The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Microsoft disables user:pass@server causing Invalid Syntax Error

Discussion in 'General Discussion' started by hostultra, Feb 9, 2004.

  1. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    Just a notice to everyone
    Microsoft seems to have disabled the http://user:password@server.com/ thing in the latest patch for internet explorer.

    So if your login forms send your customers to an url like that they will get a invalid syntax error!

    It took me ages to track this problem down.
    Many customers were complaining to me about getting this error and could find no problem.
    Today I updated my own PC with windows update, downloaded the IE service pack patch and i noticed it.
     
  2. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
  3. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    You can shut this off by adding a registry entry.

     
  4. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    LOL, I posted 3 minutes too slow... ;)
     
  5. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    Having customers edit a registry entry to login is not a good solution.

    Is there any other way to redirect the browser into cpanel without asking for user/pass other then this method which doesnt work by default anymore.
     
  6. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Well its a security measure that I don't think the average user should skirt around. But if you wanted to help out your users I guess you could whip up a few registry patches and offer them to your clients. Of course you'll need to make one for each version of windows.

    I don't see a way to "re direct" anyone as there's no page there to add a redirect to.
     
  7. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    No i dont think you understand.
    I dont want my users to have to download a registry patch.
    I want it to work by itself, the way it did before microsoft screwed with it.

    Is there another way to send in the username/password, like a javascript or URL trick other then http://user:pass@
     
  8. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    I understood you the first time. The answer is no.
    Tell them to use https and type in the password every time. We are talking security here. There is no easy way around being safe. (other than editing the registry)
     
  9. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    I have multiple servers with a login on my site.
    The login form redirects them to their cpanel for the appropriate server, without using user:pass@server it means the user will have to enter their username and password twice.
    Once to find which server he is on, and another to login to the cpanel.

    I cant belive microsoft would remove such a useful function just because a few people abused it for spoof sites.
    At least a warning message would be better then disabling it completely.
     
  10. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Your password should never be in plain view of anyone. This is a given.
    Before, when you could login this way, your username and password were viewable on the bottom of your browser. So it's more than just some spoofed URLs.

    Just change the login to a URL to get to the https URL and they can click that and login, it's not that tough..
     
  11. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    I created a work around :

    <img border="0" width="0" height="0" src="http://user:pass@server.com:2082/frontend/x/branding/top_01-sm_bg.gif">
    <script language="JavaScript">self.location.href='http://server.com:2082/';</script>
     
  12. goodmove

    goodmove Well-Known Member

    Joined:
    May 12, 2003
    Messages:
    624
    Likes Received:
    0
    Trophy Points:
    16
    Do you mean https://user-pass@ works with the IE update?
     
  13. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    no it doesnt.
     
  14. TogaDave

    TogaDave Well-Known Member

    Joined:
    Apr 13, 2003
    Messages:
    135
    Likes Received:
    0
    Trophy Points:
    16
    Just got my first customer support ticket about this this morning. Just what I wanted to do today, sit around explaining to users why they get a syntax error when they try to check webmail from within cpanel... the fun never ends LOL!
     
  15. osfdeath

    osfdeath Well-Known Member

    Joined:
    Aug 29, 2003
    Messages:
    144
    Likes Received:
    0
    Trophy Points:
    16


    That does not work - login dialog box still appears
     
  16. casey

    casey Well-Known Member

    Joined:
    Jan 17, 2003
    Messages:
    2,303
    Likes Received:
    0
    Trophy Points:
    36
    Location:
    If there is trouble, it will find me
    It looks like Nick is working on it, too:

     
  17. Dr. Bogger

    Dr. Bogger Well-Known Member

    Joined:
    Dec 21, 2003
    Messages:
    96
    Likes Received:
    0
    Trophy Points:
    6
    Is this feature available yet? if so, how do you make it work? lol.

    I dont know too much about cookies yet lol.
     
  18. XPerties

    XPerties Well-Known Member

    Joined:
    Apr 10, 2003
    Messages:
    401
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    New Jersey, USA
    For those who use https://root:PASSWORD@IP:2083 and have downloaded the latest IE fix from MS you will notice it no longer works. You get an syntax error. Here is the fix to remove the block.


    Copy and paste this into a text file:

    save the text file as:

    Enable username&password in IE.reg

    then click on the file, and choose yes to import it into your registry. This will disable the MS update.
     
  19. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    I think I posted that in the beginning of this thread.. ;)
     
  20. hostultra

    hostultra Well-Known Member

    Joined:
    Aug 21, 2002
    Messages:
    167
    Likes Received:
    0
    Trophy Points:
    16
    The login box will appear on those which have the microsoft patch, but will not appear if they do not have the patch.

    it just avoids the horrible syntax error.
     
Loading...

Share This Page