Bug 461050 - Bogus scam warning with trailing space
Summary: Bogus scam warning with trailing space
Status: REPORTED
Alias: None
Product: kmail2
Classification: Applications
Component: general (show other bugs)
Version: 5.19.3
Platform: openSUSE Linux
: NOR normal
Target Milestone: ---
Assignee: kdepim bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-10-27 04:50 UTC by Volker Kuhlmann
Modified: 2023-04-27 05:52 UTC (History)
2 users (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments
Email with bogus scam warning (30.95 KB, text/plain)
2023-04-27 00:31 UTC, Volker Kuhlmann
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Volker Kuhlmann 2022-10-27 04:50:02 UTC
SUMMARY
Bogus scam warning with trailing space in link text.

STEPS TO REPRODUCE
1. Read an email like this in kmail.

OBSERVED RESULT
Big warning in red reading "This email contains a link which reads as 'https://1stdomains.nz/renew ' in the
text, but actually points to 'https://1stdomains.nz/renew'. This is often the
case in scam emails to mislead the recipient"

EXPECTED RESULT
No warning.
I'm not too worried about a trailing space in the link text.

SOFTWARE/OS VERSIONS
5.19.3 (21.12.3)
Linux (x86_64) release 5.14.21-150400.24.21-default
openSUSE Leap 15.4
Comment 1 Laurent Montel 2022-12-16 05:47:22 UTC
Do you have a test case please ?
Comment 2 Volker Kuhlmann 2023-04-26 23:53:46 UTC
You mean an actual email where someone has put a link into the body where the link text in the HTML is the same as the link except with an added space at the end? It wouldn't take more than 5 seconds for anyone to make such an email.
Comment 3 Volker Kuhlmann 2023-04-27 00:31:07 UTC
Created attachment 158471 [details]
Email with bogus scam warning

Show this email, in kmail - default HTML off.
kmail shows "This message may be a scam. (Details...)" and offers to move it to wastebin.
Details: "This email contains a link which reads as 'https://status.voyager.nz/ ' in the text, but actually points to 'https://status.voyager.nz/'. This is often the case in scam emails to mislead the recipient"

A trailing space in the path part of the link text is not a scam.
Comment 4 Laurent Montel 2023-04-27 05:52:59 UTC
(In reply to Volker Kuhlmann from comment #2)
> You mean an actual email where someone has put a link into the body where
> the link text in the HTML is the same as the link except with an added space
> at the end? It wouldn't take more than 5 seconds for anyone to make such an
> email.

Yep :) 
but it seems that it takes you more than 5 seconds :)
Thanks