Intrusion Detection Systems mailing list archives

IE 5


From: axe () marmoset net (Parasu Allumpalam)
Date: Sun, 3 Oct 1999 18:14:09 -0400 (EDT)




Hi,

I am a graduate student working on my masters in computer science. I am
interested in the area of network security and find this mailing list
vry informative.

Going on to my question, I was recently using Micro$oft Internet Explorer
5.0 to do FTP to a site which requires me to login , so I do login and get
my files. the next time I typed the words "ftp://"; in the location box in
the browser, to my shock it displayed the history of ftp with my login
name and password in clear text like "password () domain com">ftp://loginname:password () domain com</A>"
So if anybody who  used that brower to ftp will have access to my account.

I guess this info is stored in the history files right? Is there anyway
that this information is deleted automatically? and I guess this is
another security hole thro the browser. Have any of you come across this?

Thanks

Axe



Current thread: