[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] Interesting side effect of the new IE patch
- To: full-disclosure@lists.netsys.com
- Subject: Re: [Full-Disclosure] Interesting side effect of the new IE patch
- From: Nick FitzGerald <nick@virus-l.demon.co.uk>
- Date: Thu, 05 Feb 2004 15:46:51 +1300
"Kevin Gerry" <gui@goddessmoon.org> wrote:
> Actually- there is a registry key you can put in to change back to the
> 'correct' user:pass@host way of processing... So it DOES still have that
> in
> there to follow RFC- Just needs to be activated first.
Actually, this is not and never was, RFC-compliant _for HTTP[S] URLs_.
Please read the relevant RFCs to see your assertion that accepting/
parsing HTTP[S] URLs including "userinfo" data is "correct" is, in
fact, badly mistaken.
> (It's in a newer KB article.)
And the correct syntax of HTTP[S] URLs is in older _and_ newer RFCs...
Regards,
Nick FitzGerald
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html