On Wed, Jun 16, 2004 at 01:26:28PM +0200, R Armiento wrote:
[snip]
> For example: attacker 'A' sends 'B' a social engineering request
> for "the secret plans" and says "if you are unsure, forward my
> request to your boss and ask if this is okay". 'B' forwards the
> email to his boss 'C' and asks "Is this okay?". However, 'C':s
> spam filter silently drops the email. 'A' forges a reply from
> 'C' saying: "Sure, no problem, go ahead."
Many will probably discard the above as farfetched or ignore it
since it's not a "real" vulnerability that gives remote root to
the attacker, I think it's beautiful though. :)