Spyware Sucks
“There is no magic fairy dust protecting Macs" – Dai Zovi, author of “The Mac Hacker’s Handbook"

It gets worse – OS X vulnerability

February 21st 2006 in Uncategorized

Update: ICSAN says it is worse than first though:

“This actually looks more serious then we initially thought it is. The workaround specified above will prevent Safari from automatically executing the PoC file, but it looks like your machine is still vulnerable and it doesn’t need Safari to run this file at all.”

Original blog article:

Edit: Secunia have caught up 🙂

Richard Harper spotted this little nasty and sent a heads-up to a mailing list I monitor ….
“The demo attempts to open a Terminal window to display the contents of a folder.  If you are running Mac OS X in its standard configuration and use Safari, the window will open without waiting for a prompt. The […]

