[GH-ISSUE #416] Security: visual spoofing of email (address, name), attachment name, etc. #346

Open
opened 2026-02-25 21:34:48 +03:00 by kerem · 4 comments
Owner

Originally created by @dumblob on GitHub (Jul 29, 2020).
Original GitHub issue: https://github.com/cypht-org/cypht/issues/416

Originally assigned to: @jasonmunro on GitHub.

🗣 Suggestion

Current severe issues making it impossible to visually detect there is something wrong with the contents you're dealing with:

https://www.virtuesecurity.com/pentesting-user-interfaces/

Note, I didn't test this in Cypht, but I think there could be some more countermeasures implemented 😉.

Originally created by @dumblob on GitHub (Jul 29, 2020). Original GitHub issue: https://github.com/cypht-org/cypht/issues/416 Originally assigned to: @jasonmunro on GitHub. ## 🗣 Suggestion Current severe issues making it impossible to visually detect there is something wrong with the contents you're dealing with: https://www.virtuesecurity.com/pentesting-user-interfaces/ Note, I didn't test this in Cypht, but I think there could be some more countermeasures implemented :wink:.
Author
Owner

@jasonmunro commented on GitHub (Jul 29, 2020):

I think we are safe from some of this, but I am definitely going to test it out :)

<!-- gh-comment-id:665966323 --> @jasonmunro commented on GitHub (Jul 29, 2020): I think we are safe from some of this, but I am definitely going to test it out :)
Author
Owner

@marclaporte commented on GitHub (Jul 31, 2022):

@dumblob Any chance you could do a quick test?

<!-- gh-comment-id:1200482325 --> @marclaporte commented on GitHub (Jul 31, 2022): @dumblob Any chance you could do a quick test?
Author
Owner

@dumblob commented on GitHub (Nov 7, 2022):

No time now to set up a current Cypht version. But let us fill the following table first:

particular visual spoofing permalink to source code line(s) dealing with it
URLs in email bodies (both in plain text and HTML) MISSING
attachment names MISSING
email addresses "everywhere" (in email headers, bodies, etc.) MISSING
RTL/LTR domains MISSING
<!-- gh-comment-id:1305841599 --> @dumblob commented on GitHub (Nov 7, 2022): No time now to set up a current Cypht version. But let us fill the following table first: particular visual spoofing | permalink to source code line(s) dealing with it --- | --- URLs in email bodies (both in plain text and HTML) | **MISSING** attachment names | **MISSING** email addresses "everywhere" (in email headers, bodies, etc.) | **MISSING** RTL/LTR domains | **MISSING**
Author
Owner

@marclaporte commented on GitHub (May 7, 2024):

@dumblob

Please retest, as a lot has changed since you reported this issue. Notably, we now have 3 active branches and recently released Cypht 2.0.0

<!-- gh-comment-id:2097121639 --> @marclaporte commented on GitHub (May 7, 2024): @dumblob Please retest, as a lot has changed since you reported this issue. Notably, we now have 3 active branches and recently released Cypht 2.0.0 - https://github.com/cypht-org/cypht/releases/tag/v2.0.0 - https://github.com/cypht-org/cypht/wiki/Lifecycle
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/cypht#346
No description provided.