Exploit May Cause Safari To Toss Its Cookies
November 25th, 2003 at 2:00 PM - Mac OS by Daniel Miller
The information technology security company, Secunia, has released an advisory about a vulnerability in Safari, Appleis Web browser. The exploit can be used remotely to trick the browser into sending a useris private cookie information for a website. Cookies are bits of information stored on a personis computer that are pertinent to that specific person. Their main purpose is to identify visitors so a certain Web site can be customized for them. From the Secunia advisory page:
A vulnerability has been reported in Apple Safari, which can be exploited by malicious people to steal a useris cookies. The vulnerability is caused due to an error when handling URLs. This can be exploited to disclose a useris cookie information for an arbitrary website by including a NULL character ("") in the URL. The vulnerability has been reported in versions 1.0 (v85) through 1.1 (v100.1).
The vulnerability carries a threat level of 4 on a scale of 1-5. That level is characterized by the existence of easy to exploit flaws, no solutions being available, no public awareness or workarounds requiring high technical skills, and the exploit being out "in the wild."
Secunia suggests using another browser to avoid being exposed to the security hazard.
Recent Headlines - Updated March 11th
- Thu, 12:16 PM
- Product News - SiteGrinder 3 Offers 300+ New Features for Photoshop Web Dev
- 11:16 AM
- TMO Appearances - Ted Landau Discusses Tethering, Google Voice on MacNotables
- 10:45 AM
- News - Apple Tops Consumer Reports Customer Service Survey
- 10:19 AM
- Hot Forum Topic - Reader Discussion: Ramping Up for iPad Pre-orders
- 9:16 AM
- TMO Appearances - TMO’s Jeff Gamet Shares Cool iPhone Apps at CoMUG
- 8:44 AM
- News - Court to EMI: Don’t Break Up Floyd
- 8:16 AM
- Product News - Metron 2 Adds Rhythm Patterns, More
- Wed, 4:54 PM
- iPad - Amazon, Google, Dell to Take on iPad With Dell Streak Tablet
- 4:04 PM
- Games - Mac Version of Fallen Earth MMO Enters Open Beta
- 3:56 PM
- Ted Landau's User Friendly View - iPhone Internet Tethering and the iPad
- 3:31 PM
- iPhone - Stanford Survey Finds iPhone Addicting
- 3:01 PM
- News - Bing Takes Search Traffic Share at Yahoo’s Expense
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
Mac Memory and Hard Drives: MacBook Pro Memory 8GB kits $349.99! iMac Memory 4GB DDR Kits for $109.99! Mac Pro Memory 4GB Kits for $135.99! Mac Hard Drives 1.5TB Seagate SATA II for $147.99! Click Here!
- CarMD Handheld Device & Mac/PC Software System saves you time and money on car maintenance and repair. Buy at www.CarMD.com! Save $10 with code TMO2.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.


Refurbished MacBook Air 1.6GHz Intel Core 2 Duo $1099.00 Delivered
