AplusWebMaster
Topic Starter
FYI…
Safari 'carpet bomb' attack code released
- http://preview.tinyurl.com/65fe66
June 10, 2008 (Computerworld) - "A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers. The source code, along with a demo of the attack, was posted Sunday on a computer security blog. It can be used to run unauthorized software on a victim's machine, and could be used by criminals in Web-based computer attacks… the vulnerability has to do with the way Windows handles desktop executables and recommended that Windows users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple." The attack affects all versions of Windows XP and Vista, Microsoft said in its advisory*…"
- http://isc.sans.org/diary.html?storyid=4562
Last Updated: 2008-06-12 11:22:32 UTC
…Since the proof of concept is easily available, if you are using Safari on Windows please change the default download location as described in Microsoft's advisory available at
* http://www.microsoft.com/technet/security/…ory/953818.mspx

Safari 'carpet bomb' attack code released
- http://preview.tinyurl.com/65fe66
June 10, 2008 (Computerworld) - "A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers. The source code, along with a demo of the attack, was posted Sunday on a computer security blog. It can be used to run unauthorized software on a victim's machine, and could be used by criminals in Web-based computer attacks… the vulnerability has to do with the way Windows handles desktop executables and recommended that Windows users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple." The attack affects all versions of Windows XP and Vista, Microsoft said in its advisory*…"
- http://isc.sans.org/diary.html?storyid=4562
Last Updated: 2008-06-12 11:22:32 UTC
…Since the proof of concept is easily available, if you are using Safari on Windows please change the default download location as described in Microsoft's advisory available at
* http://www.microsoft.com/technet/security/…ory/953818.mspx