| OS X - Operating System General OS operation information and support |
| Post Reply | New Thread | Subscribe |
|
|
Thread Tools |
![]() Member Since: Nov 12, 2004
Location: Lancashire, UK
Posts: 356
![]() Mac Specs: MacMini DC 1.66, Powerbook G4
|
http://isc.incidents.org/diary.php?storyid=1138
Thoughts? I understand the first part, but can someone explain the second part please of how this still makes a machine vulnerable without needing Safari? I ask this because surely the user would have to decompress the file to begin with, and if the file is from a suspicious/malicious site, then a user would not choose to unzip it ? Also, does OSX not give you a warning when you are unzipping a file if there are commands in it? Last edited by Kyomii; 02-21-2006 at 06:13 AM. |
| QUOTE Thanks | |
![]() Member Since: Jun 27, 2005
Location: In the mac store and at home on my iMac
Posts: 1,165
![]() |
Mac Pro (Early 2009) 8 Core 2.26 GHz, 6 GB Ram, 640 GB Drive. Dell 2408WFP. |
| QUOTE Thanks | |
![]() Member Since: Nov 12, 2004
Location: Lancashire, UK
Posts: 356
![]() Mac Specs: MacMini DC 1.66, Powerbook G4
|
Quote:
Yes, I agree. I always have mine unticked too. However, they are saying, even if it is unchecked in Safari that it still presents a serious risk in the updated part, as it does not require Safari to run. Just wanted to know in layman's terms what they are trying to say in the second part of the report as I can see the vulnerability, but the method behind it (having to uncompress a suspect file) is unlikely to happen too much - unless users are in the habit of uncompressing suspect files perhaps? |
|
| QUOTE Thanks | ||
|
Guest
Posts: n/a
|
This is just a reflection of Safari autohandleing certain file types automatically near as I can tell.
This was corrected for default behavior with the whole widget fiasco. If someone has safari (or other app) set to autohandle the file there is a risk. Further as near as I can tell you can have a script autorun on unzipping of the file, this might not be the wisest of things to allow a zip file to do without warning. If that is the case then it is "as designed" but is a potential problem. |
| QUOTE Thanks | |
|
Guest
Posts: n/a
|
You guys are missing the severity of this:
Taken from link: Quote:
|
|
| QUOTE Thanks | ||
![]() Member Since: Jan 08, 2005
Location: New Jersey
Posts: 6,190
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Mac Specs: Mac Pro 8x3.0ghz 12gb ram 8800GT , MBP 2.16 2GB Ram 17 inch.
|
Quote:
|
|
| QUOTE Thanks | ||
|
Guest
Posts: n/a
|
Quote:
I can show them how to protect themselves, the fact is they won't. I can lead the horse to water, **** I can toss it in. But unless I ram a feeding tube down it's throat or stick it with an IV, 90% of the time it's not going to take a drink. |
|
| QUOTE Thanks | ||
![]() Member Since: Mar 30, 2004
Location: USA
Posts: 4,744
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Mac Specs: 12" Apple PowerBook G4 (1.5GHz)
|
Quote:
|
|
| QUOTE Thanks | ||
|
Guest
Posts: n/a
|
The code activates and runs in the Terminal; it does not run in Safari. Deselecting the open safe files option does not prevent downloading the malicious file; it only prevents it from being automatically opened. And it does not stop Mail or other programs from opening the file. You can prevent the code from running by simply renaming the Terminal to something else like myTerminal. Macintouch has posted a link to a non-harmful example to test your system.
|
| QUOTE Thanks | |
![]() Member Since: Jan 08, 2005
Location: New Jersey
Posts: 6,190
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Mac Specs: Mac Pro 8x3.0ghz 12gb ram 8800GT , MBP 2.16 2GB Ram 17 inch.
|
It would be productive to do that, but how many people who want to make their own applicatoin with their own icon would get annoyed by the fact that there is going to be a badge over it?
|
| QUOTE Thanks | |
|
Guest
Posts: n/a
|
Quote:
|
|
| QUOTE Thanks | ||
|
Guest
Posts: n/a
|
Quote:
Renamed /applications/utilities/Terminal.app to _Terminal.app Create a workflow containing: Ask for Confirmation Launch Application In the Ask for Confirmation, say something like Are you sure you wish to launch the Terminal? Give the security reasons why. Launch application - > Point to _Terminal.app Save the workflow as an application called Terminal.app in /applications/utilities Now whenever /applications/utilities/Terminal.app is called, it will request your permission. |
|
| QUOTE Thanks | ||
| Post Reply | New Thread | Subscribe |
| Thread Tools | |
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
|
|||||||
Thread |
Thread Starter |
Forum |
Replies |
Last Post |
| having some serious issues... | speedydave | Apple Notebooks | 3 | 09-12-2005 04:53 PM |
| Critical Flaw Found in Firefox | IChing | OS X - Operating System | 0 | 05-09-2005 06:37 PM |
| HELP!! Installing OSX was tough, But NOW I'm hosed | Aloel | OS X - Operating System | 8 | 04-23-2005 07:13 PM |
| Broken Disk Drive but Want to Upgrade to OSX...Impossible? | mariamarchita | OS X - Operating System | 3 | 02-27-2005 01:52 PM |
| printing PostScript with OSX | davidp158 | OS X - Operating System | 9 | 02-09-2005 08:56 PM |
All times are GMT -4. The time now is 11:28 AM.
Powered by vBulletin