4 ms·
http://support.microsoft.com/kb/834489 http://support.microsoft.com/kb/834489 I remember reading about Microsoft stopping supporting that option actually. The
by avbor 14y ago
http://support.microsoft.com/kb/834489 http://support.microsoft.com/kb/834489
I remember reading about Microsoft stopping supporting that option actually. The reasoning being that it could be used for sending users to malicious sites.
"malicious users can use this URL syntax together with other methods to create a link to a deceptive (spoofed) Web site that displays the URL to a legitimate Web site in the Status bar, Address bar, and Title bar of all versions of Internet Explorer."
I'm wondering if this was the reasoning for doing so in Chrome.
- deleted 14y ago[deleted]
- Dylan16807 14y agoThat's a ridiculous reason. The most recent version of IE that supports the syntax already hides the username:pass to completely solve this problem. Opera does the same thing. Firefox asks if I want to log in then does the same thing. The pre-change version of chrome I have does the same thing.
- nl 14y agoIt's not a ridiculous reason at all. The phishing attack occures when you look at the URl before clicking on it. http://www.microsoft.com:getwindowsforyourcomputer.etc@evilsite.com/ http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.
- piotrSikora 14y ago...and how is that different from <a href="http://evilsite.com">microsoft.com</a> ?
- sirclueless 14y agoIt looks different in the status bar, which is the important bit.
- piotrSikora 14y agoLike Dylan16807 said - it doesn't. Chrome already hides "user:pass" bits in the status bar.