Full Disclosure mailing list archives

Re: Interesting side effect of the new IE patch


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Fri, 06 Feb 2004 17:01:21 +1300

Stefan Esser <s.esser () e-matters de> wrote:

Of course they are not happy now. Like a lot of other people who relied
on this standard. It is really sad, that Microsoft removes features
because they are to lazy to think up other solutions. Like showing
the username, password in a different color, not showing it at all...
It is one thing to remove a feature because it is like writing the
password to the back of your keyboard but it is another thing to 
just remove it because you have no clue how to make it obvious for
people that this is not part of the servername. 
<<snip>>

Hmmmmm, a security researcher employed by a web development company 
advocating the use of non-standards compliant features that have 
obvious security concerns...

How odd!


Regards,

Nick FitzGerald

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: