Slashdot Mirror


Remote iChat Exploit Patched

99BottlesOfBeerInMyF writes "Apple has released a security update to patch a hole in iChat. Apparently, correctly crafted links sent via iChat can execute programs if the path is known. If this allows for command line attributes to be included, it could be a pretty big hole; although it would still require some social engineering. The Apple description is here."

6 of 55 comments (clear)

  1. Wow... by PedanticSpellingTrol · · Score: 5, Funny

    This sounds exactly like the away:// hole in AIM from a few weeks ago. Has anyone audited the UNIX talk command for similar bugs?

  2. Re:social engineering by teh*fink · · Score: 5, Funny

    How hard is to to socially engineer the average mac user?

    you wouldn't believe how easy it is. whenever new users come into the "panther" chatroom using ichat, they are told to hit command-L for a list of other chatrooms. 80% fall for it. some repeatedly; they come back and ask for the key combo again, figuring they entered it wrong the first time.

    --
    "I DARE you to make less sense!"
  3. Re:All I want to know is... by Anonymous Coward · · Score: 5, Funny

    Every time you reboot, god kills a kitten.

  4. Re:social engineering by hunterx11 · · Score: 4, Funny

    I wonder how many Mac users get tricked into typing Alt+F4 only to wonder why nothing happens?

    --
    English is easier said than done.
  5. But ... but ... but... by commodoresloat · · Score: 4, Funny

    What about my uptime? What about my precious uptime??!!!

  6. Windows Geeks are Hermaphrodites by Anonymous Coward · · Score: 1, Funny

    But I bet you already knew that.

    So how long until "Chicks With Dicks 25" comes out anyway? Randall preordered that thing ages ago.