There is a flaw in the way that Internet Explorer displays URLs in the address bar.
By opening a specially crafted URL an attacker can open a page that
appears to be from a different domain from the current location.
Exploit
By opening a window using the
http://user@domain nomenclature an attacker can hide the real location
of the page by including a non printing character (%01) before the "@".
Internet Explorer doesn't display the rest of the URL making the page appear to be at a different domain.