Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

RE: MS to stop allowing passwords in URLs
From: "Richard M. Smith" <rms () computerbytesman com>
Date: Tue, 3 Feb 2004 07:54:22 -0800

   >>> Anyone have any comments regarding legitimate 
   >>> uses of this syntax and Microsoft removing it 
   >>> from their browser? (and presumably the OS since
   >>> the browser IS the OS).

It always was a bad idea to put plaintext passwords in URLs because it
encouraged users to give away passwords in links on public Web pages.  The
spoofing games were the second big problem with them that showed up later.
Glad to see Microsoft getting rid of the feature.

Richard 


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]