New Safari exploit allows remote code execution?
updated 12:10 pm EDT, Mon May 17, 2004
New Safari exploit?
Insecure.ws reports on a . Apple was been notified back in February and still hasn't answered or fixed the problem."
Insecure.ws reports on a . Apple was been notified back in February and still hasn't answered or fixed the problem."
Bound to happen..
05/17, 12:21pm reply
As OS X becomes more popular. You know OS X has hit the big time when the first adware/spyware for OS X is created!
klinux
Senior User
Joined: Jul 2002
so?
05/17, 12:37pm reply
So what. It's still not as bad as Windows which can be exploited just by being on the 'net with no interaction at the keyboard.
mbryda
Senior User
Joined: Mar 2002
Aiiiiieeeeeee!!!!!
05/17, 12:44pm reply
Run screaming into the night! This is a time to panic, not to be rational or anything. I'm getting out my al Qaeda kit from the 'duct tape and plastic sheathing' scare from last year and sealing myself in my basement until I get the all clear!
testudo
Fresh-Faced Recruit
Joined: Aug 2001
i love apple but...
05/17, 01:20pm reply
...at least microsoft addresses these problems.
Chiznibitz
Fresh-Faced Recruit
Joined: May 2001
ms addresses
05/17, 01:29pm reply
these problems? is that a joke? do you have any idea the number of "these problems" that microsoft let lie over the years? perhaps you're just too young to remember but microsoft has a long history of NOT addressing these problems. only since "trusted" computing have they started making an effort to plug their incredibly bugged system, you know, the system that needs plugged 3, 4, 5 times a week.
nat
Junior Member
Joined: Mar 2002
As nothing...
05/17, 01:34pm reply
This will be as nothing once the real hole introduced with Panther is found: ...://tell your mac to delete everything
Clive
Mac Enthusiast
Joined: Jan 2001
This isn't
05/17, 01:42pm reply
anti microsoft or anti apple.. just goes to show that when you have millions of lines of code and questionable and somewhat sloppy programming (programs) you will get exploits!
All that's left is for OS X to have it's source code stolen (see MS and Cisco) and then internet will be totally security free... :)
techguysteve
Fresh-Faced Recruit
Joined: Jun 2000
Fix soon?
05/17, 01:43pm reply
This is a serious exploit. The script could be designed to run anything/issue any command to which the logged-in user has access to.
Hopefully by making this public, Apple will get their butt in gear.
Perhaps its fixed in 10.3.4...
Cadaver
Addicted to MacNN
Joined: Jan 2003
InternetConfig?
05/17, 02:03pm reply
From the http://netilus.org/~insecure/ website:
"To protect yourself:
- disable auto opening of safe files in Safari (bad protection)
- change the help helper in InternetConfig (better protection) "
InternetConfig is an OS 9 program. What gives with that?
Jeff Hull
Fresh-Faced Recruit
Joined: Dec 1999
IC
05/17, 02:06pm reply
InternetConfig has been implemented in MacOSX, and you can edit its values using "More Internet" for example.
You can find this application on the web
kangoo_boo
Dedicated MacNNer
Joined: May 2001