LESSON 9 E-MAIL SECURITY part IV

9.2.2 HTML E-Mail
One of the security concerns with HTML based e-mail is the use of web bugs. Web bugs are
hidden images in your e-mail that link to the senders’ web server, and can provide them with
notification that you have received or opened the mail. Another flaw with HTML e-mail is
that the sender can embed links in the e-mail that identify the person who clicks on them.
This can give the sender information about the status of the message. As a rule, you should
use a mail client that allows you to disable the automatic downloading of attached or
embedded images. Another problem is related to scripts in the e-mail that may launch an
application ,if your browser has not been patched for security flaws.
For web based e-mail clients, you may have the option of disabling the automatic download
of images, or viewing the message as text. Either is a good security practice. The best way to
protect yourself against HTML e-mail based security and privacy attacks is to use text based email.
If you must use HTML e-mail, beware!

 

9.2.2 超文本电子邮件

超文本电子邮件的一个安全问题是网络爬虫。网络爬虫在你的电子邮件中看不到东西,这些爬虫连接到发送该邮件人的网络服务器上,提醒这些人你已经收到并打开这封邮件了。HTML电子邮件的另一个漏洞是发送者能在邮件中贴上链接,通过这些链接来确认点击链接的人。这种方法给发送者提供了关于这封邮件状态的信息。通常来说,你要用电子邮件客户端来阻断邮件中附带图片的自动下载。如果你的浏览器没有安装安全补丁,电子邮件文字部分都可能运行一个应用程序。

对基于网页电子邮件客户端来说,你可以选择阻断电子邮件中附带图片的自动下载,或者用文本形式来阅读这些邮件。这都是一个很好的安全方式。对HTML电子邮件来说,最好的防范安全和隐私攻击的方式是使用文本电子邮件。

 

9.2.3 Attachment Security
Another real concern related to received e-mail security is attachments. Attackers can send
you malware, viruses, Trojan horses and all sorts of nasty programs. The best defense against
e-mail borne malware is to not open anything from anyone you don’t know. Never open a
file with the extension .exe or .scr, as these are extensions that will launch an executable file
that may infect your computer with a virus. For good measure, any files you receive should be
saved to your hard drive and scanned with an antivirus program. Beware of files that look like
a well known file type, such as a zip file. Sometimes attackers can disguise a file by changing
the icon or hiding the file extension so you don’t know it is an executable.

 

9.2.3  附件安全

另一个比较关注的电子邮件安全问题是附件安全。攻击者会给你发送流氓插件,病毒,木马以及各种各样恶意程序。最好的防御措施是不打开你不认识的人发给你的邮件。不要打开一个带有extension.exe或.scr的文件,因为这些文件可能是一个可执行文件,会让你的电脑感染上病毒。还有一个比较好的措施,将这些文件保存到硬盘上,用杀毒软件扫描。注意那些你认识格式的文件,譬如一个zip文件。因为有时候,攻击者能通过改变文件的图标或者隐藏该文件的扩展名来假装别的格式的文件,你就不知道这些文件其实是可执行的问价。

 

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值