Re: The Bat! and Mailsplit Vulnerability

2017-12-11 Thread Quality Office
Title: Re: The Bat! and Mailsplit Vulnerability Hello Maxim, Monday, December 11, 2017, 2:12:57 AM, you wrote: > We are now working on the first of the test messages. > https://bt.ritlabs.com/view.php?id=1364 > This is not a trivial fix. Hi Max. Not to worry.  I just wanted to

Re[2]: The Bat! and Mailsplit Vulnerability

2017-12-11 Thread Paul Van Noord
12/11/2017 7:33 AM Hi Maxim, On 12/11/2017 Maxim Masiutin wrote: >> I just did a test and I can confirm the problem is real. MM> We are now working on the first of the test messages. MM> https://bt.ritlabs.com/view.php?id=1364 MM> This is not a trivial fix. Understood, but has very high

Re: The Bat! and Mailsplit Vulnerability

2017-12-10 Thread Maxim Masiutin
Hello Ethan, Saturday, December 9, 2017, 8:03:14 PM, you wrote: > I just did a test and I can confirm the problem is real. We are now working on the first of the test messages. https://bt.ritlabs.com/view.php?id=1364 This is not a trivial fix. -- Best regards, Maxim Masiutin __

Re: The Bat! and Mailsplit Vulnerability

2017-12-10 Thread Maxim Masiutin
Saturday, December 9, 2017, 7:38:44 PM, Maxim Masiutin replied to Gwen's message: >> At https://www.mailsploit.com/index#demo you can send a mail with >> faked Sender adddres. > Thank you, we will do necessary changes in the code ASAP. Sorry for inappropriate quoting in the message quoted. --

Re: The Bat! and Mailsplit Vulnerability

2017-12-09 Thread Ethan J. Mings
Hello Maxim, Saturday, December 9, 2017, 12:38:44 PM, you wrote: > Thank you, we will do necessary changes in the code ASAP. I just did a test and I can confirm the problem is real. Jerry -- Ethan J Mings President, The Desk Consulting Group Inc Oakville, Ontario Canada. L6L 3B7 Write to me a

The Bat! and Mailsplit Vulnerability

2017-12-09 Thread Maxim Masiutin
Hello Gwen, Thank you, we will do necessary changes in the code ASAP. Tuesday, December 5, 2017, 5:06:04 PM, you wrote: > Hello tbbeta, > Hello Maxim, > At https://www.mailsploit.com/index#demo you can send a mail with > faked Sender adddres. > The Bat! may show wrong address. > Can you pleas

Re: The Bat! and Mailsplit Vulnerability

2017-12-05 Thread Jernej Simončič
On Tuesday, December 5, 2017, 18:26:59, Gwen wrote: > Did you made all 12 tests? > in message list pane click on some From addresses header pane. > Some header changes on click! You're right, I never tried clicking in the header pane - some of those that contain embedded NULs get cut off the text

Re: The Bat! and Mailsplit Vulnerability

2017-12-05 Thread Gwen
Hello tbbeta, On Tue, 5 Dec 2017, at 17:49:00 [GMT +0100] (which was 17:49 where I live) Jernej wrote: > On Tuesday, December 5, 2017, 16:06:04, Gwen wrote: >> Can you please check if fixes are needed? > TB always shows full address for me (which may look weird in some > tests, but that's the wa

Re: The Bat! and Mailsplit Vulnerability

2017-12-05 Thread Jernej Simončič
On Tuesday, December 5, 2017, 16:06:04, Gwen wrote: > Can you please check if fixes are needed? TB always shows full address for me (which may look weird in some tests, but that's the way it's encoded). TB is probably less vulnerable to these problems, since it's written in Delphi, where strings

The Bat! and Mailsplit Vulnerability

2017-12-05 Thread Gwen
Hello tbbeta, Hello Maxim, At https://www.mailsploit.com/index#demo you can send a mail with faked Sender adddres. The Bat! may show wrong address. Can you please check if fixes are needed? -- Regards Gwen Using The Bat! Version 8.0.14.2 (BETA) (32-bit) on Windows 10.0 (Build 16299 ) pgpkVMA