DealsOnTheWeb Daily Deal: 8GB iPod Touch: $229 Delivered
Apple Releases Security Update To Address Help Viewer Exploit
by , 7:30 PM EDT, May 21st, 2004
Apple has released a security update to address the issue recently publicized by security firm Secunia. The vulnerability allows malicious scripts to be run just by getting someone to click a URL. The description of the update, which is called Security Update 2004-05-24, is sparse on details, merely saying that it updates HelpViewer, one of the weak links in the vulnerability. That description:
Security Update 2004-05-24 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components:
HelpViewer
TMO recommends that you install this update now. It weighs in at a mere 712 KB. For related information on the flaw, read our coverage about how the flaw was discovered and made public.
Observer Comments
Fri May 21, 2004 8:00 pm Subject: Apple Only Fixed After Media Spotlight
Fri May 21, 2004 9:59 pm Subject: Seems to Work...
OK just installed the update, checked some of the proof-of-concept sites, and didn't experience any scary behavior that was exhibited before the patch. At worst, Help Viewer is launched, but that's it. And for those that installed Paranoid Android, it still identifies, and allows you to cancel, the help:// URL access attempt.
Since this exploit didn't do any actual damage, the seems the net effect is some bad (and sometimes over-hyped) PR in some sectors, the creation or advertising of some nifty new tools, and a hopeful raising of awareness of how malware works. Good thing we don't (yet?) have to worry about those nasty network-based viruses that tend to cripple the Internet and institutional networks.
We now return you to your regularly scheduled Mac experience...
Sat May 22, 2004 9:50 am Subject: Seems to be a popular type of exploit
http://securityresponse.symantec.com/avcenter/security/Content/10321.html
I suppose hackers that see this vulnerability on one platform will try to exploit it on others as well.
What I'm having trouble understanding is the date of the update. It's dated two days from now ("now" being the 22nd of May, 2004).
Could May the 24th be the intended release date for 10.3.4?
Just a stirrin' up the speculation!
won
Sat May 22, 2004 10:09 am Subject: Help viewer fix-Earlier Panther & Jaguar versions?
Sat May 22, 2004 12:51 pm Subject: Re: Help viewer fix-Earlier Panther & Jaguar versions?
I type on behalf of those who won't or can't perform Apple's latest update.
I just noticed that RCDefaultApp's settings only apply to the current user when set, even if that user account is admin.
If more than one person is logged in but the admin user has only disabled the troublesome handlers from the admin account and one of the users has been to a compromised webpage that autoloads (inhale), I presume that user's account gets hoz0red.
In the background.
Unbeknownst to everybody until that user tries to login.
I suppose I'd recommend making sure you protect each account individually. In other words, log into each account on your machine and set the settings separately.
What settings? Why, these settings:
http://daringfireball.net/2004/05/unsafe_uri_handlers
and
http://daringfireball.net/2004/05/telnet_protocol
My theory may be flawed but I don't know where...
won
Sat May 22, 2004 3:23 pm Subject: Apple's patch doesn't fix the problem, just one symptom
Sat May 22, 2004 4:25 pm Subject: Another Half-Baked Apple Solution
Sat May 22, 2004 4:28 pm Subject: still vulnerable
As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory. I applied Apple's patch and this still happens. Also, this is not limited to Safari, as it also worked in Firefox 0.8 and IE 5.2.3. Firefox and IE mounted the disk image, but initially stated they were unable to resolve the protocol for "malware:unused" nor was the app on the image launched (no "owned.txt" created). However, on reload, the exploit worked, just as the text in the page stated. A simple meta refresh in an offending page would have made it work.
The patch appears to have only updated the Help Viewer application. Note that Help Viewer is never launched nor does the disk image download appear in the download manager for any of the browsers used. The disk image is mounted directly from the http:/209.152.175.64/unlinkedCrap/osxMalware.dmg address, (using the OS' ability to mount images directly from an http address) thus removing the "Open 'safe' files after downloading" option in Safari does nothing to stop this.
Sat May 22, 2004 6:44 pm Subject: All smoke with no fire
Quotereznorb5 wrote:
As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory.
ermm..no, can't say it does actually. Exploit worked before I applied the patch and now it doesn't. I'm happy with that. (Using 10.2.8)
I always had a problem with this being a 'dangerous' exploit anyway, The help viewer or disc image mounter appears unexpectedly giving a BIG clue that something isn't quite right and despite all the 'well it could be done' there wasn' t any suggestion of how harm could be done reliably what with varying download locations and spaces not working with the command.
I would guess Apple had seen that yes this was an embarrasing flaw but not one that could do any reliable harm to a significant number of users. I'll remain a smug mac user with no OS X viruses (I'm ignoring that daft trojan recently given media coverage).
Mon May 24, 2004 5:03 am Subject: All smoke with no fire
QuoteDrD wrote:Quotereznorb5 wrote:
As pointed out by "Guest", loading this address http://www.geekspiff.com/unlinkedCrap/innocousPage.html still allows the owned.txt to be created in your home directory.
ermm..no, can't say it does actually. Exploit worked before I applied the patch and now it doesn't. I'm happy with that. (Using 10.2.8)
.
Hit reload in the page once or twice. It will.
Actually, they don't. On my system, running 10.2.8, their 'benign sample exploit' does nothing, no matter how many times I refresh. It doesn't after patching, and it didn't before patching, because I disabled Help's ability to run Applescripts. Their 'benign sample exploit 2, however, demonstrates some interesting behaviour: it launches my default FTP protocol helper, Fetch (because the Finder *SUCKS BALLS* at FTP), and displays the contents of the OSXMalware.app package.
Recent Headlines - Updated Friday, May 16th, 2008
- Fri., 8:00 PM
- iPodObserver - Dr, Danger, Brickfilms, Narnia and More
- 5:10 PM
- StrangeCharm - Explosions and Debris (Week of May 12)
- 4:15 PM
- TMO's DealsOnTheWeb.com - 8GB iPod Touch: $229 Delivered
- 3:35 PM
- Safari Suffers from "Carpet Bomb" Issue
- 2:55 PM
- iPodObserver - Barack Obama's Smartphone of Choice
- 2:35 PM
- Parallels Releases Update for Vista SP1 and XP SP3
- 1:00 PM
- iPodObserver - AT&T: Back to Three iPhone Limit Per Customer
- 12:55 PM
- Mac Gaming News - Macgamestore Intros Agatha Christie: Peril at End House
- 10:35 AM
- Hot Forum Topic - The iPhone's Growing Global Reach
- 10:05 AM
- Unparsed - I found Those Missing iPhones!
- 9:45 AM
- Fone2Phone 2.01 Improves Performance, Cell Phone Support
- 9:20 AM
- Apple Scores 2 Black Pencils at D&AD Awards
- 8:40 AM
- Yahoo to Icahn: Get a Clue
- 8:05 AM
- iPodObserver - Orange Gets Europe, Middle East, Africa iPhone Deal
- 7:30 AM
- TMO Quick Tip - Quick Look: Web Archives
The Mac Observer Reader Specials
- Download Typestyler, still the Ultimate Styling Tool for Internet, Print and Video Graphics. Works great in Classic with a Native OS X Version on the way. Free Tryout: www.typestyler.com
- Other World Computing: Power up your PowerMac G4! Make you trusty PowerMac G4 like new again with up to 2.0GHz Processor Power. G4/1.2GHz for $199, Dual 1.8GHz $498, & More Plug & Play for like new A-OK for OS 9 & OS X, etc.
NEW MacPro Memory 800Mhz With Apple Spec Heat Sink 2GB Kit $104 / 4GB Kit $184 / 8GB Kit $362 Click to Maximize your Macs...
Mac observers can now play Party Poker for Mac as well as Mac casino games by going to MacPokerOnline.com.For the latest Apple products use Ciao a comparison website to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate cell phones.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

