> Some Bugtraq members have reported Mozilla / Firebird and Opera as
> vulnerable, others have reported these browsers as not vulnerable. We have
> one person here saying that Netscape on Windows is vulnerable for them and
> another who says it is not. There are inconsistencies from machine to
> machine, and some people report inconsistencies on a single machine.

One issue that I've pointed out is that the original post, in the body
text, placed the 0x01 *after* the ampersand.

# Exploit ##########
By opening a window using the http://user@domain nomenclature an
attacker can hide the real location of the page by including a 0x01
character after the "@" character.

The html source of the original POC, and Johannes' web page, all
correctly have the 0x01 (or whatever..) *before* the ampersand.

There may be some people out there who are unknowingly trying to
compare apples and oranges...

