Text Size

New Safari exploit allows remote code execution?

updated 12:10 pm EDT, Mon May 17, 2004

New Safari exploit?

Insecure.ws reports on a . Apple was been notified back in February and still hasn't answered or fixed the problem."

 
Previous Comments

Bound to happen..

05/17, 12:21pm reply

As OS X becomes more popular. You know OS X has hit the big time when the first adware/spyware for OS X is created!

klinux

Senior User

Joined: Jul 2002

0

so?

05/17, 12:37pm reply

So what. It's still not as bad as Windows which can be exploited just by being on the 'net with no interaction at the keyboard.

mbryda

Senior User

Joined: Mar 2002

0

Aiiiiieeeeeee!!!!!

05/17, 12:44pm reply

Run screaming into the night! This is a time to panic, not to be rational or anything. I'm getting out my al Qaeda kit from the 'duct tape and plastic sheathing' scare from last year and sealing myself in my basement until I get the all clear!

testudo

Fresh-Faced Recruit

Joined: Aug 2001

0

i love apple but...

05/17, 01:20pm reply

...at least microsoft addresses these problems.

Chiznibitz

Fresh-Faced Recruit

Joined: May 2001

0

ms addresses

05/17, 01:29pm reply

these problems? is that a joke? do you have any idea the number of "these problems" that microsoft let lie over the years? perhaps you're just too young to remember but microsoft has a long history of NOT addressing these problems. only since "trusted" computing have they started making an effort to plug their incredibly bugged system, you know, the system that needs plugged 3, 4, 5 times a week.

nat

Junior Member

Joined: Mar 2002

0

As nothing...

05/17, 01:34pm reply

This will be as nothing once the real hole introduced with Panther is found: ...://tell your mac to delete everything

Clive

Mac Enthusiast

Joined: Jan 2001

0

This isn't

05/17, 01:42pm reply

anti microsoft or anti apple.. just goes to show that when you have millions of lines of code and questionable and somewhat sloppy programming (programs) you will get exploits!

All that's left is for OS X to have it's source code stolen (see MS and Cisco) and then internet will be totally security free... :)

techguysteve

Fresh-Faced Recruit

Joined: Jun 2000

0

Fix soon?

05/17, 01:43pm reply

This is a serious exploit. The script could be designed to run anything/issue any command to which the logged-in user has access to.
Hopefully by making this public, Apple will get their butt in gear.
Perhaps its fixed in 10.3.4...

Cadaver

Addicted to MacNN

Joined: Jan 2003

0

InternetConfig?

05/17, 02:03pm reply

From the http://netilus.org/~insecure/ website:

"To protect yourself:
- disable auto opening of safe files in Safari (bad protection)
- change the help helper in InternetConfig (better protection) "

InternetConfig is an OS 9 program. What gives with that?

Jeff Hull

Fresh-Faced Recruit

Joined: Dec 1999

0

IC

05/17, 02:06pm reply

InternetConfig has been implemented in MacOSX, and you can edit its values using "More Internet" for example.
You can find this application on the web

kangoo_boo

Dedicated MacNNer

Joined: May 2001

0

Popular News