EFAIL and Microsoft GPO Policy Chaos

by butsch 16. May 2018 17:37



There is a man-in-the-middle leak where you can capture an E-Mail (Only if you have access to the flow) attach a content

And if the CLIENT does autoload (When you open the E-Mail) external pictures get content. Now this would not be too complicated if there where

No newsletters where people store large pictures external on webserver and the users want that active the moment the get the E-Mail.

Remember your Outlook.exe at home blocks the pictures and you have to manual download them with right click.




From 2012 ;-)


The user wants's it > IT does it. That's why it's called IT




Solution: check your GPO Policy and turn/change things. Remember by DEFAULT external content is NOT loaded.

New problem ;-)


Sometimes when it comes to GPO's you have to do a post doc in IT to understand this.

Is it now?

"Display pictures and external content in HTML e-mail"

Or should it be?

"Do not Display pictures and external content in HTML e-mail"

If you read the Description it says you have to enable > Then Outlook will NOT automatically download.

That is kind of confusing? Well no the people who write such things are developers and normally they are not normal.



Comments are closed

Werbung von Drittfirmen (Nicht Butsch Informatik):

Werbung von Drittfirmen via Google Adsense: