top | item 3664234

(no title)

jeffreyg | 14 years ago

Doesn't gmail stop these attacks without needing to force plaintext only by simply disabling images by default?

discuss

order

mike-cardwell|14 years ago

Yes. There was a bug a few years back though where they would display attached SVG images. These images could actually contain javascript, which left it vulnerable to XSS.

aptwebapps|14 years ago

Why is zzz90210's post dead? Everyone knows about tracking via images. I never considered something like bgsound, probably a lot of other people did not as well.

And it's the whole point of the article.