The Mac Observer

Skip navigational links

DealsOnTheWeb Daily Deal: 8GB iPod Touch: $229 Delivered

Additional Details Emerge About Mac Hack

by , 3:10 PM EDT, April 25th, 2007

Additional details have been posted about the Macintosh compromise discovered last week at the CanSecWest 2007 Conference. The exploit involves a Java-enabled Browser plus QuickTime and was documented at the Secunia Website on Tuesday.

Without disclosing the "how," Mr. Dino Dai Zovi who was the developer of a prize winning exploit of Mac OS X -- when connected to an external URL via Safari -- posted formal information about the exploit.

"The vulnerability is caused due to an unspecified error within the Java handling in QuickTime. This can be exploited to execute arbitrary code when a user visits a malicious web site using a Java-enabled browser e.g. Safari or Firefox," the advisory said.

The severity was rated as "Highly Critical." The advisory noted that other Browsers and platforms may also be affected.

Observer Comments

Show: Subjects Only | Full Comments
Close Name:brett_x Posts: 307 Joined: 24 Jan 2006
Subject:

Quote
The advisory noted that other Browsers and platforms may also be affected.
.... but they wouldn't get any press, so why bother mentioning them.

View Name:Guest
Subject: Why "Highly Critical?"
Close Name:gslusher Posts: 2004 Joined: 13 Nov 2002
Subject: Highly Critical?

Quote
Guest wrote:
My understanding of the exploit is that it gives a remote user logged-in user priviliges, not root. Why would that be highly critical?


It might allow the perpetrator to do damage--overwriting files, for example. It's yet another reason that a lot of experts advise running in a "standard" user mode, rather than administrator mode.

Close Name:Rainy Day Posts: 607 Joined: 07 Jun 2005
Subject: Turn off Java

I have long viewed Java as a security risk and always keep it turned off. Very few websites use it.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Wednesday, May 21st, 2008

Wed., 4:50 PM
Editorial - Apple's Curious Failure to Act Against Psystar
4:35 PM
AAPL Down Dramatically for No Obvious Reasons
4:15 PM
SpamSieve 2.7 Improves Handling of Attachments, URLs, HTML
3:45 PM
User Friendly Blog by Ted Landau - Apple's unsupported support articles
2:50 PM
Apple's Purchase of PA Semi Under Review by DoD
2:15 PM
iPodObserver - AT&T Nears Completion of Full 3G/HSPA Technology
1:35 PM
C|Net: Apple's .Mac Missing a Golden Opportunity
12:25 PM
Apple Posts Extended Version of "Sad Song" Get a Mac Ad
11:10 AM
Report: Apple to Move Entire MacBook Line to LED by 2009
10:55 AM
Man & Machine Sues Apple For "Mighty Mouse" Trademark Infringement
10:30 AM
TMO's DealsOnTheWeb.com - HP Officejet Pro L7590 Flatbed All-In-One: $199.99 Delivered
10:10 AM
Western Digital Targets "My Passport" Portable Drives at Mac Users
9:00 AM
iPodObserver - Phishing Scheme Fakes iTunes for Bait
7:30 AM
TMO Quick Tip - One-click File Name Copying
 

The Mac Observer Reader Specials

Apple Stock Quote

  • AAPL: $178.19. Change Today: -7.71.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb