lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: lists at onryou.com (Cael Abal)
Subject: Microsoft's fix for URL containing username:password@
 obfuscation

Zach Forsyth wrote:
> And for people saying don't use IE, if you aren't the sole admin on the
> server you don't have the choice to install other apps.
> Believe me if I could install something else I would just put a real ftp
> app and firebird on there and not have to ask silly questions on FD.

Please tell me you don't do a lot of web browsing from your server.

IE being required on a Windows server (for SUS management, etc.) is 
one of my pet peeves -- but folks who browse the internet from their 
server actively freak me out.

(This isn't directed specifically at you, Zach, but to people who 
play Russian roulette logged in as a domain admin.)

C


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ