This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Safari attack code released...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Safari 'carpet bomb' attack code released
- http://preview.tinyurl.com/65fe66
June 10, 2008 (Computerworld) - "A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers. The source code, along with a demo of the attack, was posted Sunday on a computer security blog. It can be used to run unauthorized software on a victim's machine, and could be used by criminals in Web-based computer attacks… the vulnerability has to do with the way Windows handles desktop executables and recommended that Windows users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple." The attack affects all versions of Windows XP and Vista, Microsoft said in its advisory*…"

- http://isc.sans.org/diary.html?storyid=4562
Last Updated: 2008-06-12 11:22:32 UTC
…Since the proof of concept is easily available, if you are using Safari on Windows please change the default download location as described in Microsoft's advisory available at
* http://www.microsoft.com/technet/security/…ory/953818.mspx

:ph34r:
FYI…

Safari version 3.1.2…
- http://blog.washingtonpost.com/securityfix…afari_on_1.html
June 19, 2008 - "Apple today pushed out a new version of its Safari browser for Microsoft Windows users. The latest iteration plugs at least four security holes, including one that allowed automatic downloading of files to the Windows desktop. In some cases, these files could be started without the user's knowledge. Safari version 3.1.2 corrects a flaw, which allows any rogue Web site to "carpet bomb" the user's Windows Desktop… The new version is available from Apple Downloads* …"
* http://www.apple.com/support/downloads/
"This update is recommended for all Safari Windows users and includes stability improvements and the latest security updates."

- http://secunia.com/advisories/30775/
Release Date: 2008-06-20
Critical: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: Safari for Windows 3.x …
Solution: Update to version 3.1.2 …
Original Advisory: Apple:
http://support.apple.com/kb/HT2092

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2540

:ph34r: