RES: blocking messages with <form> tags

Rodrigo Scarano rscarano at targetsis.com.br
Tue Jul 22 13:49:41 IST 2003


Sylvain,
I use Allow IFrame Tags = yes and Allow Object Codebase Tags = yes, but the
line Convert Dangerous HTML To Text is set to yes. I guess i'm secure with
this.

Regards,



Rodrigo Scarano
Target Sistemas
http://www.targetsis.com.br/
rscarano at targetsis.com.br


-----Mensagem original-----
De:     MailScanner mailing list [mailto:MAILSCANNER at JISCMAIL.AC.UK] Em nome de
Sylvain Phaneuf
Enviada em:     Terça-feira, 22 de Julho de 2003 06:19
Para:   MAILSCANNER at JISCMAIL.AC.UK
Assunto:        blocking messages with <form> tags

Hi everyone,

I have upgraded MS to 4.22-5 last week, and selected to block messages
containing form tags. I am quite puzzled to see how many messages we
have stopped because of that. It seems that a lot of genuine mail is
coming with those form tags, e.g. from medical /scientific abstract
services.

I haven't got a clue how dangerous can these forms be. Should I
continue stopping these messages? I noticed that a few services seem to
know that their messages are likely to be stopped, they have the
following line in plain text at the top of the message:
""If you cannot view this email, please copy and paste the following
link into your browser: http://master.emedicine.com/email/radio23.html""


Thanks in advance for sharing your opinions.



Sylvain

===========================================================
Sylvain Phaneuf --- Computing Manager   | phone : +44 (0)1865 221323
Information Management Services Unit  -  Medical Sciences Division
Oxford University                               | email :
sylvain.phaneuf at imsu.ox.ac.uk
Room 3A25B John Radcliffe Hospital      | fax :  +44 (0) 1865 221322
Oxford   OX3 9DU   England
===========================================================




More information about the MailScanner mailing list