Slashdot Mirror


Malicious Web Pages Can Install Dashboard Widgets

bonch writes "If you're running Safari on OS X Tiger and go to this website, a 'slightly evil' Dashboard widget will be automatically downloaded and installed and can't be removed without manually removing the file from the Library folder and rebooting the computer. The widget is called Zaptastic and is a demonstration by the author of how easy it is to exploit Dashboard for nefarious purposes. The essay, released under the Creative Commons License, goes on to describe the many ways users can be taken advantage of--imagine porn sites auto-installing adware widgets without your knowledge." So if you're on a Mac, it would be smart to view that page with something other than Safari.

26 of 610 comments (clear)

  1. yes but... by Anonymous Coward · · Score: 5, Funny

    magine porn sites auto-installing adware widgets without your knowledge.

    Yes, but do they install porn?
    -SJ53

    1. Re:yes but... by mike518 · · Score: 5, Funny

      "magine porn sites auto-installing adware widgets without your knowledge."

      i dont need to imagine, im running windows xp.

      --
      Mike
      I heart the RIAA & MPAA, im sure its mutual...
  2. Serves you right by th1ckasabr1ck · · Score: 3, Funny

    If people would just run a secure OS like Linux or Windows, they wouldn't be hit with attacks like this. When will people learn?

    1. Re:Serves you right by Mitleid · · Score: 2, Funny

      God damn I wish I had some mod points. Very well said, my friend.

      --

      --
      Is it me, or did it just get fatter in here?
    2. Re:Serves you right by Anonymous Coward · · Score: 2, Funny
      I use a Mac, there are not exploits for my OS

      whenever [OS X] is found to have a flaw, those zealots are awfully quiet.

      Good thing it hasn't happened then.

    3. Re:Serves you right by whitepony02027 · · Score: 2, Funny

      but what makes it better is that we have the problems here and now while Windows users have to wait a year and a half for them.

  3. In soviet russia by zkn · · Score: 4, Funny

    Apple copies Microsoft.....

  4. HAH! by JoeCommodore · · Score: 2, Funny

    I'm running Jaguar!

    I can't afford to buy all the Apple "upgrades of the month."

    --
    "Enjoy what you're doing! If it becomes drudgery, you're doing it wrong!" - Jim Butterfield
  5. Thanks Slashdot! by CypherXero · · Score: 1, Funny

    Nothing happened to me (I'm running XP at the moment), but there's a friggin ZIP file sitting on my desktop. OK, time to bring out my tin foil hat! And to the /. editors, don't link to shit like that, damn! That's just common sense.

    1. Re:Thanks Slashdot! by jericho4.0 · · Score: 4, Funny
      Oh. My. God. There's a zip file on your desktop. Holy Shit. A zip file, for Christ's sake! What will your fate be? Long and painful, or medium and painful? How will your family go on?

      --
      "A language that doesn't affect the way you think about programming, is not worth knowing" - Alan Perlis
  6. Yeah... by Nanoda · · Score: 3, Funny
    imagine porn sites auto-installing adware widgets without your knowledge.

    Yeah... I'm imagining those porn sites.........

  7. uh... by pkboy · · Score: 2, Funny

    "imagine porn sites auto-installing adware widgets without your knowledge." I guess Mac users can now blame their browsers for the pr0n popping up on their computers as well.

  8. Awww...How cute! by justforaday · · Score: 3, Funny

    Looks like he was nice and made us a goatse.cx widget. Too bad I don't have Tiger yet... :'(

    --
    I'll turn into a supernova and burn up everything. Well I'll turn into a black little hole and you'll turn into string.
  9. YOU BAD MOUTHED ABOUT APPLE! by Anonymous Coward · · Score: 0, Funny

    Mod parent down now!

  10. O Great Oracle of Slashdot by Dachannien · · Score: 5, Funny

    If there's anything that Slashdot has taught us, it's that it's never safe to use your computer.

  11. Re:Not much of a problem... by Anonymous Coward · · Score: 2, Funny

    JPEG files are "safe"

    hello.jpg, tubgirl, need I go on?

  12. Imagine it? by Anonymous Coward · · Score: 4, Funny



    imagine porn sites auto-installing adware widgets without your knowledge

    Imagine it? I'm a Windows/IE user...I live it!

  13. Thank God for Firefox and Windows by Pedrito · · Score: 3, Funny

    I'm just glad I'm running Firefox under Windows. No need for me to worry about nefarious web sites.

  14. This can't possibly be true by rudy_wayne · · Score: 3, Funny

    This can't possibly be true.

    Everyone knows that Linux and OS X are perfect and only Windows has security exploits.

    Let's get it right people! You're slipping!

  15. Re:widgets limited by Anonymous Coward · · Score: 1, Funny

    And then, of course, come the inevitable vulgar ACs, fucktard.

  16. some guy in Russia by Eric_Cartman_South_P · · Score: 3, Funny
    "some guy in Russia"

    Just find this guy and kick his ass. Problem fixed, no need to patch shit.

  17. Re:widgets limited by Cecil · · Score: 2, Funny

    > > And then, of course, come the inevitable vulgar ACs, f**ktard.

    > Like yourself and your hypocritical vulgar potty mouth?

    Of course, we can't forget the "joke went *whooooosh* RIGHT over my head" crowd! Thanks for reminding us!

  18. This is why I run BeOS by l0rdpestilence · · Score: 1, Funny

    I run BeOS for this reason: Netpostive is so out of date vary little runs in, sometimes even HTML. (Note to mods this is a funny)

  19. ohohoho this is gonna be fun by Pinefresh · · Score: 1, Funny

    gonna send this to all my friends who have a mac

  20. Afraid that won't work cuz... by NoData · · Score: 4, Funny

    IN SOVIET RUSSIA...some guy kicks ass of YOU!

    (Oh christ, why? The karma, it burns like my shame)

  21. Re:Oh but it has, and you've proved part of my poi by U96 · · Score: 3, Funny


    I use a Mac

    We could tell from your beret.

    --

    "I thought they were the dominant species..."