[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [suse-security] Squid Update ?

André Sänger wrote:
> Tuesday, October 28, 2003, 5:01:22 PM, you wrote:
> > Mozilla 1.4 on Win32 is also able to send NTLM.
> > http://www.mozilla.org/releases/mozilla1.4/README.html#new
> But both Mozilla 1.4 (didn?t try 1.5 yet) and Mozilla Firebird 0.7
> still pop up a password dialog. IE doesn?t.

Open an IE window and display the status bar. The right-most entry
in the bar displays the current zone. Double-Click this zone. Your
computer now displays a property sheet for "Internet Security
Options". In the last grouped elements is a button labeled
"Configure"/"Stufe anpassen". Hit it an scroll down the list. The
second top level group should be labeled "User authentication" /
"Benutzerauthentifizierung" Your setting for this zone is probably
"automatic login only in the intranet zone". 

IE sends the password prematurely.

You should sent an "WWW-Authenticate: NTLM" (or similar) whenever an
browser sends an proxy-request not accompanied by NTLM-auth

Have fun,

Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here