Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Safari for Windows, 0day exploit in 2 hours

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:05 AM
Original message
Safari for Windows, 0day exploit in 2 hours
Apple released version 3 of their popular Safari web browser today, with the added twist of offering both an OS X and a Windows version. Given that Apple has had a lousy track record with security on OS X, in addition to a hostile attitude towards security researchers, a lot of people are expecting to see quite a number of vulnerabilities targeted towards this new Windows browser.

I downloaded and installed Safari for Windows 2 hours ago, when I started writing this, and I now have a fully functional command execution vulnerability, triggered without user interaction simply by visiting a web site. I will not sell this one to ZDI or iDefense but instead release it here, as I have done lately with a number of 0day vulnerabilities. This place is where you get my latest research :)

A bunch of other security researchers such as David Maynor and Aviv Raff have been pounding safariWin with their fuzzing tools, going through thousands upon thousands of test pages in the hopes of triggering some form of memory corruption for potential exploitation. I am a big fan of fuzzing and believe it can produce some tremendous results, but sometimes good old fashioned application specific knowledge can get you far.

<snip>

http://larholm.com/2007/06/12/safari-for-windows-0day-exploit-in-2-hours

You can click on the link to see the steps.
Printer Friendly | Permalink |  | Top
LoZoccolo Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:09 AM
Response to Original message
1. I think this incident brings up something they may not have thought of.
That bringing Safari to a Windows-sized user base will expose it to a Windows-sized h4x0r base as well.
Printer Friendly | Permalink |  | Top
 
ihelpu2see Donating Member (935 posts) Send PM | Profile | Ignore Wed Jun-13-07 07:13 AM
Response to Original message
2. I'm not sure of your claim of lack of security with Mac OS, I opened my
medical office 8 years ago with all Macs. Never had 1 virus or 1 security breach of my network and for that matter never had a hardware problem.(the one iMac that failed failed right out of the box and was replaced the next day). While my other doctor friend has a Windows network in their office and pay 10 Xs what I do for support and security. Mac has definitely been a great business decision for my medical practice.... :)

:toast:
Printer Friendly | Permalink |  | Top
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:17 AM
Response to Reply #2
3. I make no claims ...
the author makes the claims.
Printer Friendly | Permalink |  | Top
 
ihelpu2see Donating Member (935 posts) Send PM | Profile | Ignore Wed Jun-13-07 07:20 AM
Response to Reply #3
6. my apologies I did see the link, I did not see the snip part.... I usually
put " " around stuff that is not attributable to me..

sorry again
Printer Friendly | Permalink |  | Top
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:39 AM
Response to Reply #6
11. No prob ...
:hi:
Printer Friendly | Permalink |  | Top
 
ananda Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:18 AM
Response to Reply #2
4. imo
It's most likely a windows problem.

I use Firefox and Safari on my Mac, and I've never had a problem.. ever.
Printer Friendly | Permalink |  | Top
 
proud2BlibKansan Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:20 AM
Response to Reply #4
5. Same here
Firefox works great on my new Mac.
Printer Friendly | Permalink |  | Top
 
ChairmanAgnostic Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:38 AM
Response to Reply #4
9. I run my practice on macs,
and hate the fact that my dual chip macbook has to have windows 98 on it, simply because one client demands it.

I have never had a problem either. I suspect that those reports of problems are sour grapes on the part of windows users who just love blue screens of death, and constant viroids destroying their data.
Printer Friendly | Permalink |  | Top
 
originalpckelly Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 08:34 AM
Response to Reply #4
14. It's a Firefox problem, and Safari is vulnerable because it uses Firefox to help it on Windows.
That's how Safari has all the necessary extensions, without actually giving the developers time to create Safari specific ones.
Printer Friendly | Permalink |  | Top
 
EV_Ares Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:31 AM
Response to Original message
7. I think it still is somewhat of a personal preference and what you
Edited on Wed Jun-13-07 07:31 AM by EV_Ares
need your computer for and what you are used to.

Mac is a great computer and if you need graphics far superior to Windows. However, if you look at how many use windows and this includes corporations and government offices, this is where the priority of hackers are and where they go. Macs are starting to see more attacks and more vulnerabilities every day. So far, I don't see where Safari is having a lot of success with Windows and it doesn't have the security that IE-7 does.

I use Vista and and always been a Windows user and have used Mac but for me Windows works best but certainly would have no problem with a Mac either.

Whichever, you need to have the proper protection just as you would a good condom, good firewall, anti-virus and spy ware protection is just as important along with keeping up with the updates.
Printer Friendly | Permalink |  | Top
 
pimpbot Donating Member (770 posts) Send PM | Profile | Ignore Wed Jun-13-07 07:39 AM
Response to Reply #7
10. Wintel boxes have caught up in the graphics dept.
I can play HD movies, ripped straight from HDDVDs on my XP box. All on a box that cost me under $700 to build, with plenty of room to upgrade for future improvements (more memory, better gfx card if needed, maybe add in another ATSC tuner?)

The mini caught my eye because I was looking for a solution that was small, however after researching it, the lack of upgradability turned me off.

Printer Friendly | Permalink |  | Top
 
EV_Ares Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:58 AM
Response to Reply #10
12. Thanks, thats good to hear, I thought they would probably improve in
that area. Sounds like you are satisfied with what you are working with.
Printer Friendly | Permalink |  | Top
 
Lone_Star_Dem Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 07:37 AM
Response to Original message
8. This is why I'll wait until after it's out of beta
Beta testing of browsers is for people who want to attempt to hack it or are masochist. I'm neither.
Printer Friendly | Permalink |  | Top
 
originalpckelly Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 08:37 AM
Response to Reply #8
15. In the interim are you using Firefox or IE?
Edited on Wed Jun-13-07 08:37 AM by originalpckelly
I would like to point out that this is really a Firefox exploit, so if you use Firefox, you're susceptible to this.
Printer Friendly | Permalink |  | Top
 
originalpckelly Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-13-07 08:32 AM
Response to Original message
13. Did you actually read the successful exploit?
It's not really a Safari exploit, but a Firefox exploit. It uses a flaw in Firefox, which Safari uses when it needs a plug-in, in this case Safari doesn't handle the Gopher protocol, so it uses Firefox for that. The flaw is in Firefox.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 01st 2024, 11:14 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC