Found dangerous Object Codebase tag...

Julian Field mailscanner at ecs.soton.ac.uk
Wed Aug 13 11:35:50 IST 2003


At 18:08 12/08/2003, you wrote:
>An HTML tag that causes a browser to load programming code when the page is
>viewed.  Some mail filtering systems "defang" such tags by changing them to
>something safe, which usually leaves the rest of the message completely
>readable, but I don't think (and will hopefully be corrected if I'm wrong)
>that MS yet can be made to do that.

# Do you want to convert HTML messages containing <IFrame> or
# <Object Codebase=...> tags into plain text?
# This will only apply if you are also allowing the tags to be present
# using the configuration options above. You can allow messages
# that contain the tags, but convert them to plain text. This makes
# the HTML harmless, while still allowing your users to see the text
# content of the messages.
# This can also be the filename of a ruleset, so you can make this apply
# only to specific users or domains.
Convert Dangerous HTML To Text = no

--
Julian Field
www.MailScanner.info
MailScanner thanks transtec Computers for their support



More information about the MailScanner mailing list