Closed
Bug 168258
Opened 22 years ago
Closed 22 years ago
Even with Cookie in Mail off cookies are being set when getting css in HTML mail
Categories
(MailNews Core :: Security, defect)
MailNews Core
Security
Tracking
(Not tracked)
People
(Reporter: bugzilla, Assigned: security-bugs)
References
()
Details
set Mozilla to "dont accept cookies" in Mozilla Mail
set Mozilla to "dont show remote images" in Mozilla Mail
set Mozilla to show "original HTML"
now send a mail to browserspyhtmlmail@gemal.dk
now check your cookies in the Cookie manager. A cookie from gemal.dk is now present!
20020911
Comment 1•22 years ago
|
||
This is extremely easy to confirm, for me on 1.1final Win32.
Reporter | ||
Comment 2•22 years ago
|
||
the cookie is inserted form the HTTP request of the css file from a HTML mail.
See bug 168174 about the css fetch
Depends on: 168174
Comment 3•22 years ago
|
||
This is actually a dup of bug 22994 (Mail reader allows spammers to set cookies
to track web usage) and it indicates that there is more work to be done for that
bug.
*** This bug has been marked as a duplicate of 22994 ***
Status: NEW → RESOLVED
Closed: 22 years ago
Resolution: --- → DUPLICATE
Comment 5•22 years ago
|
||
henrik, is browserspyhtmlmail@gemal.dk still up and running?
Reporter | ||
Comment 6•22 years ago
|
||
it's browserspy-htmlmail@gemal.dk
just send a mail and you get a HTML test mail return. The tests include image support, scripting support, cookies, etc
henrik, is browserspy-htmlmail@gemal.dk still up and running?
Updated•20 years ago
|
Product: MailNews → Core
Updated•17 years ago
|
Product: Core → MailNews Core
You need to log in
before you can comment on or make changes to this bug.
Description
•