Vulnerability Development mailing list archives

Re: Winnt/Win2k Vuln ?


From: Kevin Gagel <Gagel () cnc bc ca>
Date: Fri, 10 Aug 2001 13:41:17 -0700



David Schwartz wrote:


---cut---

        If you care about security, enter fully-qualified URLs, don't use
abbreviations. Any scheme to accept abbreviations will sometimes fail to get

Unfortunatly in an educational environment we have little control over
users.
They just love to click and double click on anything. Entering a
fully-qualified
URL would be like work for most of them. So for us this is a problem.

---cut---


        I only wish you could disable them. Both IE and Netscape have done things I
didn't expect more than once.


Disabling them would be nice, but what could we do about the browsers?
;-)

-- 
=============================
Kevin W. Gagel
Network Administrator
College of New Caledonia
gagel () cnc bc ca
(250)561-5848 loc. 448
=============================


Current thread: