New Safari exploit allows remote code execution?
updated 12:10 pm EDT, Mon May 17, 2004
New Safari exploit?
Insecure.ws reports on a . Apple was been notified back in February and still hasn't answered or fixed the problem."
Insecure.ws reports on a . Apple was been notified back in February and still hasn't answered or fixed the problem."
Comments
So what. It's still not as bad as Windows which can be exploited just by being on the 'net with no interaction at the keyboard.
Run screaming into the night! This is a time to panic, not to be rational or anything. I'm getting out my al Qaeda kit from the 'duct tape and plastic sheathing' scare from last year and sealing myself in my basement until I get the all clear!
...at least microsoft addresses these problems.
these problems? is that a joke? do you have any idea the number of "these problems" that microsoft let lie over the years? perhaps you're just too young to remember but microsoft has a long history of NOT addressing these problems. only since "trusted" computing have they started making an effort to plug their incredibly bugged system, you know, the system that needs plugged 3, 4, 5 times a week.
This will be as nothing once the real hole introduced with Panther is found: ...://tell your mac to delete everything
anti microsoft or anti apple.. just goes to show that when you have millions of lines of code and questionable and somewhat sloppy programming (programs) you will get exploits!
All that's left is for OS X to have it's source code stolen (see MS and Cisco) and then internet will be totally security free... :)
This is a serious exploit. The script could be designed to run anything/issue any command to which the logged-in user has access to.
Hopefully by making this public, Apple will get their butt in gear.
Perhaps its fixed in 10.3.4...
From the http://netilus.org/~insecure/ website:
"To protect yourself:
- disable auto opening of safe files in Safari (bad protection)
- change the help helper in InternetConfig (better protection) "
InternetConfig is an OS 9 program. What gives with that?
InternetConfig has been implemented in MacOSX, and you can edit its values using "More Internet" for example.
You can find this application on the web
OR
Network Headlines
Most Popular
Recent Reviews
Logitech Cube
The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...
NewerTech and Targus USB Hubs For Gifts
A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...
X-Rite ColorMunki Photo
Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...
Most Commented
Popular News
Senior User
Joined: Jul 2002
Bound to happen..
As OS X becomes more popular. You know OS X has hit the big time when the first adware/spyware for OS X is created!