Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: ~Kim4VRWC's~; 1234; 50mm; 6SJ7; Abundy; Action-America; acoulterfan; Aliska; aristotleman; ...
This is a rehash of old FUD... but it is FUD season, so here it is. PING!

There is a vulnerability here, one reported months ago, but there are no exploits in the wild.

The source of this particular incarnation of the security concern claims that he used this vulnerability to "pwn the target Mac" on the "first day of the last Pwn to Own" competition at CanSecWest but was not allowed to win because the judges ruled it was an already known vulnerability. The rules did state that the exploit had to utilize a new vulnerability, one that had not been reported.

However, there is another problem with this claim... the first day of the contest merely had the target computers sitting running the targeted browsers. In the case of the Mac, the browser was Safari. On that first day, the attempts to compromise the browser could not require the navigation to any specific website. The contest judges have stated that none of the target machines were compromised on the first day.

It was only on the second day—when the attackers could direct the referees to navigate to their prepared sites and click on a link—that Safari fell to Charles Miller's pre-prepared exploit—the one he had been working on for several months—in two seconds.


MacPing!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 05/20/2009 8:56:24 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: Swordmaker

IMO, I think JavaScript is a bigger vulnerability in browsers than Java.


3 posted on 05/20/2009 9:00:38 PM PDT by NVDave
[ Post Reply | Private Reply | To 2 | View Replies ]

To: Swordmaker

4 posted on 05/20/2009 9:31:25 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 2 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson