Security Site Forum  

Global Announcements:
03/11/09 November 2009: Staff & Gold Promotions. Click Here
02/11/09 Mastercard processing for Gold now available.
02/11/09 Lurker Clear-out of Grand Proportions (57,148). Click Here

Go Back   Security Site Forum > Off Topic > Chatter Box

Reply
 
Thread Tools Display Modes
HELP me please
Old
  (#1 (permalink))
SSF God
 
iammrxxx's Avatar
 
Status: Offline
Posts: 1,447
Join Date: Feb 2003
Location: New York
HELP me please - 02-04-2004, 02:37 AM

Everytime I copy and paste a password,

(example: "http://bshaw:letitrid:@www.hotglamourgirls.com/members/")

I get a "invalid syntax error;" and "This page cannot be displayed"

I've been at this site for a long time and NEVER had this problem, but EVERY time I try to access a site now, I get the same error.

What is going on?

Thanks for responding.


"the mind cannot live without the body" - Morpheus
   
Reply With Quote
 
Re: HELP me please
Old
  (#2 (permalink))
SSF Silver Member
 
tichy's Avatar
 
Status: Offline
Posts: 837
Join Date: Nov 2002
Re: HELP me please - 02-04-2004, 02:43 AM

Quote:
Originally posted by iammrxxx
Everytime I copy and paste a password,

(example: "http://bshaw:letitrid:@www.hotglamourgirls.com/members/")

I get a "invalid syntax error;" and "This page cannot be displayed"

I've been at this site for a long time and NEVER had this problem, but EVERY time I try to access a site now, I get the same error.

What is going on?

Thanks for responding.
Simple. It should not be http://bshaw:letitrid:@ ... but http://bshaw:letitrid@ ...

It means, the ":" before the "@" is not correct http syntax.
   
Reply With Quote
Here's Why...
Old
  (#3 (permalink))
Super Moderator
 
vettdj's Avatar
 
Status: Offline
Posts: 4,204
Join Date: Dec 2002
Here's Why... - 02-04-2004, 02:46 AM

This was within the latest security update for IE via Microsoft Security Bulletin MS04-004 at the msn website.

Cumulative Security Update for Internet Explorer (832894)
Issued: February 2, 2004
Updated: February 3, 2004
Version Number: 1.1

Summary
Who should read this document: Customers who are using Microsoft® Internet Explorer

This is the part that effect all of us. Basically, Microshaft is trying to get rid of the user:pass in front of our urls;

A vulnerability that involves the incorrect parsing of URLs that contain special characters. When combined with a misuse of the basic authentication feature that has "username:password@" at the beginning of a URL, this vulnerability could result in a misrepresentation of the URL in the address bar of an Internet Explorer window. To exploit this vulnerability, an attacker would have to host a malicious Web site that contained a Web page that had a specially-crafted link. The attacker would then have to persuade a user to click that link. The attacker could also create an HTML e-mail message that had a specially-crafted link, and then persuade the user to view the HTML e-mail message and then click the malicious link. If the user clicked this link, an Internet Explorer window could open with a URL of the attacker's choice in the address bar, but with content from a Web Site of the attacker's choice inside the window. For example, an attacker could create a link that once clicked on by a user would display http://www.tailspintoys.com in the address bar, but actually contained content from another Web Site, such as http://www.wingtiptoys.com. (Note: these web sites are provided as an example only, and both redirect to hxxp://www.microsoft.com.)

Aint that a bitch!

~vettdj
   
Reply With Quote
Old
  (#4 (permalink))
SSF Senior Member
 
mutelabs's Avatar
 
Status: Offline
Posts: 138
Join Date: Nov 2003
Location: AU
02-04-2004, 03:03 AM

yea i only noticed it happening today, does mozilla or opera let u run URL's like IE 'used' to?


SS GOLD FTW!
   
Reply With Quote
Old
  (#5 (permalink))
SSF God
 
iammrxxx's Avatar
 
Status: Offline
Posts: 1,447
Join Date: Feb 2003
Location: New York
02-04-2004, 03:21 AM

tichy, thanks a lot, but that didn't help.

vettdj, does that mean that everyone using IE has this problem now? How do I/we get around this? Do we now have to manually type in each and every userass?

Thanks again.


"the mind cannot live without the body" - Morpheus
   
Reply With Quote
Old
  (#6 (permalink))
Morgoth
 
Morgoth's Avatar
 
Status:
Posts: n/a
02-04-2004, 03:56 AM

Quote:
Originally posted by mutelabs
yea i only noticed it happening today, does mozilla or opera let u run URL's like IE 'used' to?
Yes, These Are Real Browsers Not Like That M$ IE Thing

Quote:
Originally posted by iammrxxx
vettdj, does that mean that everyone using IE has this problem now? How do I/we get around this? Do we now have to manually type in each and every user:pass
Yes, If You Use IE You Have To type in each and every user:pass, Or Copy/Paste
   
Reply With Quote
Old
  (#7 (permalink))
SSF Silver Member
 
The Roots's Avatar
 
Status: Offline
Posts: 1,235
Join Date: Sep 2002
Location: Virginia
02-04-2004, 04:06 AM

damn microsoft, always trying to screw the average joe.

Last edited by The Roots : 02-04-2004 at 04:14 AM.
   
Reply With Quote
Old
  (#8 (permalink))
SSF Senior Member
 
mutelabs's Avatar
 
Status: Offline
Posts: 138
Join Date: Nov 2003
Location: AU
02-04-2004, 04:14 AM

/me re-installs mozilla firebird


SS GOLD FTW!
   
Reply With Quote
Old
  (#9 (permalink))
SSF Active Member
 
Karso's Avatar
 
Status: Offline
Posts: 536
Join Date: Dec 2003
02-04-2004, 04:21 AM

The following are two fixes for the problem. I found both on another passes site.

I don't know if they actually work, so use at your own risk!



a) If you want to render a relatively easy fix if you've already installed the update:

To disable the new default behavior in Windows Explorer and Internet Explorer, create iexplore.exe and explorer.exe DWORD values in one of the following registry keys and set their value data to 0:

For all users:
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME
_PASSWORD_DISABLE

For the current user only:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME
_PASSWORD_DISABLE


b) ...I don't know guys but for me messing with the Registry is like messing with somebody's brain, you mess it up and you are dead....so, I did some brainstorming and this program fixed the problem....If you have Windows XP(the most affected) and have already installed the latest windows auto-update....Go to Start, Accessories, System tools and press on "SYSTEM RESTORE" (this program does magic!!!)...keeping in mind that the auto-update was released on 2/2/04, restore your system back a couple days at least, and hit OK.....once your system gets rebooted, the computer will actually behave as it never downloaded the Windows auto-update patch.....YOU ARE SET!!!!....the funny thing is that after a few minutes the auto-update screen will pop up and ask you to install the update that you installed on 2/2/04....just avoid it as much as you can(try me in 3 days!) until some computer geek comes with a patch that fix the nagging "invalid syntax error"......as for concerns on security issues, well guys, nothing comes free in life.....as long as you have a firewall protector (Zone Alarm)and keep a low profile online, you should not be worryng about being hacked....Of course, with all kind of shit happening online, all updates from MS should be taken seriously, so it is your choice...Hopefully, someone will come up with a fix....GOOD LUCK
   
Reply With Quote
Old
  (#10 (permalink))
Super Moderator
 
vettdj's Avatar
 
Status: Offline
Posts: 4,204
Join Date: Dec 2002
02-04-2004, 04:23 AM

Now we just have to hope and pray that mozilla & the others don't follow microcrap's lead on this. I'll keep a watch on this one for sure.

In any case, I would bet that this problem is going to be coming up as a "help me" on every board in the world for a while. We might want to make a sticky for our people here.

Especially with the great fix that Karso just posted above. Nice job Karso!!!

Last edited by vettdj : 02-04-2004 at 04:25 AM.
   
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Powered by vBulletin® Version 3.6.8 PL2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

. XXX adult password pass board forum

Page generated in 0.09550691 seconds (79.75% PHP - 20.25% MySQL) with 15 queries