Notices

Water Fountain General Chit/Chat

Reply
 
LinkBack Thread Tools
Old 02-21-06, 10:54 AM   #1 (permalink)
Banned from Site
 
reese's Avatar
Addicted Member
 
Join Date: May 2004
Posts: 4,564
Thanked 0 Times in 0 Posts
Critical OS X zero-day exploit

http://blogs.zdnet.com/Apple/index.php?p=103

Quote:
Heise online is reporting that a new critical vulnerability for Mac OS X has been discovered and it appears to have ramifications beyond the Safari brows. The problem is severe because a user simply needs to visit a malicious website and shell scripts with launch with zero user interaction!
Wonder what all the apple people will say about this one...

Here is the temporary work-around:
The best immediate recourse against such an attack is to deactivate the option "Open 'safe' files after downloading" in the "General" section of Safari's preferences. Alternative web browsers such as Camino or Firefox do not support the automatic execution of files. These browsers can be prompted to automatically download a file by using the refresh command in the HTML source code of a web page. However, the file will not be executed. Since the Finder selects the icon for a file based on its extension, users are advised to verify that the OS is using the proper file type. This can be done through the information window or in column view.

Last edited by reese; 02-21-06 at 10:58 AM.
reese is offline   Reply With Quote
Sponsor Ads
Old 02-21-06, 05:19 PM   #2 (permalink)
Axim_X50_owner
Guest
 
Posts: n/a
Alright a simple step: Throw saffari in the recycle bin and use mozzila. Also if you are trying to make mac look bad, I can post windows explot's but there are so many they would proubly crash the server......
-Justin
  Reply With Quote
Old 02-21-06, 06:26 PM   #3 (permalink)
Tblove
Guest
 
Posts: n/a
Looks like reese was just posting some useful info to me,not bash anything.
  Reply With Quote
Old 02-21-06, 06:27 PM   #4 (permalink)
Aximsite All Star
 
coolbre304's Avatar
Elite Member
 
Join Date: Aug 2003
Location: Lexington, SC
Posts: 919
Device: Motorola V710
Carrier: Verizon
Thanked 0 Times in 0 Posts

Awards Showcase
Aximsite Contest Winner 
Total Awards: 1

I don't think he intended to make the Mac look "bad" and I agree, there are THOUSANDS more holes in windows than in OS X but, just a little tip for those who didn't know im sure.
__________________
BM

"If the automobile had followed the same development cycle as the computer, a Rolls-Royce would today cost $100, get one million miles to the gallon, and explode once a year, killing everyone inside." Robert X Cringely

Addition who needs that kind of stuff any way huh?

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


Who cares if I'm only 16?
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
coolbre304 is offline   Reply With Quote
Old 02-21-06, 07:08 PM   #5 (permalink)
Aximsite Legend
 
Howard2k's Avatar
Addicted Member
 
Join Date: Jun 2003
Location: Toronto, Canada
Posts: 13,721
Thanked 4 Times in 4 Posts

Awards Showcase
Aximsite Active Silver Member Moderator Medal Silver Poster 
Total Awards: 3

It requires certain settings to be enabled (and I think they are by default).

There is a setting in Safari that will allow it to automatically open known files.

I *think* the same exploit applies to Windows doesn't it? If a user clicks on a link to a word document and the word document contains a macro virus then they're infected right?


Either way - good computing practices provide a lot of protection. OS X makes it plain sailing to do all of your day to day activities outside of an admin account so there is some "sand boxing" against these social engineering type attacks.
__________________
Always read stuff that will make you look good if you die in the middle of it.
Howard2k is offline   Reply With Quote
Reply

Tags
critical, exploit, zeroday

Sponsor Ads

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:02 PM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2003-09 LeckMedia, LLC