<a href="http://www.citibank.com" onClick="location.href=unescape('http://[EMAIL PROTECTED] om'); return false;">Citibank</a> will show http://www.citibank.com in the status and location bar but direct them to wells fargo.
-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Clint Bodungen Sent: Tuesday, December 09, 2003 2:30 PM To: [EMAIL PROTECTED] Subject: Re: [Full-Disclosure] RE: FWD: Internet Explorer URL parsing vulnerability However, using this approach still allows the user to see the absolute URL path in the task bar (with the %01 ommitted). _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html