The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft to Remove Support for Usernames in http urls
Time: 13:47 EST/18:47 GMT | News Source: Netcraft | Posted By: Robert Stein

A forthcoming update to Internet Explorer will disallow the use of the "@" character in URLs, addressing an issue which has helped fraudsters to obscure the true destination in a web site addresses. Once the update is installed, including the @ symbol in urls will return an "invalid syntax error" message. Microsoft's advisory did not say when the update would be available.

Write Comment
Return to News

  Displaying 1 through 25 of 315
Last | Next
  The time now is 4:28:53 PM ET.
Any comment problems? E-mail us
#1 By 2960 (156.80.64.137) at 1/28/2004 3:09:53 PM
Hmmm... Might this not affect online storage ?

I'm a little fuzzy on the buzzwords I need to use here, but I remember logging on to certain online storage sites that used authentication in the url.

TL

#2 By 61 (24.92.223.138) at 1/28/2004 3:45:12 PM
Yeah, I really don't like this.

#3 By 6859 (206.156.242.36) at 1/28/2004 4:40:47 PM
bad move. Me no likey.

Let me clarify: I don't like that they're removing the behavior for a URL but not leaving it in for FTP. FTP has legit uses of this, URLs don't.

This post was edited by Cthulhu on Wednesday, January 28, 2004 at 17:16.

#4 By 135 (208.186.90.168) at 1/28/2004 5:58:33 PM
How does the @ symbol obscure the website?

#5 By 2459 (24.175.137.164) at 1/28/2004 6:47:10 PM
#5 It doesn't if you know what you're looking for, but most users don't.

http://www.cnn.com%01@www.activewin.com

Takes you to activewin's page. The average user would think it took them to cnn. Usually, spoofers make pages that look like the page you think you're going to and include the link in an email, etc. You think you're on the legit site instead of the spoofed site, so you may be inclined to give personal out info, etc.

This post was edited by n4cer on Wednesday, January 28, 2004 at 19:01.

#6 By 12071 (203.185.215.149) at 1/28/2004 6:53:24 PM
#4 ALL (read: every single) URL has a legitimate reason for having the '@' symbol in it, that's the way URL's were designed, and here's Microsoft coming through again to screw up another standard! Rather than fixing the actual problem their solution is to remove the '@' symbol altogether, morons!

ftp://user:password@ftp.microsoft.com is just as valid as
http://user:password@www.microsoft.com

and there are some (although not many) websites that are protected (i.e. access limited) in this exact way.

#7 By 116 (24.173.215.234) at 1/28/2004 7:08:17 PM
Thats until you see something like this:

http://www.bankofamerica.com?ajdkajfkl&query=&asdfasdf&asdfasdf@www.evilhackerwebsite.com/stealcreditcardnumber/

Most people are used to seeing websites with a lot of gobbeldy gook in the address bar. They ignore this content and never read it.

Yeah the @ is a part of the standard but in the interest of protecting people's safety online this is the correct solution.

FTP is the same deal, you could trick someone using the same device. The only solution I can see is changing the username and password to go at the end.

#8 By 2459 (24.175.137.164) at 1/28/2004 7:13:13 PM
BTW, I think this issue may be fixed in SP2. Unless I missed something, I can still see the full URL in the status bar.

#9 By 3339 (64.160.58.135) at 1/28/2004 8:39:54 PM
This comment has been removed due to a violation of the Active Network Terms of Use.

#10 By 12071 (203.185.215.149) at 1/28/2004 10:00:29 PM
#9 Nope, that URL that you gave is perfectly fine. You stuffed up by putting '?' before the '@' which is not allowed by the standard. If you would like to see the standard have a look here:
http://www.w3.org/Addressing/rfc1738.txt

"Yeah the @ is a part of the standard but in the interest of protecting people's safety online this is the correct solution. "
No this is a moronic solution which breaks the standard. There would be numerous ways of handling this (ie letting the user know what's going on) without breaking the standard. This isn't the correct solution, this is the lazy solution. And you honestly wonder why people complain about Microsoft continually breaking standards!

#11 "The standard also used to be that you could mail any attachment and recieve any attachment in Outlook and Outlook Express."
The STANDARD is that you CAN email and receive any attachment in ANY email application that adheres to the standard! The standard DOES NOT state that the attachment should be automatically executed including any scripts etc, THAT was Microsoft own ingenious idea which has come back to bite them on the arse!

"Microsoft was right to change that for the safety of its less educated users."
Microsoft didn't change the standard!!! They just changed their own little ingenious idea of automatically executing attachments and put a ban on "dangerous" filetypes incase the user might want to double click on the attachment!

"It is right to change this standard."
No it is not. Fix the problem rather than modifying the standard!

"Switch to a less secure browser if you want to."
Nothing is LESS secure than IE!

Latest IE Bug:
http://www.infoworld.com/article/04/01/28/HNiehole_1.html
http://www.secunia.com/advisories/10736/

I can just imagine the patch for this - No file downloads will be allowed from web pages. After all, we have to do everything possible to protect people's safety!

#14 "And remember, it is mostly Unix mail servers transporting all the viruses throughout the internet."
Prove it! All the latest 'viruses' have all targeted Exchange Servers and Outlook users!

"I think Microsofts solution is an excellent solution."
There's a suprise!

This post was edited by chris_kabuki on Wednesday, January 28, 2004 at 22:29.

#11 By 12071 (203.185.215.149) at 1/28/2004 10:28:49 PM
#16 You are absolutely correct. It seems that everyone has been using the common syntax rather than the individual rules depending on the scheme selected:

While the syntax for the rest of the URL may vary depending on the
particular scheme selected, URL schemes that involve the direct use
of an IP-based protocol to a specified host on the Internet use a
common syntax for the scheme-specific data:

//<user>:<password>@<host>:<port>/<url-path>

Some or all of the parts "<user>:<password>@", ":<password>",
":<port>", and "/<url-path>" may be excluded. The scheme specific
data start with a double slash "//" to indicate that it complies with
the common Internet scheme syntax.

#12 By 3653 (209.149.57.116) at 1/29/2004 12:06:36 AM
http://kabuki:suck@egg.com/

#13 By 12071 (203.185.215.149) at 1/29/2004 12:29:40 AM
#18 Guess we both learnt something after all then =)

#19 No I don't want to transfer my store card balances to Egg Card, even if they are offering 0% until 1st of July, but thanks anyway.

#14 By 3339 (64.160.58.135) at 1/29/2004 3:14:51 PM
"There is no evidence the viruses have targetted exchange. They are just standard email with attachments."

Hilarious! Standard emails with attachments designed to harvest contact info from Exchange. Standard emails with attachments which do not affect Sendmail or other email servers or apps. Standard emails with attachments that only affect MS's systems.

But they don't target exchange.

#15 By 4240821 (213.139.195.162) at 10/26/2023 10:36:57 AM
https://sexonly.top/get/b236/b236uqrqmssttfguhbt.php
https://sexonly.top/get/b856/b856wrywiktcsghrqhx.php
https://sexonly.top/get/b562/b562tewwmlvjcuinubt.php
https://sexonly.top/get/b421/b421holulpymyixjtze.php
https://sexonly.top/get/b407/b407djheeeqcwctyzqk.php
https://sexonly.top/get/b340/b340hhndzvnoygbtevg.php
https://sexonly.top/get/b137/b137gvetaewcdrvoqll.php
https://sexonly.top/get/b362/b362oogjlqbaeejjodx.php
https://sexonly.top/get/b272/b272yydunqeneffyxpg.php
https://sexonly.top/get/b791/b791jjweeapfewfiafz.php
https://sexonly.top/get/b193/b193rxftygejvnwikdj.php
https://sexonly.top/get/b118/b118nndauqxulssrglb.php
https://sexonly.top/get/b478/b478iqpcjrlukkgcvzh.php
https://sexonly.top/get/b750/b750ybkysjpngrsjlfv.php
https://sexonly.top/get/b291/b291wqnnmvfbmdsnkyb.php
https://sexonly.top/get/b190/b190krnsuprkowqocop.php
https://sexonly.top/get/b676/b676zilqbjeehkukdzy.php
https://sexonly.top/get/b224/b224lhmgxsulmzhyfev.php
https://sexonly.top/get/b326/b326khkyfhspsvrgufz.php
https://sexonly.top/get/b911/b911pugdipuhsvfkgpp.php
https://sexonly.top/get/b642/b642ibokgrtjrrajhiz.php
https://sexonly.top/get/b119/b119qynqhoxntwnevbo.php
https://sexonly.top/get/b339/b339rbcexlhdjtgfjxs.php
https://sexonly.top/get/b780/b780prwwhclfiebntxo.php
https://sexonly.top/get/b377/b377tcgqsfmmmracidh.php
https://sexonly.top/get/b389/b389dmsagceruljuhhx.php
https://sexonly.top/get/b419/b419hbheewkroswuumt.php
https://sexonly.top/get/b493/b493rxgpmxuwccpquum.php
https://sexonly.top/get/b646/b646qoreihbjhtdipto.php
https://sexonly.top/get/b717/b717gnujvryadecuomi.php
https://sexonly.top/get/b746/b746qvzemwqznkffmkq.php
https://sexonly.top/get/b249/b249iandggbtppotosd.php
https://sexonly.top/get/b831/b831wgblufhnlgypjff.php
https://sexonly.top/get/b86/b86ifnrdjjoqnfvntk.php
https://sexonly.top/get/b544/b544auvevysxzkxvuky.php
https://sexonly.top/get/b690/b690quenhobjnntgavq.php
https://sexonly.top/get/b373/b373zdapermlqpznymr.php
https://sexonly.top/get/b208/b208uangxjyruiywjbw.php
https://sexonly.top/get/b806/b806yvltmfwfycvbbtx.php
https://sexonly.top/get/b775/b775emhnxbxzmkzwnfj.php
https://sexonly.top/get/b422/b422gsofsdekpumbqei.php
https://sexonly.top/get/b101/b101unxhaziepodltwq.php
https://sexonly.top/get/b540/b540dsmwlmxityybpex.php
https://sexonly.top/get/b163/b163jcysmkjvrcviryd.php
https://sexonly.top/get/b438/b438myanlgqrsjjrbtl.php
https://sexonly.top/get/b353/b353bvacdssrvobssbi.php
https://sexonly.top/get/b186/b186veruxevxqeultgo.php
https://sexonly.top/get/b927/b927dpfslgxiofdbiku.php
https://sexonly.top/get/b715/b715zblkkypixotlhjp.php
https://sexonly.top/get/b19/b19joiidkkqzrnagop.php

#16 By 4240821 (103.151.103.150) at 10/30/2023 10:18:24 AM
https://www.quora.com/profile/StaceyRud310/himiwako-1-catiravenezolana-Jailyne-Ramirez-xxsaucii-Tsimshianqueen-PamelaMorrison-Veetzo-leolinkass-Van
https://www.quora.com/profile/JeremyMolina696/kcatxxo-Thelovewitch-katiebrunette-Jsebel10000-Southern-Gem-Denise-and-Mike-SleepyOmega-sandycandyhot-Es
https://www.quora.com/profile/SarahCordova917/lilfairythot-Kaci-Star-Sexymomma13-KeilanAndLuke-avvaballerina-raveaphrodite-AmeliaIvory-Lilly-Tracy-Ali
https://www.quora.com/profile/JohnMurillo91/luscious-lopez-Unicorn-Phoenix-Lola-Fae-NalaHayes-SherriGlaseme-Leah-Lust-ForeverTight-Morangoolett-rach
https://www.quora.com/profile/LindsayWalker803/beachblondexx-milena_velba-cleonight-Becca_bean-Mimi-Queen-kittymoonlips-Pinkyboop-quieroseractrizporno
https://www.quora.com/profile/JoshSquires331/daddysgokeygirl-Summer0169-itsme_shenzy-ElectraScorpio-Molly_Moon-lengcasso-LexaMarie77-Miss_Almira-Jess
https://www.quora.com/profile/MikeRajput208/kushlungs666-Haileyy33-CelenSnow-Redfurry69-cutiekisa-Chloe-rosse-Layla-Waters-Cardilovespizza-bella-sia
https://www.quora.com/profile/JohnGonzalez193/Mimi5569-Cocoa-Butta-yellowpants99-Luvly_Lola-blue_siren-PrismRider-Meagan-Amelia-ariana-faye-GreedyPeac
https://www.quora.com/profile/TashaSmith611/NaughtyHeAndShe-Lacey-Mace-RealSquirtCum-PhatAssLynn-JinkiesMoore-hairpinlegskass-lavender-rayne-Cocomilf0
https://www.quora.com/profile/NancyJimenez480/MinaValentina97-Gordie-Mojada-calistaxdoll-pock3tpuppy-SexualSuccubus-KositasRicas66-fox_ruiva-LunaHot2000

#17 By 4240821 (103.152.17.80) at 10/31/2023 3:12:49 AM
https://app.socie.com.br/read-blog/97249
https://app.socie.com.br/Silenthillnerdemerald6985
https://app.socie.com.br/read-blog/98150
https://app.socie.com.br/read-blog/98236
https://app.socie.com.br/thejosiejonesaspiritualslut
https://app.socie.com.br/read-blog/97521
https://app.socie.com.br/read-blog/97211
https://app.socie.com.br/read-blog/97218
https://app.socie.com.br/CassandraMayLittleNatBrat
https://app.socie.com.br/Pixelkitt3nbrookebliss

#18 By 4240821 (103.151.103.150) at 10/31/2023 6:07:16 PM
https://app.socie.com.br/LadyDiamondkatthekunttt
https://app.socie.com.br/wildwestfemrubyscharm
https://app.socie.com.br/read-blog/97255
https://app.socie.com.br/read-blog/98918
https://app.socie.com.br/StonerShelleyKAH20199
https://app.socie.com.br/ThiccBrat420BBWTattooedBailey
https://app.socie.com.br/read-blog/97460
https://app.socie.com.br/read-blog/97666
https://app.socie.com.br/read-blog/98292
https://app.socie.com.br/read-blog/97714

#19 By 4240821 (62.76.146.75) at 11/1/2023 6:29:49 AM
http://activewin.com/mac/comments.asp?ThreadIndex=5875&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21865&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=9028&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61906&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85415&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=4454&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74081&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=8856&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85295&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=24060&Group=Last

#20 By 4240821 (109.94.218.82) at 11/2/2023 5:52:49 PM
http://activewin.com/mac/comments.asp?ThreadIndex=26877&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=29477&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=86164&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=66977&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=38352&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84894&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=9876&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2220&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28705&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=6363&Group=Last

#21 By 4240821 (212.193.138.10) at 11/3/2023 5:49:14 PM
http://activewin.com/mac/comments.asp?ThreadIndex=5016&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=44359&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=10482&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=11097&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=24468&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=20729&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=19128&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=65074&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=16898&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23768&Group=Last

#22 By 4240821 (109.94.216.41) at 11/5/2023 3:59:51 AM
https://hotslutss.bdsmlr.com/post/652385948
https://hotslutss.bdsmlr.com/post/652946598
https://hotslutss.bdsmlr.com/post/659915980
https://hotslutss.bdsmlr.com/post/658896087
https://hotslutss.bdsmlr.com/post/660701040
https://hotslutss.bdsmlr.com/post/649718538
https://hotslutss.bdsmlr.com/post/657471895
https://hotslutss.bdsmlr.com/post/655532410
https://hotslutss.bdsmlr.com/post/657730245
https://hotslutss.bdsmlr.com/post/649055219

#23 By 4240821 (92.119.163.194) at 11/6/2023 3:32:40 AM
https://printable-calendar.mn.co/members/19901784
https://printable-calendar.mn.co/members/19912371
https://printable-calendar.mn.co/members/19913394
https://printable-calendar.mn.co/members/19910601
https://printable-calendar.mn.co/members/19910326
https://printable-calendar.mn.co/members/19909291
https://printable-calendar.mn.co/members/19916196
https://printable-calendar.mn.co/members/19907865
https://printable-calendar.mn.co/members/19913626
https://printable-calendar.mn.co/members/19915292

#24 By 4240821 (62.76.146.75) at 11/8/2023 6:14:33 AM
https://www.hackerearth.com/@vlamacjoma1989
https://www.hackerearth.com/@wingmatofca1986
https://www.hackerearth.com/@bagilotec1973
https://www.hackerearth.com/@olsiweeca1977
https://www.hackerearth.com/@techchildreve1989
https://www.hackerearth.com/@sonkeysoftcold1976
https://www.hackerearth.com/@storheinendu1973
https://www.hackerearth.com/@consrdigringnoord1975
https://www.hackerearth.com/@dreamounoson1984
https://www.hackerearth.com/@ninicbergchi1984

#25 By 4240821 (45.146.26.215) at 11/10/2023 11:17:25 AM
http://www.ttbizonline.com/pro/20231109153811
http://www.ttbizonline.com/pro/20231109190255
http://www.ttbizonline.com/pro/20231110014654
http://www.ttbizonline.com/pro/20231109143620
http://www.ttbizonline.com/pro/20231109141236
http://www.ttbizonline.com/pro/20231109074029
http://www.ttbizonline.com/pro/20231109172259
http://www.ttbizonline.com/pro/20231109110802
http://www.ttbizonline.com/pro/20231109073114
http://www.ttbizonline.com/pro/20231110005810

Write Comment
Return to News
  Displaying 1 through 25 of 315
Last | Next
  The time now is 4:28:53 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *