Enjoy Every Sandwich

Thoughts on SQL, XML, .NET and sometimes beer.

<November 2008>
SuMoTuWeThFrSa
2627282930311
2345678
9101112131415
16171819202122
23242526272829
30123456


Navigation

Tools

List O'Links

Kent's Other Stuff

Subscriptions

News

Please read these
Notices and Disclamiers

Post Categories

Article Categories



KB834489 vs. KB135975: Fix FTP too!

With KB834489, I can not longer use HTTP URLs with embedded credentials to IE5 and IE6. That's great -- good fix.

With KB135975, I can still use FTP URLs with embedded credentials to IE2 and IE6. That's not so good.

I can understand why this was fixed for HTTP/HTTPS. Its a gaping security issue there. But, limiting this just the HTTP/HTTPS protocol is -- at best -- a partial solution. FTP is just as vulnerable and sometimes is even more valuable. Volume of exploit shouldn't matter.

posted on Monday, August 23, 2004 6:49 AM by ktegels





Powered by Dot Net Junkies, by Telligent Systems