CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Security HeadLines: Microsoft to Strike Passwords from URLs in IE image
Microsoft

Microsoft to Strike Passwords from URLs in IE

By David Worthington, BetaNews January 29th, 2004, 5:23 AM

Due in large part to December's highly publicized URL spoof attacks, Microsoft intends to release a patch for Internet Explorer that will modify the way the browser handles user credentials.

According to a recent knowledge base article, support for user names and passwords will now be stricken from URLs.

This modification is based upon the findings of Demark based security firm Secunia, which on Wednesday released another advisory revealing additional spoofing vulnerabilities in IE. The latest advisory warns that a spoofing attack could potentially obfuscate the extensions of downloaded files by embedding a CLSID in the file name. Users would in turn not know the true file type of the content they are downloading.

Specifically to address issues such as these, the patch from Microsoft will disallow the format "username:password@host.com" from being used to pass credentials in HTTP and HTTPS URLs. This format allowed hackers to spoof legitimate domain names by way of specially crafted URLs intended to facilitate convincing "phishing" schemes, or even cross site scripting attacks.
Source: BetaNews
Posted on Thursday, 29 January 2004 @ 09:27:56 UTC by cj (1132 reads)
[ Trackback ]
image

"Security HeadLines: Microsoft to Strike Passwords from URLs in IE" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· News.com
· PHP HomePage
· Microsoft
· HotScripts
· W3 Consortium
· Google Microsoft Search
· Microsoft
· Technet Online
· HotFix & Security Bulletins
· More about Microsoft
· News by cj


Most read story about Microsoft:
Microsoft Security Bulletin MS06-001: Official WMF Patch

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer