Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: MS to stop allowing passwords in URLs
From: Paul Smith <paullocal () pscs co uk>
Date: Tue, 03 Feb 2004 16:52:34 +0000

At 22:54 28/01/2004, McAllister, Andrew wrote:
I just read that Microsoft will stop allowing IDs and passwords to be
embedded in URLs used by Internet Explorer. So you will no longer be
able to use a URL like https://user:password () www somehost com/

See http://support.microsoft.com/default.aspx?scid=kb;en-us;834489

Anyone have any comments regarding legitimate uses of this syntax and
Microsoft removing it from their browser? (and presumably the OS since
the browser IS the OS).

Personally, I think it's a reasonable step - these spoofed URLs are a big problem for many people.

You can disable the functionality in IE if you wish (the above link has details)

I think I'd prefer it if you could override it on a site by site basis (eg using the 'trusted sites' functions, or by having the username:password () url in your IE 'favourites')

(Although, having said that, having spammers use http://username () url is quite a good trigger to put in email anti-spam rules, as I've never seen anyone use that format in an email link legitimately..)
Paul                            VPOP3 - Internet Email Server/Gateway
support () pscs co uk                   http://www.pscs.co.uk/



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]