[4839] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Cleartext Password display in NS Communicator

daemon@ATHENA.MIT.EDU (Holger Kanzog)
Wed Jul 2 15:16:28 1997

Date: 	Wed, 2 Jul 1997 19:55:52 +0200
Reply-To: Holger Kanzog <holger@TLNET.DE>
From: Holger Kanzog <holger@TLNET.DE>
X-To:         Fred Albrecht <fred@DOTCOM.FR>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <Pine.LNX.3.95.970702172059.14266B-100000@homefree.dotcom.fr>

On Wed, 2 Jul 1997, Fred Albrecht wrote:

> The following has been tested with Netscape Communicator 4.0 on NT 4 =
and
> 4.0b4 on Linux with the same results :

[..]

> The password is now plainly visible in the URL field :
>     =AB ftp://user:passwd@host =BB

Appendix to my previous message:

It happens only when connecting over proxy Squid (1.1.10) and it appear=
s
also in Squid's access.log.

Holger

PGP-public-key : http://www.tlnet.de/holger.asc
PGP-fingerprint: 2A AE 66 7B 25 C6 0E 21  5A C5 42 E4 A0 53 59 DD

home help back first fref pref prev next nref lref last post