Why emails do not upload images directly

Email providers such as Gmail, yahoo, hotmail do not upload images directly to email. These services require the images to be laminated. Why are they doing this? Should XSS / CSRF be prevented?

+3
source share
3 answers

Two reasons are confidentiality and CSRF.

Privacy

This allows the sender to find out if I opened the email or not, without my knowledge. Spammers can find out if their marketing campaigns have had any consequences or not.

CSRF

CSRF , . , CSRF.

, , paypal csrf. , PayPal. <img src="http://paypal.com/transferfunds?fromAccount=victim&toAccount=attacker"/>. , .

+5

, .

+2

- . :

<img src="http://example.com/validImage.png?mail=toto@example.com" />
0
source

Source: https://habr.com/ru/post/1762424/


All Articles