Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say forum.
PDFPrintE-mail

Safari vulnerable to remote file-stealing attack

Opinion and Analysis

A newly revealed vulnerability in Apple's Safari web browser allows a remote site to read files stored on a Mac or Windows system. According to the discoverer, the vulnerability has been acknowledged by Apple.

According to Brian Mastenbrook (who describes himself as a 'next big thing architect' and software engineer), "Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention."

"[T]his vulnerability could be exploited by a phishing site in a way that would not cause affected users to suspect their information had been stolen," he added.

Although Mastenbrook did not disclose details of the vulnerability, it may involve the use of malformed feed: URLs. History suggests that the underlying problem is either a buffer overflow or a format string issue.

The vulnerability is said to affect Safari on Windows as well as Mac OS X 10.5.

According to Mastenbrook, an interim workaround for Mac OS X users is to set a program other than Safari as the default RSS reader in Safari's preferences.

Users of other Mac web browsers are vulnerable unless they make this change. Presumably an exploit would involve a feed: link in a web page or email that would still be directed to Safari unless that preference was altered.

Does Mastenbrook have a track record that adds credibility to his claim? See page 2.



SPONSORED PRESS RELEASES

Websense Security Labs Reports ‘User Trust’ Targeted Attacks; Over 1 in 10 ‘Top Search’ Results Categorised as Malware; Increased Focus on Web 2.0
Websense, Inc. today revealed the findings from its bi-annual research report: Websense Security Labs, State of Internet Security, Q3-Q4 2009.

Featured IT jobs

A varied DBA role that involves multitasking in a dynamic software development environment dealing with challenging customer needs on a daily basis.
Skills Tags:   Linux  Oracle  UAT
A position has just become available for experienced Program/Project Manager to join a large organisation on a major Data Centre upgrade....
Skills Tags:   SAP
URGENT! Experienced BDM needed for senior sales role in Melbourne - must have ITSM consultancy sales experience.
Skills Tags:   C  Development  EDI  IT
CRITICAL INCIDENT COORDINATOR - 24 x 7 shifts - 3 month CONTRACT ONLY...
Skills Tags:   Excel  IT  ITIL  Management  Reporting

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases