so just a wild guess if u sent to a group of your contacts in Outlook and is has a bad 
adresss this can happen ?

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of R. Scott Perry
Sent: 3. oktober 2003 15:35
To: [EMAIL PROTECTED]
Subject: Re: [Declude.Virus] Blank Folding



>Why is this mail cached by the "blank folder"
>
>I can't see anywhere that there are an error which should cause this

The Outlook "Blank Folding" Vulnerability occurs when there is a line in 
the headers with just a single space or a single tab character.  In this case:

>From: "Eivind Pettersen" <[EMAIL PROTECTED]>
>To: =?iso-8859-1?Q?Helge_B=F8e_=28E-post=29?= <[EMAIL PROTECTED]>,
>         "Carl E. M. Flygare (E-post)" <[EMAIL PROTECTED]>,
>         "Harald Fossum (E-post)" <[EMAIL PROTECTED]>,
>         "Petter(jobb) (E-post)" <[EMAIL PROTECTED]>,
>         =?iso-8859-1?Q?Karl_Erik_Sletteb=F8e_=28E-post=29?= 
> <[EMAIL PROTECTED]>,
>
>X-Declude-Sender: [EMAIL PROTECTED] [213.236.237.229]

The last header (before Declude added its headers) was a line with just a 
single tab character.  This is in violation of RFC822 3.2.3, and creates 
the vulnerability.  Even more interesting, it appears that the mail client 
dropped off one of the recipients -- the last one ends with a ",", which 
would imply that there were more addresses that "disappeared."

                                                    -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to