Massive OS X Security Issue
Jay Allen and Liz Lawley are talking about a serious security hole in OS X.
Two vulnerabilities have been reported in Mac OS X, allowing malicious web sites to compromise a vulnerable system.
1) The problem is that the “help” URI handler allows execution of arbitrary local scripts (.scpt) via the classic directory traversal character sequence using “help:runscript”.
2) It is reportedly also possible to silently place arbitrary files in a known location, including script files, on a user’s system using the “disk” URI handler.
Various variants of the URI handler vulnerabilities are currently being discussed. This has been confirmed on Macintosh OS X using Safari 1.2.1 (v125.1) and Internet Explorer 5.2. Other browsers may also be used as attack vectors.
NOTE: The rating has been upgraded to “Extremely Critical” because the issues are very easy to exploit and a large number of working exploits are available.
There’s even more details on MacNN, but if you just want to fix it, Liz suggests:
If, like me, you just want to know how to fix this fast (since Apple has apparently known about this since February and hasn’t fixed it, it wouldn’t be wise to wait for their patch), here’s the approach to use.
1. Download the freeware tool MoreInternet.
2. From the disk image, run “install prefpane,” which will put the MoreInternet preference panel into your System Preferences panel.
3. Open the MoreInternet panel, and select the help: protocol.
4. Change the application it launches from the Help Viewer (which has the script-running vulnerability) to something benign. (I used TextEdit.) I used Chess, which, unlike TextEdit, gives me a clear visual cue that a page tried to invoke the help: protocol.
5. Make sure it worked by going to the scary but harmless example.
UPDATE: MacNN is reporting that Apple is taking this very seriously” and is “actively investigating this potential security issue.”
Share
Jay Allen and Liz Lawley are talking about a serious security hole in OS X. Two vulnerabilities have been reported in Mac...
Add a Comment
You may want to also change the helper for the disk:// protocol. Probably not such a good idea to let people mount disk images on your machine from over the internet...
May 18 2004 at 10:58 PM Report abuse Permalink rate up rate down Replywaa i tested the link and it opend the terminal and help file thingy. I wonder why apple has not patched this yet! this is really big problem. (can see people getting links in email already taking them to websites useing this script!)
May 18 2004 at 6:37 PM Report abuse Permalink rate up rate down ReplyI tested the link using Mozilla 1.7rc1 & it was also vulnerable
May 18 2004 at 2:43 PM Report abuse Permalink rate up rate down ReplyHot Apps on TUAW
Deals of the Day
more deals- Used Apple iMac 17" Core 2 Duo 1.83GHz for $430 + $28 s&h
- Lounge Deluxe Stand for iPhone / iPod touch for $28 + $8 s&h
- Brookstone Surround-Sound Earbuds for $14 + $7 s&h
- Refurbished Skullcandy Tokidoki Smokin' Buds Mic'd Headset for $5 + $2 s&h
- Stitchway Backup Battery for iPod / iPhone for $5 + free shipping
- Used Apple MacBook Pro 2.4GHz 15" LED Laptop for $1,030 + $29 s&h
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



3 Comments