Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
At least two of the security flaws addressed in the release version of Safari 4.0 can be used to attack Safari 3.x. Proofs of concept are in circulation.
We asked Apple for clarification, and have yet to receive a reply beyond a statement that Safari 4.0 "is the full update that replaces the previous beta version of Safari 4.0 and any previous editions of Safari."
But if one security researcher is correct, at least two of the addressed vulnerabilities can be found in Safari 3.x for Mac OS X and Windows.
According to Google employee Chris Evans, Safari's XML processing can be fooled into delivering the contents of a local file. Not nice.
"XXE [Xml eXternal Entity] attacks are most common server-side; this advisory notes a client-side attack against the Safari browser," observes Evans, who has provided a proof of concept for this vulnerability.
He also notes that a second XML flaw allows cross-domain access with the potential to steal sensitive information. For this vulnerability, Evans' proof of concept shows how it can be used to steal inbox details from a logged-in Gmail session.
According to Evans' descriptions of the issues, both problems were "found on Google's time" and originally reported to Apple in June 2008.
Barring the prompt arrival of a Safari 3.x update from Apple, this suggests that if you can upgrade to Safari 4.0 then you probably should.
David Bass
| For the fourth year in a row, IDC has placed content security provider Websense (NASDAQ: WBSN) at the top of the IDC Worldwide Web Security 2011 –…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.