ie spoofing vulnerability

|

There is a new kb article about ie address spoofing. KB834489, which details how MS are going to address the address bar spoofing that hit the headlines several months ago and which I demonstrated here. Basically they are fixing it by disabling internet explorer from accepting urls in the format of http://username:password@domain This sounds like its breaking the WWW agreed format for urls and could stop bookmarks (and other applications?) from storing usernames/passwords etc. I'm not convinced this is a good workaround as it means some urls will work in mozilla, opera etc but not in ie. Will be interesting to see if this also breaks ie wrappers such as Myie.

Categories

Pages

Powered by Movable Type 4.1

About this Entry

This page contains a single entry by published on January 29, 2004 11:45 AM.

Mail servers. was the previous entry in this blog.

Microsoft Virtual PC installation kills entire lan. is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.