"Mailto:" and Other URI Threats May Target Everyone
Created 2007-10-15 14:54

RELATED ARTICLES
  • I Practice Safer Browsing
  • Think Before You Click on That Great "Job Offer"
  • Protect Your Linux Box from Viruses
News
  • Hitachi and Intel Join Forces to Develop Breakthrough Performance SSDs
  • One Billion Logitech Mice Now in the Wild
  • Canon May Pursue SED Display Technology after Winning Legal Battles
  • YouTube Clamping Down on Family-Unfriendly Content
  • VIA's Dual Core Nano Goes Into Production in 2010
SEE MORE NEWS
News

"Mailto:" and Other URI Threats May Target Everyone

Posted 10/15/07 at 04:54:55 PM |  by Mark Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponReddit

If you've been smirking because of the latest security problems coming out of Redmond, such as the Windows XP+IE7+Adobe Acrobat/Reader threat I discussed last week in Didn't Ask for That PDF File? Watch Out!, it may be time to sober up. According to PCWorld.com on Saturday, URI-handling problems like Mailto: are also likely to exist in Windows' biggest rivals: MacOS X and Linux.

URI 101

So, what's a URI? URI is short for "Uniform Resource Identifier." A URI identifies a point of content on the Internet, such as a web page (also known as a URL), an email address, a Telnet server, and so forth (see this PC Magazine page for a list of the most common URI schemes). Of course, URIs are used inside of web browsers, but email clients, word processing programs used as email editors, Adobe Acrobat and Adobe Reader are just a few of the applications that can interact with the mailto: URI, for example. Until now, Microsoft's attitude has been that applications that interact with URIs should be responsible for checking for threats, but that attitude is changing, as evidenced by last week's security advisory: Microsoft has now decided that it's up to the operating system to keep an eye on applications' use of URIs.

All Will Be Revealed..at ToorCon 9!

So, will Linux and MacOS X be the next under the hammer? Attendees at the ToorCon 9 hacker/security conference in San Diego this week will have front-row seats for the latest word on this topic. The presentation URI Use and Abuse is the place to be to learn about the latest threats to all major players in the operating systems game. If security researchers' suspicions about other operating systems are accurate, it looks as if everyone will be in for a few rounds of software updates.

In the Meantime...

...you know the drill. Hover the mouse over a URL or URI from a suspicious source to find out where it really points to, ignore all those dire warnings from "your bank" or from "eBay" that your account's gone down the tubes unless you click now, and, in general: think before you click.

COMMENTS:
1
TAGS: 
vista, windows, Security, virus, malware, linux, XP, threat, MacOS X, hacker
comment Commentsprint Printemail EmailDeliciousDiggStumbleUponReddit
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2008 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/mailto_and_other_uri_threats_may_target_everyone

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://www.maximumpc.com/article/didnt_ask_for_that_pdf_file_watch_out
[3] http://www.pcworld.com/article/id,138428-pg,1/article.html
[4] http://www.pcmag.com/encyclopedia_term/0,2542,t=URI scheme&i=53515,00.asp
[5] http://www.microsoft.com/technet/security/advisory/943521.mspx
[6] http://toorcon.org/2007/intro.php
[7] http://toorcon.org/2007/event.php?id=35
[8] http://www.uc.edu/infosec/HowToTellIfaMSmsgIsGenuine.htm
[9] http://www.maximumpc.com/article/safer_browsing
[10] http://www.maximumpc.com/article/think_before_you_click_on_that_great_job_offer
[11] http://www.maximumpc.com/article/protect_your_linux_box_from_viruses
[12] http://cve.mitre.org/cve/index.html
[13] http://nvd.nist.gov/home.cfm