[67149] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Latest IE patch breaking non username:password@encoded websites?

daemon@ATHENA.MIT.EDU (David Schwartz)
Tue Feb 3 13:24:26 2004

From: "David Schwartz" <davids@webmaster.com>
To: <nanog@merit.edu>
Date: Tue, 3 Feb 2004 10:21:13 -0800
In-Reply-To: <012b01c3ea7b$f52fe6a0$0b01a8c0@bryanhhome>
X-MDaemon-Deliver-To: nanog@merit.edu
Reply-To: davids@webmaster.com
Errors-To: owner-nanog-outgoing@merit.edu



> Yes they broke basic auth in a URL.
>
> I am uncertain as to why it was necessary to remove this functionality.
>
> Bryan

	Apparently, there were ways to use this to make one URL look like the URL
of another site. According to Microsoft, it isn't just
'www.microsoft.com@63.49.11.12/foo', but there were other problems involving
being able to completely fool even technically savvy people (that is,
nothing on the screen would reveal the real source of the web page you were
looking at and every visible indicator was spoofable).

	DS



home help back first fref pref prev next nref lref last post