troubleshooting/tutorials/security
05/17/2004, 12:10pm, EDT
Monday, May 17th
New Safari exploit allows remote code execution?
Insecure.ws reports on a new Safari exploit, which it says allows remote websites to execute code on any machine: "there is a new Safari exploit, using a management error in the HelpViewer.app Helper which allows to execute anything on the client computer, especially when Safari Safe File Opening is activated (this is your default setting). A demo of the problem, writting a text on your hard disk and displaying is available on the Web. Apple was been notified back in February and still hasn't answered or fixed the problem."
Filed under: troubleshooting
,
, 23
,
,
,
,
,
,

subscribe to comments
for this article
All that's left is for OS X to have it's source code stolen (see MS and Cisco) and then internet will be totally security free... :)
Hopefully by making this public, Apple will get their butt in gear.
Perhaps its fixed in 10.3.4...
"To protect yourself:
- disable auto opening of safe files in Safari (bad protection)
- change the help helper in InternetConfig (better protection) "
InternetConfig is an OS 9 program. What gives with that?
You can find this application on the web