User Login    
 + Register
  • Main navigation
Login
Username:

Password:

Remember me



Lost Password?

Register now!


Donate

Wired Feed
Google

Browsing this Thread:   2 Anonymous Users





Safari browser vulnerable to auto hack attack
Webmaster
Joined:
1/8 21:05
From Dayton, Ohio
Group:
Webmasters
Registered Users
Moderator
Vets
Plus+User
Posts: 59
Offline
WhiteHat has disclosed a critical security vulnerability in Apple's Safari browser that could allow hackers to extract personal information from the OS X address book.

"Right at the moment a Safari user visits a malicious website, even if they've never been there before or entered any personal information, [it] can uncover their first name, last name, work place, city, state and email address," WhiteHat CTO Jeremiah Grossman wrote in an official blog post.

"Safari v4 & v5, with a combined market browser share of 4% (~83 million users), has a feature (Preferences > AutoFill > AutoFill web forms) enabled by default. Essentially we are hacking auto-complete functionality."

According to Grossman, malicious websites would likely operate by surreptitiously extracting Address Book card data from Safari and dynamically creating form text fields with matching names.

The site would then simulate A-Z keystroke events using JavaScript.

"When data is populated, that is AutoFill'ed, it can be accessed and sent to the attacker. [Now], this entire process takes mere seconds and represents a major breach in online privacy," explained Grossman.

"The [breach] could be further leveraged in multistage attacks including email spam, (spear) phishing, stalking and even blackmail if a user is de-anonymized while visiting objectionable online material."

However, Grossman emphasized that any AutoFill data beginning with a number would remain off limits to a malicious website.

"For some reason, the data [will] not populate in the text field. Still, such attacks could be easily and cheaply distributed on a mass scale using an advertising network where likely no one would ever notice because it's not exploit code designed to deliver rootkit payload.

"In fact, there is no guarantee this has not already taken place. What is safe to say is that this vulnerability is so brain dead simple that I assumed someone else must have publicly reported it already, but exhaustive searches and asking several colleagues turned up nothing."

Unsurprisingly, Grossman revealed that Apple had yet to seriously address the issue.

"I figured Apple might appreciate a vulnerability disclosure prior to public discussion, which I did on June 17, 2010 complete with technical detail. A gleeful auto-response came shortly after, to which I replied asking if Apple was already aware of the issue.

"I received no response after that, human or robot. I have no idea when or if Apple plans to fix the issue, or even if they are aware, but thankfully Safari users only need to disable AutoFill web forms to protect themselves."

Posted on: 7/22 14:57
_________________
The more I know, the more I know that I didn't wanna know.
Transfer the post to other applications Transfer


Re: Safari browser vulnerable to auto hack attack
Webmaster
Joined:
1/8 21:05
From Dayton, Ohio
Group:
Webmasters
Registered Users
Moderator
Vets
Plus+User
Posts: 59
Offline
Delivering on a promise the company made back in June, Apple on Wednesday released an update to Safari 5 which turns on extensions support akin to what browsers such as Firefox and Internet Explorer have been offering for years.

In addition to the debut of these plugins, Apple also plugged several security issues, including a widely publicized flaw in the AutoFill feature that could open up users to information disclosure.

Posted on: 7/28 16:03
_________________
The more I know, the more I know that I didn't wanna know.
Transfer the post to other applications Transfer






You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You cannot vote in polls.
You cannot attach files to posts.
You cannot post without approval.

[Advanced Search]


Who's Online
8 user(s) are online (6 user(s) are browsing Forums)

Members: 0
Guests: 8

more...
New Members
kyngofkomedy 2010/8/29
robert2 2010/8/28
glitch 2010/8/20
MassAssassin 2010/8/19
throoper
throoper
2010/6/27
azevedan 2010/6/9
Synja 2010/5/29
poppij 2010/5/23
EMGARCIA 2010/5/13
choatpadda 2010/4/4
Google
      Stop Spam Harvesters, Join Project Honey Pot
Site Info
Webmasters
dante
dante
 
Spectre
Spectre
 
Moderator
dante
dante
 

Rolling Stone: Videos