NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Apple / Software

Software


More Voices Calling on Apple to Fix the Safari 'Carpet Bomb'

Apple still short on a Safari patch

By Filip Truta, Apple News Editor

30th of May 2008, 07:59 GMT

Adjust text size:


This is what can happen to Windows users, according to Nitesh Dhanjani
Enlarge picture
ZDNet is reporting that "the Google-backed StopBadware coalition has called on Apple to rethink its stance" on the Safari "carpet bomb" issue. Reported weeks ago by Nitesh Dhanjani, the flaw puts both Mac and Windows users at a serious security risk, according to voices on the Internet. Apple doesn't seem to be on the same level with everyone.

"Malware downloaded to the user's desktop without the user's consent" is the primary issue researcher Nitesh Dhanjani encountered with Apple's standard web browser on Mac OS X 10.5 Leopard. Research has revealed that it is actually quite simple to use the browser and deploy malware on a user's computer. Still, Secunia rated the vulnerability as "less critical" at the time and still does.

Files downloaded by Safari to the Downloads folder on Mac OS, or to the desktop, on Windows, "create the potential for multiple files of unknown nature to mingle with legitimate downloads", StopBadware is reporting. Nitesh Dhanjani's example shows that Safari "cannot be configured to obtain the user's permission before it downloads a resource: assume that http://malicious.example.com/cgi-bin/carpet_bomb.cgi is the following: #!/usr/bin/perl print "Content-type: blah/blah". Since Safari does not know how to render content-type of blah/blah, it will automatically start downloading carpet_bomb.cgi every time it is served."

Now, here's Apple's response to that: "We can file that as an enhancement request for the Safari team. Please note that we are not treating this as a security issue, but a further measure to raise the bar against unwanted downloads. This will require a review with the Human Interface team. We want to set your expectations that this could take quite a while, if it ever gets incorporated."

So, it should be clear to everyone that Apple's standard web browser on Leopard running machines doesn't bother to ask users for permission when downloading content from websites. Since Safari does not know how to render the content-type of a certain address, it will automatically start downloading the "carpet bomb" every time it is served. Needless to say, you should take extra caution downloading stuff you know little or nothing about, at least until Apple issues a patch.

TAGS:

Safari | flaw | exploit | carpet bomb | arbitrary
Read by 1,006 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.0/5) 4 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Free dmg-Making Tool, iDMG 2 Adds Growl Support, More

1Password 2.6.2 Available. AllBookmarks Updated Too

Softpedia Recommended Mac Apps of the Week - 17.05.2008

Safari Vulnerable! Apple to Issue Fix for One of Three Faults

iPhone / Touch - Readdle to Allow Viewing Uploaded Books without a Live Internet Connection

AOL Desktop (1.0) for Mac Launched. Download Here.

Leech 1.0 New Download Manager for Mac

Beta Available for Wild West Online: Gunfighter

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM