macnn

05/20/2008, 6:55pm, EDT

Tuesday, May 20th

"Safari Carpet Bomb" attack possible

A large security hole in the Windows version of Safari has security researcher Nitesh Dhanjani believing that malicious users could exploit the browser with what he calls a “Safari Carpet Bomb”. Stop Badware reports that the exploit works through Safari’s inability to obtain a user’s permission before downloading resources, related to how it handles content-type rendering. Dhanjani filed a security report with Apple, and was met with a rather neutral response.

“We can file that as an enhancement request for the Safari team. Please note that we are not treating this as a security issue, but a further measure to raise the bar against unwanted downloads. This will require a review with the Human Interface team. We want to set your expectations that this could take quite a while, if it ever gets incorporated.”

Stop Badware writes that the issue is larger than Apple is giving it credit for, saying that the vulnerability would cause a serious security threat.


Filed under: industry, security, software, hacks
Other story tags: Safari

, , 5comments, del.icio.us, slashdot, digg, buzz


5 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings

the sky is falling

0
05/21, 3:48am, EDT

"carpet bomb"?!? Can we get more sensational than that? Great way to grab some headlines. Next time, try "nuclear holocaust".

I wonder how long after he submitted the report to Apple before he went for the headlines. Did he give them time to investigate and work up a solution (assuming it was merited)?

Fresh-Faced Recruit
Joined Sep 2007
User is offline

re: the sky is falling

0
05/21, 10:39am, EDT


Well you could have just read the response from Apple to get an idea of what they thought.

"We can file that as an enhancement request for the Safari team. Please note that we are not treating this as a security issue..."

Apparently he waited long enough for them to reply.

He was apparently nice enough to notify them instead of just releasing malicious code based on the 'supposed' exploit.

Fresh-Faced Recruit
Joined Apr 2008
User is offline

nice

-4
05/21, 12:35pm, EDT

Apparently apple doesn't see downloading automatically a large amount of files a problem. Hmmm.

Fresh-Faced Recruit
Joined Aug 2001
User is offline

This is just a DOS

0
05/25, 1:05pm, EDT

This is just a DOS attack. Downloading a file is not an exploit: at most downloading a lot of files can lead to your link being saturated and eventually your disk filling up, but you will notice it and you can unilaterally stop it at any time. There are far worse attacks you can pull on a browser... simply opening a bunch of frames and rendering a big HTML file in each will bog a browser down worse than this "attack".

Oh, should I have notified Microsoft and Firefox and Apple before saying that?

Fresh-Faced Recruit
Joined Jan 2005
User is offline

my understanding,,,

0
06/11, 1:37pm, EDT

,,,is that yes, safari does automatically download the files, but it's microsoft's OS that automatically RUNS the dll files. sems safari's problem may be somewhat minor in comparison

Fresh-Faced Recruit
Joined Dec 2005
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

IT Education and Training at University of Phoenix: View our complete list of Information Technology Courses and Programs. Official Site.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.