christoph ender


Hello there! These pages are intended to share notes and experiences from my work as an IT freelancer – yes, you can hire me – working in OPs, networking and development.
→ read more …


mobile: +49 (0)171 1592365
pgp: 0fe1e446f585711c3d56d45154f51a402f3c6660 2f3c6660

latest blog entry: “Kobold letters”

Turns out specific e-mails, called Kobold letters, may change their contents when they're forwarded, simply by putting properly coded CSS into the mail:

This attack is possible because most email clients allow CSS to be used to style HTML emails. When an email is forwarded, the position of the original email in the DOM usually changes, allowing for CSS rules to be selectively applied only when an email has been forwarded.

Currently the only defense appears to be switching off HTML in e-mails alltogether.

→ read more …