Microsoft to Change IE Behavior to Block Spoofing Attacks

Microsoft to Change IE Behavior to Block Spoofing Attacks

Written By
Larry Seltzer
Larry Seltzer
Jan 29, 2004
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft Corp. has announced in a support document that it will be releasing a software update to Internet Explorer and Windows Explorer to disable the use of certain syntax in HTTP URLs. The syntax, designed to allow a username and password to be passed to a password-protected page, has a history of abuse. The company did not give a timeline for the release of the patch.

The syntax takes the form http[s]://username:password@server/file.html, such as http://joe:blow@www.microsoft.com/, where “joe” is the username and “blow” is the password. But a site that does not look for the username and password will ignore the values passed, and only the string after the “@” symbol is used for the domain name. Other browsers support this syntax to varying degrees.

Because the values before “@” are ignored, attackers have often attempted to use them to confuse users into believing that they are going to a different site than they are actually visiting. For example, the URL http://www.microsoft.com%2F@10.11.12.13/ might appear to be going to www.microsoft.com, but it is actually going to the IP address 10.11.12.13.

The problem was compounded by the recent discovery of a display bug in Internet Explorer that stops the browser from displaying parts of the URL. This allows an attacker utilizing both techniques to display only the legitimate looking portion of the URL to the user.

Microsoft took some time deciding how to address the problem, but on Tuesday released the support document. After installing the patch, Internet Explorer will react to the syntax with a Web page containing the following error message: “Invalid syntax error.”

A registry entry will be available for users to re-enable the feature, or to enable it in third-party software that uses the IE Web browser control.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.