[mdlug] Evil URLs at OpenSuSE

Robert Meier eaglecoach at wwnet.com
Fri Feb 23 19:52:10 EST 2007


Ray,

> Maybe this usage has been around a while and I just haven't noticed,
> but this week I did notice, urls like this:
> http://software.opensuse.org/download/X11:/xfce/SUSE_Linux_10.0/i586/
> The evil bit seems to be the inclusion of the colon ':' in the directory
> name.

I didn't have a problem with this or other URLs are I tried using
Netscape 7.  What browser are you using?

>From the narrow range of dates,
I suspect that an automated system generated the unconventional URLs,
and has since been rendered more conventional.


  "...
   Within the <path> and <searchpart> components, "/", ";", "?" are
   reserved.  The "/" character may be used within HTTP to designate a
   hierarchical structure.
   ...
   urlpath        = *xchar    ; depends on protocol see section 3.1
   ...
   xchar          = unreserved | reserved | escape
   ...
   reserved       = ";" | "/" | "?" | ":" | "@" | "&" | "="
   ..."
	-- RFC 1738

A colon appearing in the path section of an http url should cause no
problems.  

-- 
Dr. Robert J. Meier



More information about the mdlug mailing list