Macs running OS X and browsing with Safari under OS X are not affected.
Great catch! ;-)
This, apparently, is a Windows vulnerability. Mac users that run Windows XP or VISTAin either virtualization through Parallels or VMWare's Fusion, or through Boot CampAND use Windows for browsing (It is much safer to browse in OS X), can get their Windows' Clipboards taken over by this exploit. Although this report has appeared in at least three on-line publications, Sophos has no article citing the problem on their website.
Still, a warning is appropriate. PING!
If you want on or off the Mac Ping List, Freepmail me.
Dammit. I was hoping to rub this in the faces of you Mac users.
Oh well. Someday, someday...
Computer viruses are spread behaviorally. Just say NO to Windows!
Ok, I’m feel like an idiot, but what is Windows clipboard?
That's just sloppy writing. The vulnerability is in Flash, which has the ability to access the clipboard on both operating systems (and Linux, too).
If you have a Photobucket account, you've probably used the Direct Link facility they put below each image. Click it, and it copies the picture URL to the clipboard. If you examine the underlying code, you will find it uses Javascript to access an included .swf, which does the actual copy operation.
I believe I have witnessed the end-result of this very problem. I have received numerous messages on facebook from folks I know, that have a short three or four word message, and a long crazy looking url. While the URLs appear to be different, they all go to the same fake video hosting “page” that if you click ANYWHERE on the page, it downloads an exe file that appears to be a pretty ugly bug.
The friends I have received this from are all pretty good folks who would not intentionally pass on such trash. I suspect they used one of the apps on facebook to send something to all their friends - and the malicious url was put through instead.
Or the problem is completely unrelated - but sure sounds so (notice the reference to facebook in the text).
Of course, as I sit here typing on my iBook, I’m not worried about the .exe file sitting on my desktop.
Anyone want me to send you the file????