Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Malicious behavior performed by MS Outlook 98 (application/ms-tnef)

0 views
Skip to first unread message

Jeroen Pulles

unread,
Sep 17, 1998, 3:00:00 AM9/17/98
to
Hi all,

Imagine this:

I am subscribed to a mailing list named "SquidForum". I daily get emails from
this mailing list, many of which are redirected to the waste bin immediately.
One of those wasted emails contains an attachment from the original mailing list
contributor of the MIME application/ms-tnef. Without me knowing, Outlook (yes,
Outlook, not my uncle) replies to the deleted message with an email with me as
the sender (e.g. my account), titled "Not Read: <original message title>" and
with a application/ms-tnef attachment. This message is replied to the mailing
list, not the mailing list contributor. Next thing you know, all mailing list
recipients of "SquidForum" are receiving this mysterious email from 'me'. I,
surprised, see that I sent a contribution to the mailing list. Can't remember
having posted an email, I must be getting forgetful... I open up the email and
read: "Your message of date xxxx was deleted without being read bla bla". This
email cannot be found from the "sent items" folder, so I can't see if 'I' sent
it.

Nice, eh. Well, it happened to me.
And I am not amused.

Outlook can apparently send messages without letting the user know it does so
and without leaving a trace. And whilst stating that the user send the email.
How do I know if Outlook does this all the time? I consider sending autoresponds
in background operation as being malicious behavior.

- Is this an undocumented feature? Gee, smart thinking, Microsoft.
- What's the application/ms-tnef attachment?
- Does Bill Gates get a blind carbon copy of all my emails?


Some Privacy Please, MS people!
-- Jeroen Pulles


Email me at j dot pulles at io dot tudelft dot nl

Vince Averello [MVP-Outlook]

unread,
Sep 17, 1998, 3:00:00 AM9/17/98
to
The application/ms-tnef attachment is where Exchange derived clients store
the Rich Text Format information. Also, things like receipt requests get
stored there. That's what happened in your situation. The user that send
that item requested a read receipt and Outlook complied with the request
(sending a response that said "Not read" since you trashed the item without
reading it).

Jeroen Pulles <j.pu...@see.signature.nl> wrote in message
36010F64...@see.signature.nl...

Charlie Wilkinson

unread,
Sep 18, 1998, 3:00:00 AM9/18/98
to
Vince Averello [MVP-Outlook] <vi...@maverick.com> wrote:
> The application/ms-tnef attachment is where Exchange derived clients store
> the Rich Text Format information. Also, things like receipt requests get
> stored there. That's what happened in your situation. The user that send
> that item requested a read receipt and Outlook complied with the request
> (sending a response that said "Not read" since you trashed the item without
> reading it).

...this most likely being further aggrevated by a mailing list set up to
add/substitute its own address to a "Reply-To:" header in all outgoing
mail traffic. Outlook dutifully replied to the "sender" respecting the
Reply-To: address as it was intended to be.

The moral of the story is that mailing lists should not mangle headers,
most especially the Reply-To: field. What happened to you is a perfect
example of why. You may want to run this by the SquidForum admins and
point them at:

http://www.unicom.com/pw/reply-to-harmful.html

Other folks may chime in about the convenience or other advantages of
munging the Reply-To: field in outbound list traffic, but the bottom
line is that DOING IT BREAKS THINGS. As much as I can't stand Microsoft,
I can't really blame them for what happened in this case.

(Donning asbestos longjohns...)

-cw-

--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Charlie Wilkinson - cwil...@boink.clark.net
Parental Unit, UNIX Admin, Homebrewer, Cat Lover, Spam Fighter, Maintainer of
Radio For Peace International Website: http://www.clark.net/pub/cwilkins/rfpi
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
CLOBBER INTERNET SPAM: See!! <http://spam.abuse.net/>
Join!! <http://www.cauce.org/>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
QOTD:
The early bird who catches the worm works for someone who comes in late
and owns the worm farm.
-- Travis McGee

era eriksson

unread,
Sep 20, 1998, 3:00:00 AM9/20/98
to
On 18 Sep 1998 19:32:16 GMT, Charlie Wilkinson
<cwil...@boink.clark.net> posted to microsoft.public.outlook.usage,
comp.mail.misc:

> Vince Averello [MVP-Outlook] <vi...@maverick.com> wrote:
>> The application/ms-tnef attachment is where Exchange derived clients store
>> the Rich Text Format information. Also, things like receipt requests get
>> stored there. That's what happened in your situation. The user that send
>> that item requested a read receipt and Outlook complied with the request
>> (sending a response that said "Not read" since you trashed the item without
>> reading it).
> ...this most likely being further aggrevated by a mailing list set up to
> add/substitute its own address to a "Reply-To:" header in all outgoing
> mail traffic. Outlook dutifully replied to the "sender" respecting the
> Reply-To: address as it was intended to be.

Stuff like delivery/nondelivery reports should go to the envelope
sender, absolutely not the Reply-To: address. (Can anybody come up
with RFC chapter and verse?)

/* era */

--
Bot Bait: It shouldn't even matter whether (`') Just (`') http://www.iki
I am a resident of the State of Washington \/ Married! \/ .fi/~era/

0 new messages