DaveDaniel.Net

A Sign of Intelligent Life

Check this out

Welcome Back - I know, you missed me! Due to a number of reasons, the site has been mostly unavailable - until now. A new server, a reduction in distractions, and a percolating energy around self-importance brings back the site, with archived blogs from the past, and all-new content coming. I hope you enjoy the information. Remember, all web design and content is copyright material. Thanks for visiting, and please come back soon.

Site Design - Recently seen on the web are new boosts of this website graphics design, clear down to the (ahem) innovative use of unnumbered lists for the navigation menus. Two sites I found actually had some original metadata remaining - including my name! It's an honor to have people copy the look, but I'd be happy to share the actual design (written in classic ASP). Either way, send me an email with a URL - it would be interesting to keep a list.

Search Archives


Enter search text
Or, Enter Date

Favorite Sites

www.DaveDaniel.com www.IndyBmw.com www.Splintershop.com www.BeakersAviary.com

Info

Copyright © 1994-2010
Dave Daniel

XML Newsfeed RSS Newsfeeds

Privacy Policy & Legal Notice


Valid XHTML 1.0!

Web Technology - Thin Client Maxed


Interesting URL Bug
A 'feature' of most browsers allow the true address of a site to be obscured from the user by using a carefully crafted URL string. If you click on this link you will note that CNN is now carrying my photo gallery. We all know that they don't have my latest posts on their site, so what's going on?
I was curious how spam email is somehow sending me to what appears to be a legit website (such as the spam emails asking you to reenter credit card info). This started when I was getting emails from PayPal asking me to click on the link to reenter my profile info, including my password. When I clicked on the link, it indeed looked like I was on PayPal's site. Being the suspicious one that I am, and knowing that legit businesses don't ask for confidential info via emails, I closed the browser and checked with PayPal. According to them, the email was bogus.
Research led me to a little known browser standard and how they treat URL's containing special escape characters. When put into a URL string, they do special things, such as ignore any characters that follow - which is how the masquerade works. So, instead of being on a legit site, the true URL (hidden to me) was www.paypal.com[escapecharacters]bogus-site.com - in other words I was at a page on bogus-site.com that simply displayed that it was the PayPal site. (Feeling a little nervous now?)
I won't be any more specific here, but be warned that clicking on an email link to what looks like a legit site might not send you where you think you should be. You have been warned.
Tuesday, December 16, 2003



top