Windows 7 Forums


Reply
Thread Tools

Homeland Security Warns About Latest Dangerous Apple Browser Bug

 
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,739
Thanked: 1055
 
      05-11-2010
From: DailyTech.com

May 10, 2010 5:20 PM



Apple, which perpetually makes fun of Microsoft's Windows for being "buggy" and "virus prone" is yet again endangering its users with lax security and poorly written code. (Source: Apple)




This time Apple's latest security woe is a "highly critical" flaw in its Safari browser; and Apple is yet again silent on the issue.


Cyberthieves can use the vulnerability to execute arbitrary code, steal information


Apple's arrogant air when it comes to security has yet again come back to bite it. This time Danish security research firm Secunia discovered yet another vulnerability in the web browser Safari, which they billed as "highly critical" -- their most serious rating.

Secondary confirmation of the bug came from the United States Computer Emergency Readiness Team (US-CERT) (part of the U.S. Department of Homeland Security), which issued an advisory after Polish researcher Krystian Kloskowski disclosed the bug on Friday.

The bug exploits Apple's poor implementation of code that handle's the browser's parent windows. According to Secunia, "This can be exploited to execute arbitrary code when a user visits a specially-crafted Web page and closes opened pop-up windows."

US-CERT adds that HTML email opened in webmail services such as Gmail or Windows Live Hotmail may also exploit the flaw. By compromising the operating system, hackers are free to log user information (such as credit cards or personal contacts) and install malware to accomplish a host of evils.

The flaw works in Windows 7 on the latest version of Safari 4 (4.0.5). "Other versions may also be affected" according to US-CERT -- so OS X users of Safari aren't off the hook yet. Charlie Miller, noted Mac hacker and security expert was not available to verify whether the bug existed in OS X. He's on vacation after hacking Safari and earning $10,000 in loot in March at the Pwn2Own contest.

Miller has stated that Macs and Apple software are often easier to hack than PCs and Windows software. Overall there's been relatively little interest in hacking Macs or Apple products, but what little attention there has been has revealed a host of security flaws. Apple patched 16 flaws in Safari in mid-March -- including 10 that affected OS X. Miller's exploit was among those flaws fixed.

Apple is keeping quiet on the latest danger to its customers -- its usual response to such security dangers. Security experts at US-CERT and Secunia are providing Safari users with some sound advice for now at least -- don't open untrusted HTML emails, and disable JavaScript except on trusted sites.

Many security experts have criticized Apple's lax stance on security and poorly implemented products. Charlie Miller states, "Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town."

Or as Mac researcher Dino Dai Zovi once put it, "There is no magic fairy dust protecting Macs. Writing exploits for [Microsoft] Vista is hard work. Writing exploits for Mac is a lot of fun."

SOURCE


My Personal Note:
I have found this article to be extremely interesting to say the least!
 
Reply With Quote
 
 
 
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,510
Thanked: 510
 
      05-12-2010
It's about time flaws are being discovered in Apple's software. Users who spends a minimum of $1,100 for a standard sized laptop, which happens to be their rot-gut line of products (the bottom of the bucket), all the way to $5,000 or more, are now finally getting their share of what the other brands has gotten. No one is immune to remote code execution, as some Windows & Linux users knows firsthand.

Honestly, it's baffled me for a long time as to why more shots aren't being taken at Mac users, they are the ones with the money, with all kinds of juicy information to be found on their "uncrackable" systems. In the upcoming months, we're probably going to find out just how secure these systems really are. It's their turn.

Finally, a short education to those who are unaware of what "remote code execution" is. It's not a virus. It's perhaps the most dangerous thing that can happen to any computer user. Once it's planted on your computer, the one(s) responsible for the attack can pretty much do what they please with your computer. Think about that for a minute, pretty much do as they please. The skill level of the attacker and the users security posture at the time of attack are both critical to the outcome of the attack.

So with that in mind, make sure you have a decent AV, along with a separate malware scanner (such as Malwarebytes), and keep them both updated. Practice safe computing, don't open unsolicited emails, don't click onto "pop up" ads, don't go to sites that promises things that are "too good to be true" (spam leads to this). If you have Firefox, the No Script add on is your best friend, as well as Adblock Plus. Use them both. Whatever browser you use, use the latest version, and keep your entire computer updated. Do a full manual scan with your AV once weekly, and another with a separate malware scanner at least once monthly. These are the simple things you can do to stay safe as you can. It is my hope that this post makes everyone a little more aware of the dangers of the net, and no matter the brand you choose, you're never 100% safe. Don't let anyone tell you otherwise.
 
Reply With Quote
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 329
 
      05-12-2010
Apple ? Who ? ......... Oh Mac them over priced under powered things ... what a shame
 
Reply With Quote
 
roban roban is offline
Established Member
roban's Avatar
Join Date: Nov 2009
Location: East Hampton, NY
Posts: 217
Thanked: 39
Send a message via ICQ to roban Send a message via MSN to roban Send a message via Yahoo to roban
 
      05-12-2010
Good advice catilley. One should not depend on just one line of defense. In these days of Broadband the user has a responsibility to defend their own domain and few are willing to take this seriously and that is the hacker's delight. How many times I have provided the tools to my clients and how little they use them.

Why do I rant? My client's laziness is my mortgage payment
 
Reply With Quote
 
Fire cat Fire cat is offline
Established Member
Join Date: Mar 2010
Posts: 1,155
Thanked: 164
 
      05-12-2010
Proof that Mac and Apple is just about the good looks.
This ain't good for those paranoid liars!

Good advice Cat.

Cheers,
Fire Cat
 
Reply With Quote
 
patrickt patrickt is offline
New Member
Join Date: Mar 2009
Posts: 24
Thanked: 1
 
      05-12-2010
I'm sorry but anything the government warns me about gets discounted. Whether it's swine flu or Y2K it's almost always exaggerated or simply bogus. As I recall, it was Homeland Security that said I should be concerned about conservative veterans.

So, excuse me if I don't get my knickers in a twist.
 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,510
Thanked: 510
 
      05-12-2010
Quote:
Originally Posted by roban View Post
Good advice catilley. One should not depend on just one line of defense. In these days of Broadband the user has a responsibility to defend their own domain and few are willing to take this seriously and that is the hacker's delight. How many times I have provided the tools to my clients and how little they use them.

Why do I rant? My client's laziness is my mortgage payment
roban, it would be my guess that you live in a fine home, in a nice neighborhood. In your business, the work can't be exported, and it would be my guess that a fairly decent percentage of your work could have been avoided, if only your clients took the time to keep their security posture up to date. It would be safe to say that you have a lifetime job, just as Veedaz has. I wish the very best for you and your business venture.
Later,
Cat

Last edited by catilley1092; 05-12-2010 at 06:02 PM.. Reason: corrected spelling
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Apple, It's Not A Standard If It Only Works In Your Browser, And On The Mac Nibiru2012 Off-Topic Discussion 16 07-13-2010 06:35 AM
Hacker: Microsoft More Secure Than Apple, Adobe Nibiru2012 News 21 04-25-2010 07:11 PM


All times are GMT +1. The time now is 06:40 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33