Slashdot Mirror


Safari "Carpet Bomb" Attack Still a Risk

SecureThroughObscure writes "Just a short time after Apple's recent acknowledgment of and patch for the Safari Carpet Bomb 'blended' IE flaw, Microsoft researcher Billy Rios shows that Safari is still useful in a blended attack, this time with Firefox 2/3. (ZDNet's Nate McFeters also spread the word.) Rios claimed that he is able to use Carpet Bomb, despite the recent patch, to steal arbitrary files from victims who also have Firefox 2/3 installed. Both Rios and McFeters pointed out that Apple, which took some heat for not originally patching, actually did a good job of addressing the issue, as the code execution angle was not originally understood (the details came out later). Rios is withholding details of the new attack vector until Apple has had time to patch or respond to this issue."

10 of 117 comments (clear)

  1. News Flash: Windows is still a risk. by twitter · · Score: -1, Troll

    Windows is still a complete security failure. It is not possible to secure with any kind of reasonable precautions. Nor can it be secured through strenuous efforts. It is not free, so you can't fix what you think is broken.

    --

    Friends don't help friends install M$ junk.

  2. Somehow, I know MS/IE is behind the FF flaw by Anonymous Coward · · Score: -1, Troll

    MS/IE must have done something to cause this problem in firefox 2 and 3 (?!) so nothing to see here. Move along.

    1. Re:Somehow, I know MS/IE is behind the FF flaw by SecureThroughObscure · · Score: 0, Troll

      Well, but this is the hard part of the argument. See, when Microsoft develops its own system, it does so in a certain way. When M$ designs IE, they make it fit that system. Since they have more knowledge, they can prevent things like this from happening in their own softwares. Of course, when third-parties develop for that system, they don't have that intimate knowledge, so they may assume that Windows protects them, when really they need to protect themselves. The "blended" threat really creates some "Who's fault is it anyways" questions.

  3. Re:News Flash: Windows is still a risk. by Odder · · Score: -1, Troll

    You have to wonder if the people modding you down have a botnet of Windows computers and get to sneer twice about it. It is unlikely someone would use their own computers for this kind of thing.

  4. I think you will be safe, by Odder · · Score: -1, Troll

    as long as you avoid Windows. Don't blame me, that's just the way things work.

  5. Re:News Flash: Windows is still a risk. by Anonymous Coward · · Score: -1, Troll

    I am twitter!

  6. Re:FTP Carpet Bomb Demonstrated! by Odder · · Score: -1, Troll

    That's true. If you can remote execute code you can remote execute FTP and have it "Carpet Bomb" your desktop with stuff you can then execute. Most botnets perpetuate themselves in a more stealthy manner than that.

  7. One Crazy Marketing Idea. by Odder · · Score: -1, Troll

    Because these attacks don't happen on Mac or GNU/Linux, we can be sure they are only useful because of Windows flaws. The marketing people at Microsoft must have lost their minds to push this story, it only proves their OS is still not ready for networking.

  8. Re:FTP Carpet Bomb Demonstrated! by freenix · · Score: 0, Troll

    Well yeah, that's the point. It does not matter if Safari, IE, FTP or any other program is used to download an executable file to your desktop, that might be executed. What matters is that ANOTHER problem can be used to remote execute that file. That's what the Safari flap is all about, but all it does is show you that Windows has lots of holes.

  9. MSFT has to fix this. Windows security issue. by aristotle-dude · · Score: 0, Troll
    I am sick of seeing MSFT trying to pass the buck on a Windows security issue.

    When is MSFT going to implement cross-browser flagging of downloaded executables? When is MSFT going to patch IE to stop it from loading arbitrary DLLs from the desktop?

    --
    Jesus was a compassionate social conservative who called individuals to sin no more.