* Microsoft disables the use of '@' in URLs If you think about Microsoft’s Internet Explorer browser in evolutionary terms it has morphed at a rate that would make Darwin’s head spin. So in the never-ending whirl that is the browser’s feature set, Microsoft has decided to lose a feature – it is removing support for user logons in http URLs. A URL-based user logon looks like this: http://mark:webapps@www.gibbs.comThis URL form invokes the Web server’s basic authentication system to provide access to the use “mark” with the password “webapps” on the server www.gibbs.com.But a forthcoming IE update (see links below) will disallow the use of the “@” character in URLs because crooks can use it “@” to obscure the true URL of a Web site.This is how the scam works: Crooks would put an “@” sign in the URL to make it look real. And the reason it looked real was because the text to the left of the “@” was the name of the site to which a naïve victim would expect to go while the text to the right is the location of the crook’s site. For example: http://www.gibbs.com@somename.com/. While this was a reasonable scheme in the early days of the Internet the inherent lack of security made it unacceptable once the ‘Net was commercialized.And of course, there’s also a bug in IE (I know, I know, you’re shocked) that crooks have also been able to exploit. This bug allows a URL with the “%01” character in it to make IE display an incorrect URL in its address and status bars. Thus: http://www.gibbs.com%01@somename.com/. The bug would cause IE to display http://www.gibbs.com in the address and status bars even though the link would really take the browser to http://somename.com.Combine the feature with the bug and add a plausible pitch as if it came from a branded company and “phishing” expeditions become very simple.When you install the update any URL with a “@” symbol will create an “invalid syntax error” message when clicked. Despite what you may have read elsewhere, Microsoft does not offer alternate methods of automating user logons. The advisory suggests:“If users typically type HTTP or HTTPS URLs that include user information in the Address bar, or click links that include user information in HTTP or HTTPS URLs, you can work around this new functionality in Internet Explorer in two ways:1. Do not include user information in HTTP or HTTPS URLs.2. Instruct users not to include their user information when they type HTTP or HTTPS URLs. “If the Web site uses the basic authentication method, Internet Explorer automatically prompts users for a user name and a password. In some cases, users can click the Remember my password box in the dialog box to save their credentials for later visits to that Web site.”Terrific! The advisory does however discuss more useful workarounds for application and Web site developers.While the advisory makes it sound as if this update is available let me know if you can find it anywhere because I’ve been looking since Jan. 2, and from what I can see it has yet to be released. Related content news Broadcom to lay off over 1,200 VMware employees as deal closes The closing of VMware’s $69 billion acquisition by Broadcom will lead to layoffs, with 1,267 VMware workers set to lose their jobs at the start of the new year. By Jon Gold Dec 01, 2023 3 mins Technology Industry Mergers and Acquisitions news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Network Management Software Network Management Software news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe