Full Disclosure mailing list archives
RE: Microsoft's fix for URL containing username:password@ obfuscation
From: "Zach Forsyth" <Zach.Forsyth () kiandra com>
Date: Wed, 28 Jan 2004 13:47:44 +1100
Great solution :( Love the MS way of fixing things... It fixes url obfuscation somehwat but doesn't this break ftp functionality in IE when behind a firewall? If you type in ftp.mysite.com or whatever, IE automatically logs you in using anonymous credentials. If the site allows anonymous logins you don't get the chance to login using your own credentials, you are just taken straight in. Anone know a workaround to tell IE not pass anonymous credentials automatically? Cheers z
-----Original Message----- From: Bobby Brown [mailto:bbrown () netsecadmin com] Sent: Wednesday, 28 January 2004 12:57 PM To: full-disclosure () lists netsys com Subject: [Full-disclosure] Microsoft's fix for URL containing username:password@ obfuscation Summary Microsoft plans to release a software update that removes support for handling user names and passwords in HTTP and HTTP with Secure Sockets Layer (SSL) or HTTPS URLs in Microsoft Internet Explorer. The following URL syntax is no longer supported in Internet Explorer or Windows Explorer after you install this software update: http(s)://username:password@server/resource.ext This article is intended to give you advance notice of this change in Internet Explorer's default behavior. If you include user information in HTTP or HTTPS URLs, Microsoft recommends that you explore the workarounds that are described in this article before you install this software update. Microsoft will post more information in this article when the software update becomes available. http://support.microsoft.com/default.aspx?scid=kb;[LN];834489 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: Microsoft's fix for URL containing username:password@ obfuscation Zach Forsyth (Jan 27)
- Re: Microsoft's fix for URL containing username:password@ obfuscation George Capehart (Jan 27)
- Re: Microsoft's fix for URL containing username:password@ obfuscation Thomas Frenzel (Jan 27)
- <Possible follow-ups>
- Microsoft's fix for URL containing username:password@ obfuscation Bobby Brown (Jan 27)
- Re: Microsoft's fix for URL containing username:password@ obfuscation Daniel . Capo (Jan 28)
- RE: Microsoft's fix for URL containing username:password@ obfuscation Zach Forsyth (Jan 27)
- Re: Microsoft's fix for URL containing username:password@ obfuscation Cael Abal (Jan 28)
- Re: Microsoft's fix for URL containing username:password@ obfuscation Nick FitzGerald (Jan 28)
- RE: Microsoft's fix for URL containing username:password@ obfuscation Kenton Smith (Jan 28)
- RE: Microsoft's fix for URL containing username:password@ obfuscation Ron DuFresne (Jan 28)
- Re: Microsoft's fix for URL containing username:password@ obfuscation Cael Abal (Jan 28)