[Esa-l] Anyone have a comprehensive webmail URI list?

John D. Hardin jhardin at impsec.org
Thu Aug 23 06:56:22 PDT 2001

On Thu, 23 Aug 2001 Karl.Dunn at vmic.com wrote:

> You will probably have to block https too, at least for all sites
> except for a chosen few with which you do e-business.  If you
> don't, lusers can use redirectors like SafeWeb to download/upload
> stuff anyway.  Ours do, and I have been directed not to block
> https at all. 

Can you swing a policy commitment from the upper management that says
anyone (including said upper management) who brings in an infected
attachment via webmail pays your cleanup costs?

