Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > OSX and Hackint0sh/OSX86 > OSX Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-15-2009, 02:44 PM
sam's Avatar
sam
Status: Offline
Chief of Administration
iPhone Dev Team
 
Join Date: Jun 2007
Posts: 1,336
Rep Power: 10
sam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond reputesam has a reputation beyond repute
Default Security Vulnerability Found in Safari RSS

Open source programmer Brian Mastenbrook has discovered a security flaw in the way that Safari handles RSS feeds. The vulnerability, which affects both Mac and Windows versions of Safari, could allow a malicious website to gain access to sensitive user data.

I have discovered that Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention. This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites. The vulnerability has been acknowledged by Apple.

Mastenbrook reports that all OS X 10.5 Leopard users, regardless of whether they use Safari or RSS feeds, should protect themselves by choosing an application other than Safari for reading RSS feeds, an option available in the "RSS" tab of Safari's Preferences. Safari for Windows users should utilize a different browser until Apple issues a patch. Mastenbrook, who has received credit from Apple for reporting a number of security issues over the past year, says that Apple has not given a timeframe for a fix.
__________________
If you just want to support hackint0sh.org with a donation click here.
Follow me on twitter: http://twitter.com/sam_hackint0sh
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
MacRumors: Security Vulnerability Found in Safari RSS hackint0sh Latest Headlines 0 01-13-2009 07:20 PM
MacRumors: Apple Releases Safari 3.2 with Improved Security, Anti-Phishing hackint0sh Latest Headlines 0 11-14-2008 12:00 AM
MacNN: Safari 3.1.2 fixes critical security flaws hackint0sh Latest Headlines 0 07-01-2008 01:20 AM
Slashdot: Apple Fixes Safari "Carpet Bomb" Windows Vulnerability hackint0sh Latest Headlines 0 06-20-2008 03:50 PM
iPhone "registered" with overseas network (was: Total Unlock of iPhone is done) ozbimmer Turbo-, Supersim and Simcloning Solution 475 08-25-2007 10:47 AM



All times are GMT +2. The time now is 07:17 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105