Technology Questions

Go Back   Technology Questions > Software Questions > Internet > Internet Explorer

Internet Explorer Discuss IE7 or any other IE version.

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 05-29-2007, 02:00 AM
Orjan Friberg
Newsgroup Contributor
 
Posts: n/a
IE7 + IIS6 digest authentication: serious bug with multiple bad lo

Hi,

If a certain sequence of bad logins is completed when logging in from an IE7
client to an IIS6 server using digest authentication, subsequent correct
logins will always fail because IE7 stops sending the user credentials.

Assume a user "root" with password "pass". Start a fresh IE7 and access a
server using digest authentication. In the login window that appears, enter
the following sequence of credentials:

1) User: "root", password: "root" (i.e. bad password)
2) User: "root", password: blank (i.e. empty input field)
3) User: blank, password: blank

At this point you get the 401 Unauthorized message in the browser window.
Now access the same URL again, but enter the correct user credentials: you
will not be able to log in.

A network trace reveals that IE7 does not send any "Authorization" field
(containing the user credentials) in the GET request (and not in any
subsequent requests either, for that matter). A browser restart remedies the
situation.

This does not happen for all variants of three bad logins. I have not
checked whether it also affects the ability to log in to servers other than
the one used to exhibit the bug.

----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://www.microsoft.com/communities...plorer.general
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 05-29-2007, 02:00 AM
  #2 (permalink)  
Old 05-29-2007, 02:20 AM
Orjan Friberg
Newsgroup Contributor
 
Posts: n/a
RE: IE7 + IIS6 digest authentication: serious bug with multiple bad lo

A minor addition to my previous post: If I perform a successful login to
another server using digest authentication after the bug has appeared, then
accessing the first server will work fine and I won't even be prompted with a
login window.

Thus, restarting IE is not the only way out of the situation (not that a
user would know this when it happens, however).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
RE: IE7 Digest authentication continously ask password kay27 Internet Explorer 3 03-28-2009 02:49 PM
Setting up an FTP site with IIS6 surfrider26 General Questions 2 01-31-2008 09:28 AM
IIS6 forward problem in IEX7 Mathias Internet Explorer 3 05-06-2007 10:45 AM
Authentication Issues PSU Windows Vista 0 03-06-2007 08:30 PM
Re: LONG [News Digest] Linux News Digest for the 24hrs preceeding 17-12-06 Ken Snyder Windows XP 0 01-04-2007 06:23 AM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 06:30 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0