Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple

January 27th, 2012, 08:45 GMT · By

Apple Store Goes Down as Cupertino Fixes XSS Vulnerability

SHARE:

Adjust text size:


Apple Store down
Enlarge picture
The Apple online store is down worldwide — reason enough to get excited and write a story about it, as usual. But it appears security is the culprit this time around, not new product announcements.

Some Macs are due for a refresh (some, like the Mac Pro, are actually overdue), and we also shouldn’t bet against Apple releasing something new altogether on a Friday.  Apple rarely pulls its store down solely for maintenance, but it’s certainly not out of the ordinary either.

Granted, we have very little expectations in terms of a product refresh, especially since it’s a Friday. The company usually makes big announcements on Tuesdays.

If Apple is planning to release an upgraded version of the Mac Pro, the rumors say it’s a complete redesign, which means it might have deserved its own show. But Apple also has a history of refreshing Macintosh computers without building special events around them. MacBook redesigns are a good example of that.

Unfortunately, we shouldn’t expect any of this today.

We’ve received word that a security researcher (referred to as longrifle0x) submitted a cross-site scripting (XSS) vulnerability affecting store.apple.com on 21/01/2012. At the time of submission, it ranked 30 on the web according to Alexa.

The people at xssed.com say they manually validated and published a mirror of this vulnerability on January 24, and that is currently unfixed.

Exploited cross-site scripting vulnerabilities can be used by attackers to bypass access controls such as the same origin policy. Vulnerabilities of this kind have been exploited to create powerful phishing attacks and browser exploits.

In plain English, with a little social engineering, you can use this to make the Apple online store display whatever you want.

Update: just as this report was getting published online, Apple had fixed the cross-site scripting vulnerability affecting store.apple.com.

TELL US WHAT YOU THINK:

1,259 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Apple CEO Gives His Word That Worker Abuse Claims Are Blatantly False

nivio Puts Windows + Office on Your iOS Device, Mac Computer

Apple Looked the Other Way for Years on Foxconn Worker Abuse - Report

DriveSavers Rescues a Library-of-Congress-Worth of Data from Apple Computers

Macworld 2012: iRecord Pro Puts Your VHS Tapes on Your iOS 5 Device

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM