Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Senator Bedfellow
Interesting comment from Slapdash:

Also works in Mail.app
(Score:5, Informative)
by daveschroeder (516195)
on 10:27 AM February 21st, 2006 (#14767730)
(http://das.doit.wisc.edu/)

You can send this same shell script masquerading as a JPG file and shown as such by Mail.app, and it gets executed as soon as it is clicked/viewed in Mail.app (obviously not affected by Safari's "safe files" setting).

You can test this by downloading this harmless exmaple:

http://www.heise.de/security/dienste/browsercheck/ demos/safari/Heise.jpg.zip [heise.de]

...and sending the resulting JPG to yourself in Mail.app.

This is rooted in something that has been true about Mac OS in general for over 22 years, which is that any file or document - including executables - can have any icon. Other elements of the OS (such as the Get Info window) properly identify it as a Terminal document (shell script), and show that it is opened with Terminal, but most users won't see or understand this.

I'd expect a security update that addresses this *very* soon. This is a bad one.
[ Reply to This ]

12 posted on 02/21/2006 8:37:37 AM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 10 | View Replies ]


To: Senator Bedfellow

The Slapdash post is more troubling than the original report.


17 posted on 02/21/2006 9:06:12 AM PST by zeugma (This post made with the 'Xinha Here!' Firefox plugin.)
[ Post Reply | Private Reply | To 12 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson