[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 03-26-2004, 09:46 AM   #1
gwilks98
Vice Admiral
 
gwilks98's Avatar
 
Join Date: Aug 2000
Location: StL
Posts: 4,300
Send a message via AIM to gwilks98
Hi Hi I just noticed a bug in IE

Conditions that need to be met:
[list=1][*]Status bar is turned on.[*]You log on to an FTP site using IE.[*]You double click on a file inside the FTP site (like a word doc.) in an attempt to open it.[*]Internet Options for IE is set to prompt you to decide if you want to open or save the file you just clicked on.[/list=1]

Once you get the prompt, check out your status bar and it'll have the cached username and password cached into a web address.

Ftp://username:password@ftp.site.com/folder/file1.doc is how it'll look.

If your FTP site users are using the same log in credentials as your domain, I could see how this could compromise your network. Good ol' Microsoft<sigh>


<waits for post from ribitch>
__________________
"I know the pieces fit, cause I watched them fall away."

"Cold silence has
A tendancy to
Atrophy any
Sense of compassion."

MJK
gwilks98 is offline   Reply With Quote
Old 03-26-2004, 10:23 PM   #2
bachviet
What's Da Pho*?
 
bachviet's Avatar
 
Join Date: Aug 2001
Location: SoCal (714)
Posts: 13,296
Send a message via ICQ to bachviet Send a message via AIM to bachviet
IE??? What is that? J/K
__________________
Dell Dimension 9200 | Intel Core 2 Quad Q6600 (2.4GHz) | 4x1GB DDR2 | 256MB nVidia GeForce 8800GT

Dell Studio 17 | Intel Core i7-720QM (1.6GHz) | 2x2GB DDR3 1066MHz | 1GHz ATI Mobility Radeon HD 4650

Intel P4-C 3.0GHz | ECS 865PE-A | 3x512MB PC3200 | 128MB PNY GeForce 6600GT

bachviet is offline   Reply With Quote
Old 04-01-2004, 06:31 AM   #3
Joshua
Rear Admiral Upper Half
 
Joshua's Avatar
 
Join Date: Jan 2001
Location: Long Island, NY
Posts: 3,390
Send a message via AIM to Joshua
Actually, I don't believe thats a bug. FTP always passes your logon credentials in clear text. FTP itself it insecure. If you're that concerned about it, I'd recommend SFTP or another secure version. When you want to get to any password protected ftp site, that is the syntax you'd use.

Alternatively, you can use an ftp client like Cute FTP so that it would be separate from IE.
__________________
The Apexer formerly known as SnotRocket.

"Like I ****ing said, "Ok, so I hear it may be a repost. Blah But I had never seen it, so..." **** you Canta." -Jenny 12/4/2003
Joshua is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 03:25 PM.