Mistype a URL? M$N knows what you typed.

From: Darren Reed (avalon@coombs.anu.edu.au)
Date: 03/06/02


From: Darren Reed <avalon@coombs.anu.edu.au>
To: bugtraq@securityfocus.com
Date: Wed, 6 Mar 2002 11:42:02 +1100 (Australia/ACT)


If you've ever used IE and typed in "ww.foo.com" into the path, you
will end up at a web page generated by an MSN web site. How did I
get this, you ask? Well, you definately cannot find anything in the
"Internet Options" panels which lets you configure this. If you
fire up regedit, under

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search

you will find "CustomizeSearch" and "SearchAssistant". Unless you
want all of the URLs which fail to resolve in domain names to be
handed off to MSN. Furthermore, there are cookies involved with
these web sites. These "helpers" appear to only be used when there
are no proxies enabled but it would be a nice if there was an easier
way to stop Microsoft knowing every bad URL that gets typed, etc,
by those with no proxy.

FWIW, for me CustomizeSearch defaults to:
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
and SearchAssistant to:
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

Darren



Relevant Pages

  • Cannot access to MSN Explorer web to sign up
    ... I upgraded my PC from Window 98 to PX, ... to MSN web site to sign up. ... After dial connection to MSN ... the web site does not show up. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: How do we get there from here?
    ... I can't tell you how often I try to do something on a web site and finally ... figure out I have cookies turned off...then have to open up my browser to ... Will it contain tokens that will be replaced by ... >>> both tokenized, so the content in them is session driven by cookies, ...
    (comp.databases.pick)
  • [NEWS] Datalex BookIt! Consumer Password Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Datalex PLC's BookIt! ... Storing authentication credentials in cookies is never a good idea as ...
    (Securiteam)
  • Re: How do we get there from here?
    ... > figure out I have cookies turned off...then have to open up my browser to ... If 10% of the potential shoppers can't view the web site at all, ... CSS is currently tested only under IE6 and the latest FF: ...
    (comp.databases.pick)
  • RE: IE6 Privacy and Secure Web Site
    ... all cookies from a specific web site or domain, ... to authorize cookies from that secure web site, ... > prompted for logon and password. ...
    (Focus-Microsoft)

Loading