toggle

AAPL Stock: 502.21 ( + 4.54 )

Developer demos 'exploit' in Tiger's Dashboard

updated 08:05 am EDT, Mon May 9, 2005

Tiger Dashboard exploit


One developer claims to have found a in Apple's new Tiger operating system. According to his website, Apple's highly touted Dashboard technology, found in the new version of Mac OS X 10.4, has a security vulnerability that could cause malicious third-party sites to auto-install a Widget, a small program designed to display Internet content on the desktop. "If you're running Safari on OS X Tiger and go to this website, a 'slightly evil' Dashboard widget will be automatically downloaded and installed and can't be removed without manually removing the file from the Library folder and rebooting the computer." The author says it is a demonstration "how easy it is to exploit Dashboard for nefarious purposes." A subsequent discussion by the author outlines other "more evil" exploits of the security hole. Warning: the site will auto-install the 'zaptastic' widget and will require manual removal.


by MacNN Staff

toggle

Comments

  1. lysolman

    Fresh-Faced Recruit

    Joined: May 2005

    0

    Reaaaallly

    Hey this sounds awful, except...

    1. Turn off automatic open in safari 2. Safari tells you that you're about to open an application, "Do you want to open this?"

    Other than that, I can see that it's a problem.

  1. FeralCat

    Fresh-Faced Recruit

    Joined: Feb 2005

    0

    Re: turning off auto open

    "1. Turn off automatic open in safari 2. Safari tells you that you're about to open an application"

    Yep, and you'll get the added benefit of not auto-opening PDFs, QuickTime movies and other content that you really _do_ want to auto-open. Apple clearly needs to fix Safari so that it won't auto-launch spyware Dashboard widgets.

  1. ThisGuy

    Mac Elite

    Joined: Oct 2001

    0

    That's it...

    I'm switching to Windows. It is much more secure. Nothing like this ever happens on XP while I'm using Dashboard and IE. Ever.

  1. WyvernSpirit

    Fresh-Faced Recruit

    Joined: Feb 2001

    0

    re: Re: turning off auto

    "Yep, and you'll get the added benefit of not auto-opening PDFs, QuickTime movies and other content that you really _do_ want to auto-open. Apple clearly needs to fix Safari so that it won't auto-launch spyware Dashboard widgets."

    Is that new to Safari 2? I haven't turned auto launch off on tiger yet, but I did on panther. I had a plugin for pdfs, which would launch the pdf in the browser window, and quicktime opened in the browser as expected, even with auto launch off. I guess I'll need to check out safari 2 to see if they took that ability away.

  1. ecrelin

    Junior Member

    Joined: Oct 2000

    0

    Big bug…

    I was a little perplexed when I downloaded the TV widget and it auto installed, I thought the download broke because it dutifully warned me that I was downloading and application but it wasn't on my desktop when done. After the second download I checked and sure enought it was already installed. A bad model. Safari shouldn't be able to auto open an application and the system should not allow ANY download to autoinstall. Let's see what they do with this in 10.4.1, hopefully real soon.

  1. budster101

    Baninated

    Joined: Dec 2004

    0

    His website

    actually loads the widget? WTF... Why would he do that?

  1. legacyb4

    Mac Elite

    Joined: May 2001

    0

    S.O.P

    Doesn't Microsoft make a big ballyhoo when developers like this post claims of security holes to the public without giving them sufficient time to "review" these sorts of issues before making public these issues?

    Guess standard procedures don't apply to Apple...

  1. Feathers

    Grizzled Veteran

    Joined: Oct 1999

    0

    Blind Link

    Gee, so nice of MacNN to warn us without mentioning the site or developer by name so we can avoid their (unecessary) little demonstration, or perhaps protect the developer from an instant denial of service assault from "grateful" Macusers. C'mon MacNN don't filter the facts, leave that to Condeleeza Rice.

  1. rok

    Fresh-Faced Recruit

    Joined: Mar 1999

    0

    zaptastic et al.

    as much as i want to love dashboard, now that i have finally gotten a chance to work/play with it, the more i realize that it's SO different than anything apple has tried to do before. good different? bad different? just different. and there is no way that a basic user will know to turn off "auto open safe files" in safari, and while i DO like being able to OPEN safe files like pdfs, i do NOT like items auto INSTALLED like this. plus, apple doesn't make it very easy to remove widgets. go ahead, look in apple help. it says you can't remove or reorder widgets. well, that's not true of course (just look inside library/widgets), but don't you think a basic user will trust help to be telling it the truth? i just do not understand why apple has not given any sort of easy gui way of deleting widgets, like an option-drag out of the dashboard dock or something.

    like i said, it's different. different enough to confuse long-time users (i have never had anything on a mac auto-INSTALL like widgets do from an internet download... i, too, was look for the download on my desktop), and, in an attempt for transparency, really made it hard for basic users to figure out how to backtrack if they make a mistake.

  1. Feathers

    Grizzled Veteran

    Joined: Oct 1999

    0

    Not HTF

    Okay, so it's not hard to find (or avoid): www.stephan.com/

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Powerbag Business Class Bag

Many companies currently offer battery packs and various accessories to keep smartphones and other gadgets charged when away from an o ...

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

toggle

Most Commented

10 Most Discussed