named "SquidForum". I daily get emails from
this mailing list, many of which are redirected to the waste bin immediately.
One of those wasted emails contains an attachment from the original mailing list
contributor of the MIME application/ms-tnef. Without me knowing, Outlook (yes,
Outlook, not my uncle) replies to the deleted message with an email with me as
the sender (e.g. my account), titled "Not Read: <original message title>" and
with a application/ms-tnef attachment. This message is replied to the mailing
list, not the mailing list contributor. Next thing you know, all mailing list
recipients of "SquidForum" are receiving this mysterious email from 'me'. I,
surprised, see that I sent a contribution to the mailing list. Can't remember
having posted an email, I must be getting forgetful... I open up the email and
read: "Your message of date xxxx was deleted without being read bla bla". This
email cannot be found from the "sent items" folder, so I can't see if 'I' sent
it.
Nice, eh. Well, it happened to me.
And I am not amused.
Outlook can apparently send messages without letting the user know it does so
and without leaving a trace. And whilst stating that the user send the email.
How do I know if Outlook does this all the time? I consider sending autoresponds
in background operation as being malicious behavior.
- Is this an undocumented feature? Gee, smart thinking, Microsoft.
- What's the application/ms-tnef attachment?
- Does Bill Gates get a blind carbon copy of all my emails?
Some Privacy Please, MS people!
-- Jeroen Pulles
Email me at j dot pulles at io dot tudelft dot nl
Jeroen Pulles <j.pu...@see.signature.nl> wrote in message
36010F64...@see.signature.nl...
...this most likely being further aggrevated by a mailing list set up to
add/substitute its own address to a "Reply-To:" header in all outgoing
mail traffic. Outlook dutifully replied to the "sender" respecting the
Reply-To: address as it was intended to be.
The moral of the story is that mailing lists should not mangle headers,
most especially the Reply-To: field. What happened to you is a perfect
example of why. You may want to run this by the SquidForum admins and
point them at:
http://www.unicom.com/pw/reply-to-harmful.html
Other folks may chime in about the convenience or other advantages of
munging the Reply-To: field in outbound list traffic, but the bottom
line is that DOING IT BREAKS THINGS. As much as I can't stand Microsoft,
I can't really blame them for what happened in this case.
(Donning asbestos longjohns...)
-cw-
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Charlie Wilkinson - cwil...@boink.clark.net
Parental Unit, UNIX Admin, Homebrewer, Cat Lover, Spam Fighter, Maintainer of
Radio For Peace International Website: http://www.clark.net/pub/cwilkins/rfpi
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
CLOBBER INTERNET SPAM: See!! <http://spam.abuse.net/>
Join!! <http://www.cauce.org/>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
QOTD:
The early bird who catches the worm works for someone who comes in late
and owns the worm farm.
-- Travis McGee
Stuff like delivery/nondelivery reports should go to the envelope
sender, absolutely not the Reply-To: address. (Can anybody come up
with RFC chapter and verse?)
/* era */
--
Bot Bait: It shouldn't even matter whether (`') Just (`') http://www.iki
I am a resident of the State of Washington \/ Married! \/ .fi/~era/