AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1138
Last Updated: 2006-02-21 09:32:13 UTC
"…Serious vulnerability has been found in Apple Safari on OS X. "In its default configuration shell commands are execute[d] simply by visting a web site - no user interaction required." This could be really bad. Attackers can run shell scripts on your computer remotely just by visiting a malicious website…
The problem is due to a feature that is activated by default: Open Safe Files after downloading. A zip file is considered safe and so they will be opened automatically. Subsequently, a shell script with no #! at the beginning of the script will be executed automatically. No user interaction!
Recommended action: disable the option "Open 'safe' files after downloading" in the "General" preferences section in Safari.
Update:
This actually looks more serious then we initially thought it is. The workaround specified above will prevent Safari from automatically executing the PoC file, but it looks like your machine is still vulnerable and it doesn't need Safari to run this file at all…"
- http://secunia.com/advisories/18963/
Release Date: 2006-02-21
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
OS: Apple Macintosh OS X …
Description:
…Vulnerability in Mac OS X, which can be exploited by malicious people to compromise a user's system.
Solution:
The vulnerability can be mitigated by disabling the "Open safe files after downloading" option in Safari.
Do not open files in ZIP archives originating from untrusted sources…"

- http://isc.sans.org/diary.php?storyid=1138
Last Updated: 2006-02-21 09:32:13 UTC
"…Serious vulnerability has been found in Apple Safari on OS X. "In its default configuration shell commands are execute[d] simply by visting a web site - no user interaction required." This could be really bad. Attackers can run shell scripts on your computer remotely just by visiting a malicious website…
The problem is due to a feature that is activated by default: Open Safe Files after downloading. A zip file is considered safe and so they will be opened automatically. Subsequently, a shell script with no #! at the beginning of the script will be executed automatically. No user interaction!
Recommended action: disable the option "Open 'safe' files after downloading" in the "General" preferences section in Safari.
Update:
This actually looks more serious then we initially thought it is. The workaround specified above will prevent Safari from automatically executing the PoC file, but it looks like your machine is still vulnerable and it doesn't need Safari to run this file at all…"
- http://secunia.com/advisories/18963/
Release Date: 2006-02-21
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
OS: Apple Macintosh OS X …
Description:
…Vulnerability in Mac OS X, which can be exploited by malicious people to compromise a user's system.
Solution:
The vulnerability can be mitigated by disabling the "Open safe files after downloading" option in Safari.
Do not open files in ZIP archives originating from untrusted sources…"