Safari Falls Victim to Remote Code Exploit
A user writes, "A new vulnerability has been found in Mac OS X's Safari, which will launch Help.app and run an arbitrary script with a URL like 'help:runscript=...', assuming a known path (which is possible when Safari is set to automount disk images (which is the default)). A nice working demonstration is available on insecure.ws while the incident has been reported on Full-Disclosure."
"help:runscript=..."
No double-decode, unicode obfuscation, or CMD.EXE parms. Even the exploits are user-friendly!
I'm switching to Windows!
omg no!! wat wil i do?
some1 help meeeeeeee!!!!!!!
\@O@/
First signs that apple's really in competition with Microsoft
I SO GLAD MY TRS-80 COCO ISENT
VULNERABLE TO THIS. ALL YOU PE
OPLE WITH FANCY GUI COMPUTERS
WILL REGRET IT SOME DAY.
OK
?
OK
?
(Lameness filter encountered. Post aborted!
Reason: Don't use so many caps. It's like YELLING.)
Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.
Congratulations on completely missing the point.
> Also, MSIE allows changing it, and it is included with Mac OS X
Using MSIE to workaround an OS X security issue, imagine that!
I'm afraid to click on a URL containing "monkeyfood" in it in this kind of thread.
I'd like to announce the unveiling of my new website, http://www.iwilltotallyhax0ryourmac.com/evil_page. htm
Opera doesn't run the links...
finally a reason to use opera