The Mac Observer

Skip navigational links

DealsOnTheWeb Daily Deal: 8GB iPod Touch: $229 Delivered

Apple Releases Security Update To Address Help Viewer Exploit

by , 7:30 PM EDT, May 21st, 2004

Apple has released a security update to address the issue recently publicized by security firm Secunia. The vulnerability allows malicious scripts to be run just by getting someone to click a URL. The description of the update, which is called Security Update 2004-05-24, is sparse on details, merely saying that it updates HelpViewer, one of the weak links in the vulnerability. That description:

Security Update 2004-05-24 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:

HelpViewer

TMO recommends that you install this update now. It weighs in at a mere 712 KB. For related information on the flaw, read our coverage about how the flaw was discovered and made public.

Observer Comments

Show: Subjects Only | Full Comments
View Name:RealityCheck -   Troll Posts: 392 Joined: 06 May 2004
Subject: Apple Only Fixed After Media Spotlight
View Name:Guest
Subject: RC
View Name:Guest
Subject: Get over yourself!
Close Name:John F. Braun -   TMO Staff Posts: 227 Joined: 11 Jun 2001
Subject: Seems to Work...

OK just installed the update, checked some of the proof-of-concept sites, and didn't experience any scary behavior that was exhibited before the patch. At worst, Help Viewer is launched, but that's it. And for those that installed Paranoid Android, it still identifies, and allows you to cancel, the help:// URL access attempt.

Since this exploit didn't do any actual damage, the seems the net effect is some bad (and sometimes over-hyped) PR in some sectors, the creation or advertising of some nifty new tools, and a hopeful raising of awareness of how malware works. Good thing we don't (yet?) have to worry about those nasty network-based viruses that tend to cripple the Internet and institutional networks.

We now return you to your regularly scheduled Mac experience...

View Name:Guest
Subject:
View Name:Guest
Subject: Oh how terrible!
View Name:Guest
Subject:
View Name:Guest
Subject: Paranoid Android and the Help Veiwer
Close Name:won Posts: 20 Joined: 01 Sep 2003
Subject: Seems to be a popular type of exploit

http://securityresponse.symantec.com/avcenter/security/Content/10321.html

I suppose hackers that see this vulnerability on one platform will try to exploit it on others as well.

What I'm having trouble understanding is the date of the update. It's dated two days from now ("now" being the 22nd of May, 2004).

Could May the 24th be the intended release date for 10.3.4?

Just a stirrin' up the speculation!



won

View Name:Guest
Subject: Help viewer fix-Earlier Panther & Jaguar versions?
Close Name:deasys Posts: 243 Joined: 08 Apr 2003
Subject: Re: Help viewer fix-Earlier Panther & Jaguar versions?

"I'm running 10.3.1, since I don't want my Palm synching to break."

I'm syncing my Palm just fine under 10.3.3.

Close Name:won Posts: 20 Joined: 01 Sep 2003
Subject: Re; RCDefaultApp

I type on behalf of those who won't or can't perform Apple's latest update.

I just noticed that RCDefaultApp's settings only apply to the current user when set, even if that user account is admin.

If more than one person is logged in but the admin user has only disabled the troublesome handlers from the admin account and one of the users has been to a compromised webpage that autoloads (inhale), I presume that user's account gets hoz0red.

In the background.

Unbeknownst to everybody until that user tries to login.

I suppose I'd recommend making sure you protect each account individually. In other words, log into each account on your machine and set the settings separately.

What settings? Why, these settings:

http://daringfireball.net/2004/05/unsafe_uri_handlers

and

http://daringfireball.net/2004/05/telnet_protocol


My theory may be flawed but I don't know where...



won

View Name:Guest
Subject: Apple's patch doesn't fix the problem, just one symptom
View Name:RealityCheck -   Troll Posts: 392 Joined: 06 May 2004
Subject: Another Half-Baked Apple Solution
Close Name:reznorb5 Posts: 23 Joined: 24 Mar 2003
Subject: still vulnerable

As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory. I applied Apple's patch and this still happens. Also, this is not limited to Safari, as it also worked in Firefox 0.8 and IE 5.2.3. Firefox and IE mounted the disk image, but initially stated they were unable to resolve the protocol for "malware:unused" nor was the app on the image launched (no "owned.txt" created). However, on reload, the exploit worked, just as the text in the page stated. A simple meta refresh in an offending page would have made it work.

The patch appears to have only updated the Help Viewer application. Note that Help Viewer is never launched nor does the disk image download appear in the download manager for any of the browsers used. The disk image is mounted directly from the http:/209.152.175.64/unlinkedCrap/osxMalware.dmg address, (using the OS' ability to mount images directly from an http address) thus removing the "Open 'safe' files after downloading" option in Safari does nothing to stop this.

View Name:Guest
Subject:
Close Name:DrD Posts: 40 Joined: 28 Apr 2003
Subject: All smoke with no fire

Quote
reznorb5 wrote:
As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory.


ermm..no, can't say it does actually. Exploit worked before I applied the patch and now it doesn't. I'm happy with that. (Using 10.2.8)

I always had a problem with this being a 'dangerous' exploit anyway, The help viewer or disc image mounter appears unexpectedly giving a BIG clue that something isn't quite right and despite all the 'well it could be done' there wasn' t any suggestion of how harm could be done reliably what with varying download locations and spaces not working with the command.

I would guess Apple had seen that yes this was an embarrasing flaw but not one that could do any reliable harm to a significant number of users. I'll remain a smug mac user with no OS X viruses (I'm ignoring that daft trojan recently given media coverage).

Close Name:dynamicv Posts: 51 Joined: 06 May 2004
Subject: Palm synching

works fine for me under 10.3.3. Try re-installing Palm Desktop.

Close Name:reznorb5 Posts: 23 Joined: 24 Mar 2003
Subject: All smoke with no fire

Quote
DrD wrote:
Quote
reznorb5 wrote:
As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory.


ermm..no, can't say it does actually. Exploit worked before I applied the patch and now it doesn't. I'm happy with that. (Using 10.2.8)
.


Hit reload in the page once or twice. It will.

Close Name:otter Posts: 2 Joined: 19 May 2004
Subject:

Actually, they don't. On my system, running 10.2.8, their 'benign sample exploit' does nothing, no matter how many times I refresh. It doesn't after patching, and it didn't before patching, because I disabled Help's ability to run Applescripts. Their 'benign sample exploit 2, however, demonstrates some interesting behaviour: it launches my default FTP protocol helper, Fetch (because the Finder *SUCKS BALLS* at FTP), and displays the contents of the OSXMalware.app package.

View Name:Guest
Subject: Poor RC!
Close Name:Billy K Posts: 297 Joined: 06 May 2004
Subject: That was quick

I don't pay much attention to these things (cause I don't own a Windows box - I don't have to!), but I've never, ever noticed a fix for an exploit come out so quickly after it was identified.

Kudos, Apple. I'm glad to see they take so much pride in OSX's reputation.

View Name:Guest
Subject: Another Microsoft "First"
Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, May 16th, 2008

Fri., 8:00 PM
iPodObserver - Dr, Danger, Brickfilms, Narnia and More
5:10 PM
StrangeCharm - Explosions and Debris (Week of May 12)
4:15 PM
TMO's DealsOnTheWeb.com - 8GB iPod Touch: $229 Delivered
3:35 PM
Safari Suffers from "Carpet Bomb" Issue
2:55 PM
iPodObserver - Barack Obama's Smartphone of Choice
2:35 PM
Parallels Releases Update for Vista SP1 and XP SP3
1:00 PM
iPodObserver - AT&T: Back to Three iPhone Limit Per Customer
12:55 PM
Mac Gaming News - Macgamestore Intros Agatha Christie: Peril at End House
10:35 AM
Hot Forum Topic - The iPhone's Growing Global Reach
10:05 AM
Unparsed - I found Those Missing iPhones!
9:45 AM
Fone2Phone 2.01 Improves Performance, Cell Phone Support
9:20 AM
Apple Scores 2 Black Pencils at D&AD Awards
8:40 AM
Yahoo to Icahn: Get a Clue
8:05 AM
iPodObserver - Orange Gets Europe, Middle East, Africa iPhone Deal
7:30 AM
TMO Quick Tip - Quick Look: Web Archives
 

The Mac Observer Reader Specials

Apple Stock Quote

  • AAPL: $187.6201. Change Today: -2.1099.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb