Welcome to the Cell Phones Forum dedicated to wireless devices and services discussion. We are also the fastest growing discussion forum where you can discusse cell phones, downloads, news, plans, services, and tech support. For simplicity this forum has divided into sections based on service providers and manufacturers. Just scroll down and you will find them.

You are currently viewing our boards as a guest. All visitors must register before they can post questions, contact other members or search our database of over 1,000 threads and 1,1000 posts. By joining our free community you will be able to :

- Participate in all the forums and browse all the posts.
- Communicate with other mobile users privately.
- Post your own topic and discuss it with other members.
- Gain access to our free classifieds marketplace to buy, sell and trade any mobile products.

Registration is fast, simple and absolutely free. So what are you waiting for? Join our community today!

If you have any problems with the registration process or your account login, please contact us.

Go Back   Cell Phones Forum > General > Computer

Bid, Buy and Sell on eBay

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 06-13-2007, 08:46 AM
Senior Member
 
Join Date: May 2007
Posts: 467
Default Researchers find bugs in Safari for Windows

San Francisco (InfoWorld) - Just hours after Apple released a Windows version of Safari on Monday, security researchers had uncovered more than half a dozen vulnerabilities in the browser beta, including at least three that could let attackers grab complete control of the PC.

Two of the researchers blamed Apple's "false claims" about security and what they called its "hostile attitude" toward bug finders for the rush to dig up flaws.

First off the mark was David Maynor of Errata Security, who posted notice of a bug about two hours after Apple made Safari 3 available for Windows. By the end of the day, Maynor had racked up six bugs. Four could be exploited to crash the browser and/or PC in a denial of service; the other two, Maynor claimed, were remote execution vulnerabilities.

Maynor, who clashed with Apple over a demonstration of a wireless hack on a MacBook at last summer's Black Hat security conference, didn't hesitate to take a shot at the company. "I can't speak for anybody else, but the bugs found in the beta copy of Safari on Windows work on the production copy on OS X as well," he said in a posting on the Errata site. "The exploit is robust mostly thanks to the lack of any kind of advanced security features in [Mac] OS X."

Shortly after Maynor posted his first bugs, Aviv Raff, an Israeli security researcher noted for his contributions to last July's "Month of Browser Bugs" project, announced he had found a flaw, too. "I found it using a fuzzer tool, Hamachi, that was developed by HD Moore and me," Raff said in interview. "This is a memory corruption vulnerability, which is potentially exploitable for remote code execution."

Danish researcher Thor Larholm wrapped up Safari's opening day with the most damaging disclosure of all: A remote execution vulnerability accompanied by proof-of-concept exploit code. That code -- Windows Safari users can click here for a demo -- could be used to hijack the PC, said Larholm, who plucked the vulnerability from the browser and built the exploit in just two hours.

He laid part of the blame on Apple's inexperience in writing code for Windows. "On OS X, Apple has enjoyed the same luxury and the same curse as Internet Explorer has had on Windows, namely intimate operating system knowledge," said Larholm. "The integration with the original operating system is tightly defined, but [that] knowledge is crippled when the software is released on other systems, and mistakes and mishaps occur.

"[For example] you can still find references to the OS X proprietary URL protocols "open-help-anchor:" and "network-diagnostics:" inside the resource files for the Windows release [of Safari]."

Bugs are not unknown to Apple. Other applications available to Windows users, the QuickTime media player and the iTunes music store software, have been patched several times. Four fixes for QuickTime, two last month alone, have been issued by Apple this year. In March, Apple updated iTunes so it would work more smoothly with Windows Vista.

Even so, the number of vulnerabilities discovered in Safari's debut day was stunning. Aviv Raff had an explanation. "My guess is that it's because of Apple's issues with security researchers and the false claims that their products are far more secure than others," he said.

Larholm agreed. "Given that Apple has had a lousy track record with security on OS X, in addition to a hostile attitude towards security researchers, a lot of people are expecting to see quite a number of vulnerabilities targeted toward this new Windows browser."

Maynor, who until last summer worked as a senior researcher for SecureWorks, did not need to spell out his position. After he and colleague "Johnny Cache" demoed a MacBook hack prior to Black Hat, both Apple and Mac bloggers criticized the pair for either faking the hack or obfuscating its true nature. Maynor and Cache stood behind their claim. Several months later, Apple quietly patched the wireless drivers the researchers had used to break into the Mac machine.

Apple officials did not respond to a request for comment.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Bell Canada introduces Windows Mobile HTC 5800 imported_ghengis Bell Mobility 0 09-02-2007 04:04 PM
LG's Windows Mobile Smartphone : Truth or Rumor imported_ghengis LG 1 08-28-2007 01:13 PM
UPGRADE: HTC released P3600 as P3600i with Windows Mobile 6 katy HTC 0 08-22-2007 08:44 PM
Samsung Windows Mobile Phone Syncing via Wireless USB imported_ghengis SamSung 0 07-16-2007 08:00 AM
Find your usefull upgrade for you blackberry imported_ghengis RIM (Research In Motion) 0 05-28-2007 12:07 PM


All times are GMT -6. The time now is 12:51 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
CellPhonesMarket.com

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51