Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 05-15-08   #1 (permalink)
New to Overclock.net
 
0xygen's Avatar
 
intel nvidia

Join Date: Apr 2008
Posts: 542

Rep: 57 0xygen is acknowledged by some
Unique Rep: 45
Trader Rating: 0
Default [orly] Browser Security: Safari Carpet Bomb

Quote:
I recently communicated 3 security issues in the Safari browser to Apple.

Apple let me know that they will fix 1 of the issues I reported. I will not discuss the vulnerability Apple has promised to fix until they release the fix because it is a high risk issue affecting Safari on OSX and Windows.

I let Apple know that I’d like to discuss the 2 issues they won’t be fixing with the security community and they let me know they are fine with it.
oreillynet.com
__________________

System: mantis
CPU
Pentium 4 HT 3.06 GHz
Motherboard
ASUSTeK P5RC-LE
Memory
G.Skill 2GB
Graphics Card
XFX 8600 GT 256MB
Hard Drive
Samsung 200GB SATA 7200
Sound Card
Realtek HiDef Audio
Power Supply
Bestec 300W
Case
Micro-ATX
CPU cooling
Coolmax Heat sink/Fan
GPU cooling
Silent Cooling
OS
Ubuntu 9.10 / XP SP3
Monitor
Sony LCD 19"
0xygen is offline   Reply With Quote
Old 05-15-08   #2 (permalink)
Multi-Quote King
 
The Hundred Gunner's Avatar
 
amd nvidia

Join Date: Jul 2006
Posts: 9,225

Rep: 761 The Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famous
Unique Rep: 421
Trader Rating: 0
Default

Quote:
Originally Posted by From the Article
Before I get to the details, I want to make it extremely clear that the Apple security team has been a pleasure to communicate with. I sent them a couple of emails asking for clarifications, and they responded quickly and courteously every time. I want to publicly acknowledge that I appreciate this very much.

Here are the issues I reported:

1. Safari Carpet Bomb. It is possible for a rogue website to litter the user’s Desktop (Windows) or Downloads directory (~/Downloads/ in OSX). This can happen because the Safari browser cannot be configured to obtain the user’s permission before it downloads a resource. Safari downloads the resource without the user’s consent and places it in a default location (unless changed).

...

2. Sandbox not Applied to Local Resources. This issue is more of a feature set request than a vulnerability. For example, Internet Explorer warns users when a local resource such as an HTML file attempts to invoke client side scripting. I feel this is an important security feature because of user expectations: even the most sophisticated users differentiate between the risk of clicking on an executable they have downloaded (risk perceived to be higher) to clicking on a HTML file they have downloaded (risk perceived to be lower).

Apple’s response was positive:
…we have been investigating the potential for a "safe" mode for local HTML. This is an area that requires a fairly deep investigation to address compatibility issues, and to determine the proper operation. Please understand that when we label this as a security hardening measure, we are not discounting the benefits that this could have.

3. [Undisclosed]. The third issue I reported to Apple is a high risk vulnerability in Safari that can be used to remotely steal local files from the user’s file system. Apple responded positively and let me know that they are actively working to resolve the issue and issue a patch. I will post an update if I hear back from them.

I’d like to thank the Apple security team for their timely responses and for letting me discuss these issues with the security community.
Safari is a really fast browser and supports Firefox's Ad-Block's filter lists. It seems to be so riddled with holes, though... Hopefully they fix this crap.
__________________
"I just talk the way I see things... If that's offensive to you... I'm sorry; you're a loser." - Michael Savage

"But you would be amazed by how many people think that the only reason to have a computer is to play games, and that playing games is all that anyone with a computer does." - dangerousHobo

System: The Shuttle Has Landed
CPU
Athlon 64 3800+ @2.785GHz
Motherboard
Shuttle
Memory
2GB OCZ
Graphics Card
7950GT
Hard Drive
320GB Seagate in Ext. Case
Sound Card
On-board
Power Supply
250W Shuttle "Elanpower"
Case
Shuttle Glamour xPC
CPU cooling
Shuttle "ICE2"
GPU cooling
Stock
OS
Censored to avoid flaming
Monitor
HP M70
The Hundred Gunner is offline Overclocked Account   Reply With Quote
Old 05-15-08   #3 (permalink)
4.1GHz and counting...
 
onlycodered's Avatar
 
intel nvidia

Join Date: Mar 2008
Location: Rochester, NY
Posts: 4,051

Rep: 271 onlycodered is a proven memberonlycodered is a proven memberonlycodered is a proven member
Unique Rep: 223
Trader Rating: 15
Default

Safari is a piece of crap, and that's coming from a Mac user.
__________________
Quote:
Originally Posted by GH0 View Post
So, as a staff from EVGA has told me to do:
PLEASE DO NOT EVER BUY ANOTHER EVGA PRODUCT AGAIN.
Fold for the cause. Fold for team 37726!
Former "The Replacements" folding team member
CPU-Z valid GPU-Z valid

System: Desktop
CPU
E8400 (4.1GHz / 1.33v)
Motherboard
Gigabyte P35-DS3L rev 2
Memory
2x2GB mushkin XP2-8500 DDR2 1066
Graphics Card
XFX GeForce GTS 250 1GB Core Edition
Hard Drive
WD Caviar Black 640GB
Sound Card
Integrated
Power Supply
Xigmatek NRP-MC751 750W
Case
Antec Three Hundred
CPU cooling
Xigmatek Thor's Hammer / D12SM-124B
OS
Windows 7 Professional x64
Monitor
Samsung 2253BW
onlycodered is offline Overclocked Account onlycodered's Gallery   Reply With Quote
Old 05-15-08   #4 (permalink)
PC Gamer
 
intel nvidia

Join Date: Apr 2006
Posts: 4,264
Blog Entries: 8

Rep: 119 RickJS is acknowledged by manyRickJS is acknowledged by many
Unique Rep: 86
FAQs Submitted: 1
Trader Rating: 1
Default

Quote:
Originally Posted by onlycodered View Post
Safari is a piece of crap, and that's coming from a Mac user.
Agreed, FF4MAC4EVA.

o.o
__________________
System: Phrack
CPU
Q6600 B3 @ 2.4
Motherboard
ASUS x38 Maximus Extreme
Memory
G.Skill 2GB DDR3
Graphics Card
Gigabyte 8800 GT
Hard Drive
WD 250GB SATA/4GB Flash
Sound Card
Creative X-FI XtremeGamer
Power Supply
CORSAIR 620HX
Case
ANTEC 900
CPU cooling
T.R.U.E. w/AS5
GPU cooling
Stock
OS
Windows Vista Ultimate 64bit
Monitor
Westinghouse 22" WS 5 MS
RickJS is offline   Reply With Quote
Old 05-15-08   #5 (permalink)
RUNRUNRUN I HUNGER COWARD
 
Marin's Avatar
 
intel ati

Join Date: Nov 2007
Location: Norcal
Posts: 11,442

Trader Rating: 4
Default

Safari for Mac users is like IE for Windows users. It comes with it, some users use it and others install a different browser like FF and Opera.
__________________
Rampage Torture Rack Build Log|Torture Rack|Antec 300|Antec 1200|Antec 1200 Night Photos|Antec 1200 Inside

50D (Sigma 30mm f/1.4 EX DC HSM | Nikkor 50mm f/1.2 | Nikkor 55mm f/1.2 | Canon EF-S 10-22mm f/3.5-4.5 USM | Canon EF-S 60mm f/2.8 Macro USM | Canon 70-200mm f/4L IS USM | Crumpler 7MDH | B+W filters)


Images: Flickr

OCN Team Fortress 2 Group

System: All your base are belong to us
CPU
Q6600 G0 @ 3.4
Motherboard
Rampage Formula[NB]HR-05 SLI/IFX [SB]HR-05 SLI/IFX
Memory
8gb's G.Skill Black Pi DDR2-900 [4-4-4-12]
Graphics Card
VisionTek 4870x2
Hard Drive
500GB AAKS, 2x 640GB AAKS
Sound Card
X-Fi Platinum
Power Supply
Silverstone OP850
Case
Antec 1200 [Four Nanoxia FX12] [Two San Ace 1011]
CPU cooling
[Lapped] TRUE + San Ace H401 [Push/Pull]
GPU cooling
Accelero XTREME
OS
Vista Ultimate 64-bit/Ubuntu 64-bit
Monitor
Samsung 245BW
Marin is online now Overclocked Account Marin's Gallery   Reply With Quote
Old 05-15-08   #6 (permalink)
The Dapper Swindler
 
nathris's Avatar
 
intel ati

Join Date: Sep 2007
Location: Canada
Posts: 7,138

Rep: 494 nathris is a proven membernathris is a proven membernathris is a proven membernathris is a proven membernathris is a proven member
Unique Rep: 381
Folding Team Rank: 1016
Hardware Reviews: 1
Trader Rating: 0
Default

Quote:
1. Safari Carpet Bomb. It is possible for a rogue website to litter the user’s Desktop (Windows) or Downloads directory (~/Downloads/ in OSX). This can happen because the Safari browser cannot be configured to obtain the user’s permission before it downloads a resource. Safari downloads the resource without the user’s consent and places it in a default location (unless changed).
Apple programming in a nutshell... we don't think you want this so we're just not going to include it. That OSX hasn't been destroyed by hackers is a testament to how little they care about it.

System: The Possum
CPU
e8400 @ 4GHz (500x8)
Motherboard
P5Q Deluxe
Memory
4GB G.SKILL DDR2-1000
Graphics Card
XFX Radeon HD 4870 XXX (840/1078)
Hard Drive
WD6401AALS
Sound Card
X-Fi Platinum Fatal1ty Championship Gamer Edition
Power Supply
Corsair HX750W
Case
CM690
CPU cooling
Xigmatek HDT-S1283 w/XLF-F1253
GPU cooling
Accelero Twin Turbo
OS
Windows 7 Professional
Monitor
Samsung 2443BW 24"
nathris is offline I fold for Overclock.net Overclocked Account   Reply With Quote
Old 05-15-08   #7 (permalink)
AMD Overclocker
 
jameskelsey's Avatar
 
intel nvidia

Join Date: Apr 2007
Location: Oxford,Mi. USA
Posts: 2,139

Rep: 192 jameskelsey is acknowledged by manyjameskelsey is acknowledged by many
Unique Rep: 130
Trader Rating: 1
Default

Apple has never had a big enough market share for the hackers to go after it,but that's changing and the attacks will come.
__________________
System: GAMER
CPU
Core i7 870
Motherboard
Intel DP55KG
Memory
8 GB DDR3-1333 HyperX
Graphics Card
EVGA GTX 285 2 GB FTW
Hard Drive
1 TB
Power Supply
Cyber Power 800
Case
CM Storm Sniper
CPU cooling
Asetek water cooler
OS
Windows 7 HP 64
Monitor
22" Viewsonic LCD
jameskelsey is offline   Reply With Quote
Old 05-15-08   #8 (permalink)
Wannabe Audiophile
 
Higgins's Avatar
 
amd ati

Join Date: Dec 2005
Location: Michigan
Posts: 4,960

Rep: 342 Higgins is a proven memberHiggins is a proven memberHiggins is a proven memberHiggins is a proven member
Unique Rep: 280
Hardware Reviews: 7
Trader Rating: 14
Default

I seriously cannot wait for a "blaster.worm" type virus to come to OSX. Not because i want people to get infected but so this false sense of OSX being this secure fortress can finally be ripped to shreds and people can come back to reality.

Is there even an OSX anti-virus?
__________________
[Steam : teh_higgins]
- || -
Currently Playing: STALKER: SoC SMP 2.4F + L4D2 + HL2+FF CM10
| How to: Install OSX on an MSI Wind | How to: Make a Bootable USB drive | Looking for a Matrix Screensaver?|
Massive Blowout Sale
Modern Warfare 2 Bad Company 2

System: Mista PC
CPU
|AthlonII X4 620|
Motherboard
|DFI Lan Party DK 790FX-M2RS|
Memory
|4GB G.Skill DDR2 800|
Graphics Card
|CF ATI HD4830's|
Hard Drive
|1TB Seagate|250GB Maxtor|
Sound Card
|X-Fi Platinum|
Power Supply
|Silverstone 600W|
Case
|Antec 900 w/sound padding|
CPU cooling
|Arctic Cooling|Arctic Freezer 64|
GPU cooling
|Stock aftermarket coolers|
OS
|Windows 7 64bit|
Monitor
|Acer 20" x203w|
Higgins is offline Overclocked Account   Reply With Quote
Old 05-15-08   #9 (permalink)
RUNRUNRUN I HUNGER COWARD
 
Marin's Avatar
 
intel ati

Join Date: Nov 2007
Location: Norcal
Posts: 11,442

Trader Rating: 4
Default

Quote:
Originally Posted by Higgins View Post
I seriously cannot wait for a "blaster.worm" type virus to come to OSX. Not because i want people to get infected but so this false sense of OSX being this secure fortress can finally be ripped to shreds and people can come back to reality.

Is there even an OSX anti-virus?
Yes.
__________________
Rampage Torture Rack Build Log|Torture Rack|Antec 300|Antec 1200|Antec 1200 Night Photos|Antec 1200 Inside

50D (Sigma 30mm f/1.4 EX DC HSM | Nikkor 50mm f/1.2 | Nikkor 55mm f/1.2 | Canon EF-S 10-22mm f/3.5-4.5 USM | Canon EF-S 60mm f/2.8 Macro USM | Canon 70-200mm f/4L IS USM | Crumpler 7MDH | B+W filters)


Images: Flickr

OCN Team Fortress 2 Group

System: All your base are belong to us
CPU
Q6600 G0 @ 3.4
Motherboard
Rampage Formula[NB]HR-05 SLI/IFX [SB]HR-05 SLI/IFX
Memory
8gb's G.Skill Black Pi DDR2-900 [4-4-4-12]
Graphics Card
VisionTek 4870x2
Hard Drive
500GB AAKS, 2x 640GB AAKS
Sound Card
X-Fi Platinum
Power Supply
Silverstone OP850
Case
Antec 1200 [Four Nanoxia FX12] [Two San Ace 1011]
CPU cooling
[Lapped] TRUE + San Ace H401 [Push/Pull]
GPU cooling
Accelero XTREME
OS
Vista Ultimate 64-bit/Ubuntu 64-bit
Monitor
Samsung 245BW
Marin is online now Overclocked Account Marin's Gallery   Reply With Quote
Old 05-16-08   #10 (permalink)
Multi-Quote King
 
The Hundred Gunner's Avatar
 
amd nvidia

Join Date: Jul 2006
Posts: 9,225

Rep: 761 The Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famousThe Hundred Gunner is becoming famous
Unique Rep: 421
Trader Rating: 0
Default

Quote:
Originally Posted by Higgins View Post
Is there even an OSX anti-virus?
http://www.clamxav.com/
__________________
"I just talk the way I see things... If that's offensive to you... I'm sorry; you're a loser." - Michael Savage

"But you would be amazed by how many people think that the only reason to have a computer is to play games, and that playing games is all that anyone with a computer does." - dangerousHobo

System: The Shuttle Has Landed
CPU
Athlon 64 3800+ @2.785GHz
Motherboard
Shuttle
Memory
2GB OCZ
Graphics Card
7950GT
Hard Drive
320GB Seagate in Ext. Case
Sound Card
On-board
Power Supply
250W Shuttle "Elanpower"
Case
Shuttle Glamour xPC
CPU cooling
Shuttle "ICE2"
GPU cooling
Stock
OS
Censored to avoid flaming
Monitor
HP M70
The Hundred Gunner is offline Overclocked Account   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 03:42 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.17259 seconds with 8 queries