Re: [Full-Disclosure] Interesting side effect of the new IE patch

From: Stefan Esser (s.esser_at_e-matters.de)
Date: 02/06/04

  • Next message: Gregory A. Gilliss: "Re: [Full-Disclosure] [SECURITY] [DSA 435-1] New mpg123 packages fix heap overflow"
    To: Bill Royds <full-disclosure@royds.net>
    Date: Fri, 6 Feb 2004 19:48:47 +0100
    
    

    > Amy browser that allows an HTTP URL with an @ sign in it is buggy and should
    > be fixed.

    Blablabla. Anyone who bought a NTSC tv should give it back, cause it was not
    the standard at the time it was introduced.

    > HTTP URLs are not RFC compliant if the have the user:password@host syntax.

    Yes and? Any car vendor who builds a phone into the car is also adding a
    feature which could compromise the security. Because it the statistic says
    that when you phone while driving you more often produce crashs.
    And correct me if I am wrong, but I do not see "phone" in the official
    definition of a car. So whoever added a phone to his cars first is
    obviously a very very bad guy.

    How is the car example different from HTTP URLs. Microsoft added a
    feature to the HTTP URLs. This is the way they work. They change standards
    into what they like. You may like that or not, but you absolutely CANNOT
    say that a browser that implements this feature is buggy. Because it isnt
    It just has a feature that is not covered by the standard.

    If humans would only be allowed to perform actions which are
    written down in some standard and not "improve" or change the way they act
    we would not have any inventions anymore.

    You may like it or not. It was maybe braindead or not to add this feature.
    BUT you simply cannot call it a bug, because it was implemented into the
    browsers on purpose and not by accident (Well maybe with IE as exception)

    > Microsoft fixed their bug and you are complaining about a bug and
    > vulnerability fix because it removes some exploits.

    Where am I complaining about Microsoft fixing the 0x01 vulnerability?

    > Microsoft finally did the right thing and fixed their browsers. How long do
    > you think it will take for Mozilla and Opera and Safari to change as well?

    Yeah, we will see if the world is full of RFC compliant geeks.

    > The only thing that should be done for legitimate programmed uses of an
    > account and password is to add HTTP headers to the RFC (RFC 2616) to allow
    > Username, authentication type and password.
    >
    > USERNAME:DumbLuser
    > Authentication-type:plainText
    > Password:foolish

    How would that be different from BasicAuth? And I hope your argument is
    not that the password is not transfered in plain text with BasicAuth...

    Stefan

    -- 
    --------------------------------------------------------------------------
     Stefan Esser                                        s.esser@e-matters.de
     e-matters Security                         http://security.e-matters.de/
     GPG-Key                gpg --keyserver pgp.mit.edu --recv-key 0xCF6CAE69 
     Key fingerprint       B418 B290 ACC0 C8E5 8292  8B72 D6B0 7704 CF6C AE69
    --------------------------------------------------------------------------
     Did I help you? Consider a gift:            http://wishlist.suspekt.org/
    --------------------------------------------------------------------------
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Gregory A. Gilliss: "Re: [Full-Disclosure] [SECURITY] [DSA 435-1] New mpg123 packages fix heap overflow"

    Relevant Pages

    • Re: Wanted: talented programmers
      ... whether any particular feature is provided by the ... browser or by a plug-in. ... When I were a lad anyone with a smidgen of technical sense ... And most car owners probably do not want to know too much ...
      (comp.sys.acorn.misc)
    • Feature detection vs browser detection
      ... could improve the application by detecting the browser vendor/version. ... detection, and some couldn't. ... I fully understand that object detection and feature tests are to be ... We went with the event handlers, ...
      (comp.lang.javascript)
    • Re: SP2 ... just a thought to ponder ........
      ... It certainly was the case when Netscape was charging for their browser which is prolly the main reason IE overtook Netscape as the browser of choice. ... MS has always known about weak safety spots in their system (just today MS made public that ... you bought a car with electrical windows ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress.stationery)
    • Re: OT: Internet Portals
      ... because it is so popular. ... A small feature for one user might be the prime purpose for another. ... most important feature of a browser. ... the "majority" of the users, this is in fact the single most important ...
      (rec.sport.golf)
    • Re: Computed shortcut styles
      ... When I refer to feature detection as "purist" I mean that it's closer ... So I wouldn't say sniffing is purist at all. ... browsers would get fixed as currently get fixed with a simple browser ...
      (comp.lang.javascript)