English - French - Italian


Microsoft

Simple CSS can be used to bypass anti-phishing Outlook warning...

Peter • Wednesday, August 7, 2024 • 2 mins read (278)


The issue:

To help user to pay better attention to email from unfamiliar addresses, Microsoft 365 add a warning to the email stating “You don't often get email from xyz@example.com. Learn why this is important”.
The so called "First Contact Safety Tip" (from Exchange Online Protection (EOP) and Microsoft Defender).

How:

The method involves using specific CSS rules to hide the safety tip, making it invisible to recipients.

And now ?

Despite Certitude reports this vulnerability to Microsoft, the company has opted not to address it immediately, stating that it does not meet their criteria for urgent action. Microsoft acknowledged the validity of the findings but indicated it would be considered for future product improvements.
"We determined your finding is valid but does not meet our bar for immediate servicing considering this is mainly applicable for phishing attacks. However, we have still marked your finding for future review as an opportunity to improve our products. Microsoft MSRC, 14.02.2024".

Credits: certitude consulting - o365-anti-phishing-measures



New Outlook flaw: MonikerLink


Roundcube mail server fix