On UrbanBaby: Nanny vs. Daycare. Discuss!
BNET Business Network:
BNET
TechRepublic
ZDNet

May 20th, 2008

Apple under pressure to fix Safari 'carpet bomb' flaw

Posted by Ryan Naraine @ 10:37 am

Categories: Apple, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Responsible disclosure, Spyware and Adware, Vulnerability research

Tags: Apple Safari, Apple Inc., Flaw, Google-backed StopBadware.org Coalition, Security, Spyware, Adware & Malware, Instant Messaging, Cyberthreats, Internet, Online Communications

Apple under pressure to fix Safari ‘carpet bombing’ flawThe Google-backed StopBadware.org coalition has called on Apple to rethink its stance on whether the Safari “carpet bomb” issue reported by Nitesh Dhanjani constitutes a serious security risk.

Dhanjani originally discovered than it is possible for a booby-trapped Web site to litter the user’s Desktop (Windows) or Downloads directory (~/Downloads/ in OSX) with executables masquerading as legitimate icons.

“This can happen because the Safari browser cannot be configured to obtain the user’s permission before it downloads a resource. Safari downloads the resource without the user’s consent and places it in a default location (unless changed),” Dhanjani said, warning that it could be used as a drive-by malware distribution mechanism.

[ See Nate's post for background ]

Apple has classified Dhanjani’s findings as more of an annoyance than a security risk that requires an immediate patch.

In the eyes of Apple’s security team,  the user (target) would have to be complicit in an attack that causes a sufficiently high number of files to be downloaded.  “It presents a risk of annoyance, at worst, [and] can be easily stopped by closing the browser.”

A source tells me that Apple will fix the issue in Safari 3.2, which is slated for release in the summer (September) this year.

However, StopBadware.org, a non-profit managed by Harvard Law School’s Berkman Center for Internet & Society and Oxford University’s Oxford Internet Institute, wants Apple to create and distribute a fix to protect end users.

StopBadware.org researcher Laureli Mallek writes:

StopBadware.org believes that users should have control over software being downloaded to their computers, and we encourage Apple to reconsider its stance and treat this as the security issue that it is.

The good news is that Apple will fix Safari’s handling of these types of issues as an enhancement for a future release. However, if we start seeing in-the-wild exploits using carpet-bombed desktop icons to trick users into installing malilcious executables, then Apple’s delay will be hard to justify.

In the meantime, Safari users — and all Web surfers — should always very careful about clicking on untrusted links that arrive via e-mail or instant messaging communications.

* Photo credit: aditza121’s Flickr photostream (Creative Commons 2.0).

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 55 Talkback(s)
Fatal Flaw
Final note: Apple has a very strong brand image to uphold. Fixing issues in Safari would only benefit its end-users, and therefore strengthen its customer loyalty.

http://www.mbridge.com... (Read the rest)
Posted by: MBridge llc Posted on: 06/07/08 You are currently: a Guest | | Terms of Use
The problem with this one is  nmcfeters | 05/20/08
Except that  frgough | 05/20/08
I totally disagree  nmcfeters | 05/20/08
I don't know.....  James Quinn | 05/21/08
But how likely is it...  James T. Kirk | 05/20/08
Not to mention...  bigsibling | 05/21/08
Didn't this happen in other browsers before?  LinuxGuy06 | 05/21/08
Come on dude...  jasonp@... | 05/21/08
Oh close the browser?? Thx for the tip!  tikigawd | 05/21/08
Directly Attackable?  1macgeek | 05/21/08
Read the above  blazer044@... | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  s_southern | 05/20/08
Agreed  nmcfeters | 05/20/08
But why?  1macgeek | 05/21/08
market share.  rtk | 05/21/08
Not really  markdoc.geo | 05/21/08
re:Not really  richdave | 05/21/08
true, but...  devin6687 | 05/21/08
As a long time Mac user  Marcos El Malo | 05/29/08
Here, here!  Bugbyte | 06/03/08
Or Intel for that matter  klumper | 05/20/08
"10 and beyond" = 10 GHz + (nt)  klumper | 05/20/08
The Stupid Part  Kaiwai | 05/20/08
I agree it's stupid, and it's the first thing I turn off, but...  olePigeon | 05/20/08
It is stupid, and should be off by default  Kaiwai | 05/20/08
Not sure what you're talking about  Richard Flude | 05/20/08
Question: How does it know it's "safe?" (nt)  tikigawd | 05/21/08
Identified by file type  Richard Flude | 05/21/08
And that's my point  tikigawd | 05/22/08
Two red flags sometimes aren't enough  p0figster | 05/21/08
really?  abrli | 05/30/08
This is just painful  odubtaig | 05/20/08
They'll figure it out...  bigsibling | 05/21/08
True  tikigawd | 05/21/08
RE: True  silent.griffin | 05/21/08
Real simple  tonymcs@... | 05/20/08
Even simpler  NonZealot | 05/21/08
Better Yet  fde101 | 05/21/08
Amazing  tikigawd | 05/21/08
What company is?  Raymond Danner | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  ceo@... | 05/21/08
Sorry your not in Kansas any more  tech_walker | 05/21/08
So called reasonable...  arminw | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  JoeB2 | 05/21/08
This looks like an over-reaction.  markdoc.geo | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  asaverio@... | 05/21/08
Right, Apple is not...  arminw | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  john@... | 05/22/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  spinin | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  phatkat | 05/21/08
Safari's engine  Richmedia | 05/21/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  kryz42 | 06/02/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  Ceridan | 06/03/08
RE: Apple under pressure to fix Safari 'carpet bomb' flaw  MBridge llc | 06/07/08
Fatal Flaw  MBridge llc | 06/07/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here