There's a pleasing symmetry about the latest security issue involving Outlook Express.
For the last couple of years Outlook (Lookout) Express failings have been exploited to infect users. So why not take advantage of its features to send viruses in such a way that they might fool detection by AV and content checking tools?
Well that's the gist of a new method of bypassing many SMTP-based content filter engines, unearthed by researchers at Beyond Security.
Using a rarely used feature called 'message fragmentation and re-assembly' (MFR), an attacker can send emails that will "bypass most SMTP filtering engines", Beyond Security reports.
|