YISTA

Apple Safari Automatically Executes Shell Scripts

February 22nd, 2006 by George Burnett

Apple SafariShortly after reports of the first virus for Mac OS X, a new security flaw has surfaced. The culprit is the option “Open ’safe’ files after downloading” in Apple’s Safari web browser. This feature is activated by default. Its function is to automatically display images and movies after they are transmitted to the user’s computer, using the application assigned to that particular document format. Safari will also unpack ZIP archives and display the documents within if they are considered “safe”. If active content such as an application or shell script is found within the archive, a prompt requests user confirmation. So far, so good.

If a script is given an extension such as “jpg” or “mov” and stored within a ZIP archive, Mac OS X will add a binary metadata file to the archive which determines its association. This metafile instructs the operating system on another Mac to open that file with the Terminal application — regardless of its extension or the symbol displayed in the Finder. The Terminal will redirect scripts without an interpreter line directly to bash, the standard shell in OS X.

You can determine whether your system is vulnerable by using this online demonstration provided by heise Security. The demo attempts to open a Terminal window to display the contents of a folder. If you are running Mac OS X in its standard configuration and use Safari, the window will open without waiting for a prompt. The script could just as well delete all files accessible to the current user.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]
Filed under: Apple, News, Security, Software Article tags: Apple

Leave a Reply

Yah, I saw that already too, but just in case you may missed something YISTA is here to keep you up-to-date on the latest hardware, technologies, hacks and caffeinated properties :) Subscribe to our newsletter. Send tips and requests.
Grab our RSS feed  .

Additional Possibly Related Posts:

  • MacBook Zero-Day @ CanSecWest
  • Apple Updates 30″ Cinema Display
  • Mac OS X Hack Challenge Suspended
  • A Better iPod Manager :: YamiPod
  • Ajaxy Web 2.0 apps vulnerable to attacks

YISTA Sections Show Sections | Hide Sections

  • *nix
  • Apple
  • Arts
  • Audio
  • Caffeine
  • Coding
  • Conferences
  • Design
  • File Sharing
  • Gadgets
  • Gaming
  • Google
  • Guides
  • Hacks
  • Hardware
  • iPod
  • Laptops
  • Microsoft
  • Mobiles
  • Mods
  • Movies
  • Networking
  • News
  • Open Source
  • Parody
  • Rumors
  • Search
  • Security
  • Social Networking
  • Software
  • TV
  • Uncategorized
  • Videos
  • Viruses
  • VoIP
  • Web 2.0
  • Wireless

YISTA Sections Contextual Digital Nano Tattoos iPhone Redesign AT&T Rick Rollover Minutes Asus EEE Desktop PC 100 Mb Symmetric: Oh, the Iniquity! Goowy To Be Acquired By AOL BlackBerry :: Red Pearl Unboxing iPhone Keynote Ringtone Mac Mini Carputer + iTrip Pepsi Cappuccino Lawn Mower VS. iPod nano BlackBerrys & iPhones - The Comic

Hot Topics

Apple Arts AT&T Blackberry Caffeine code Coding comic compiz Conferences Dell Design DIY DRM Firefox Flickr Gaming Google Hacks iPhone iPod iTunes Linux Macbook Mac OS X Mobiles music Nintendo OLPC Open Source Parody robots Search Security Software The Pirate Bay torrents TV Ubuntu Videos VoIP Web 2.0 web app Wii

. Sign up for the YISTA daily email
You will receive our new posts delivered right into your inbox every afternoon. It's free and easy!

Recent Comments

iPhone Video Conference Hack
08/13/2008 07:02 pm
2 Comments
Trinome? A Monome Clone
07/24/2008 12:52 am
1 Comment
All Aboard the Internet Omnibus
06/06/2008 12:44 pm
2 Comments
All Colors Together - Obama Poster
05/24/2008 05:24 pm
3 Comments

Recent Posts

Welcome to the World of Tomorrow!
08/22/2008
Eclipse Code Swarm
06/17/2008
BMW’s Flexible GINA
06/11/2008
Hive Mind Robot Swarms By 2025
06/08/2008
Deathstar Cantina Comedy
05/31/2008

About YISTA

YISTA is the No. 1 technologist's guide for geeks. w00t indeed!

Subscribe: Newsletter | RSS Feed RSS

Browse: The Archives

Contact: Tips & Requests | Advertise

Copyright © 2005-2008 YISTA. All rights reserved.  Proudly powered by WordPress.