Skip to comments.
Safari (Apple browser) URL-spoofing vuln reveals how fanbois can be led astray
The Register ^
| May 20, 2015
| Alexander J Martin
Posted on 05/20/2015 8:05:38 PM PDT by dayglored
A recently published exploit for the Safari browser demonstrates a URL spoofing mechanism which might convince users they are visiting a legitimate website, when they are actually visiting another site which may be phishing their details.
Deusen researchers have disclosed a vulnerability which may be exploited by hackers to hijack user accounts on a range of websites, from social media to banking.
The proof-of-concept invites users to visit what appears to be the Daily Mail website however, a script will execute the loading of another URL before the page users are directed to can be displayed.
Tested using Safari on the iPad, the example address-spoofing script causes the Safari browser to display dailymail.co.uk whilst the browser displays content from deusen.co.uk, although the latter can be substituted for a malicious site, say Deusen's researchers.
(Excerpt) Read more at theregister.co.uk ...
TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: apple; ios; osx; safari
1
posted on
05/20/2015 8:05:39 PM PDT
by
dayglored
To: Swordmaker; tacticalogic
Swordmaker: for your list (sorry about the "fanbois", it's the original title...)
Tacticalogic: I chose to post the Register's version, the Hacker News version page creeped me out, their massive script ran forever on my Firefox.
2
posted on
05/20/2015 8:07:18 PM PDT
by
dayglored
(Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
To: dayglored
3
posted on
05/20/2015 9:26:27 PM PDT
by
TEXOKIE
(We must surrender only to our Holy God and never to the evil that has befallen us.)
To: dayglored
Swordmaker: for your list (sorry about the "fanbois", it's the original title...)
It only hurts when it's true.
4
posted on
05/20/2015 9:50:42 PM PDT
by
867V309
(Boehner is the new Pelosi)
To: 867V309
5
posted on
05/20/2015 10:49:01 PM PDT
by
Scutter
To: dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ..
WARNING A german Security Site has discovered a vulnerability in the DNS structure on Safari and Chrome browsers on Apple OS X, iOS, and also Chrome on Android. Google has patched Chrome so download a new version. Apple has yet to fix the vulnerability. The proof-of-concept is extremely simple
it uses JavaScript to load up a website (dailymail), every 10 micro-seconds, which is not enough time for the website to begin loading. So its displaying that website address, but hasnt actually loaded it yet. Meanwhile, its on a different website, which could have active malware.
As a quick fix, go to Safari Menu, Preferences, Security, uncheck Webcontent: Enable JavaScript. Problem Solved! However, you may not be able to use some sites which require JavaScript to operate. PING!
Apple Security Ping!
If you want on or off the Mac Ping List, Freepmail me.
Still working on the Freepathon. . . I challenge the members of the Apple ping list to each donate at least $10 each to the latest Freepathon. I HAVE donated $100. Many members of the Apple Ping list are already rising to the challenge. Join them. Let's show the power of the Apple Ping list in supporting Freerepublic!
If you have ordered an Apple Watch,
MAKE A DONATION TO THE FREEPATHON!
6
posted on
05/21/2015 1:11:56 AM PDT
by
Swordmaker
( This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
To: dayglored; Swordmaker; tacticalogic
Fanbois is a French term, pron. “fon-bwa”, means “intellectual” I think. ;’)
7
posted on
05/21/2015 3:58:37 AM PDT
by
SunkenCiv
(What do we want? REGIME CHANGE! When do we want it? NOW!)
To: SunkenCiv
Fanbois is a French term, pron. fon-bwa, means intellectual I think. ;)Imagine spending an evening with a bunch of French "intellectuals".
8
posted on
05/21/2015 4:09:18 AM PDT
by
tacticalogic
("Oh, bother!" said Pooh, as he chambered his last round.)
To: dayglored
Apple fanbois can be led astray..... goes on all the time as they toss their money down an obsessive rathole buying overpriced Apple watches etc. They hang on Tim Kooks every word and before that Steve Jobs.
9
posted on
05/21/2015 4:15:03 AM PDT
by
dennisw
(The first principle is to find out who you are then you can achieve anything -- Buddhist monk)
To: dennisw
Ah, thank you Dennis, I knew we could count on you to hold down your end of the spectrum with surety and aplomb.
10
posted on
05/21/2015 6:08:10 AM PDT
by
dayglored
(Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
To: Swordmaker; dayglored; tacticalogic
A German Security Site has discovered a vulnerability in the DNS structure on Safari and Chrome browsers on Apple OS X, iOS, and also Chrome on Android . . . Apple has yet to fix the vulnerability. As a quick fix, go to Safari Menu, Preferences, Security, uncheck Webcontent: Enable JavaScript. Problem Solved! However, you may not be able to use some sites which require JavaScript to operate.
Thanks to tacticalogic for the heads up on this one! - dayglored
Thanks, SM, DG, and TL.
11
posted on
05/21/2015 10:32:40 AM PDT
by
conservatism_IS_compassion
('Liberalism' is a conspiracy against the public by wire-service journalism.)
To: tacticalogic; SunkenCiv
>>
Fanbois is a French term, pron. fon-bwa, means intellectual I think. ;) > Imagine spending an evening with a bunch of French "intellectuals".
Ben Franklin spend considerable time in the company of French intellectuals, and it appears to have done him little or no damage.
OTOH, he also reportedly spent numerous evenings in the company of French whores. Whether it did the good Doctor any harm or not was not recorded for posterity.
12
posted on
05/21/2015 2:32:38 PM PDT
by
dayglored
(Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
To: dayglored
Ben Franklin spend considerable time in the company of French intellectuals, and it appears to have done him little or no damage. Ben himself would have been among the intellectuals of his day. Intellectualism I fear, ain't what it used to be.
13
posted on
05/21/2015 2:35:23 PM PDT
by
tacticalogic
("Oh, bother!" said Pooh, as he chambered his last round.)
To: tacticalogic
>
Ben himself would have been among the intellectuals of his day. Intellectualism I fear, ain't what it used to be. You sure got that right, FRiend. :)
14
posted on
05/21/2015 2:42:09 PM PDT
by
dayglored
(Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson