Remote css-stylesheets are loaded with remote image loading off

RESOLVED DUPLICATE of bug 28327

Status

Thunderbird
Mail Window Front End
--
major
RESOLVED DUPLICATE of bug 28327
13 years ago
13 years ago

People

(Reporter: Rudolf Horbas, Assigned: Scott MacGregor)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

13 years ago
User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6) Gecko/20040705 hypotext
Build Identifier: Mozilla Thunderbird 0.8 (Windows/20040913)

I turned the loading of remote images off becaues this is used by spammers to
verify mal addresses. But -- remote stylesheets in HTML mails are loaded via
http, which also enables spammers to use an unique id:

<link rel="stylesheet" type="text/css"
href="http://www.somespammer.example/layout.css?id=foo@bar.baz">

Which leads to the same success as loading a pixel gif with an id ...

Reproducible: Always
Steps to Reproduce:
1.
2.
3.



Expected Results:  
Not load anything from outside.

*** This bug has been marked as a duplicate of 28327 ***
Group: security
Status: UNCONFIRMED → RESOLVED
Last Resolved: 13 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.