WikiWirral values you and your opinion.
Forum Statistics
Forums65
Topics76,361
Posts1,033,315
Members14,578
Most Online16,551
Feb 2nd, 2024
Who's Online Now
5 members (1 invisible), 9,835 guests, and 408 robots.
Key: Admin, Global Mod, Mod
Top Posters
sunnyside 45,164
MattLFC 22,315
Mark 21,269
granny 17,788
_Ste_ 16,345
Newest Members
PaulRobson, meolswanderer, Firminafirm, YesterYearGenea, Luke121
14,578 Registered Users
New General Forums
Hi to everyone
by PaulRobson - 15th Apr 2024 1:18pm
Last person to post wins...
by GaryB - 9th Oct 2007 9:15pm
New Wirral History
Moreton History
by IanFife - 1st Apr 2024 1:03pm
Campbell Terrace, behind old St. Andrew's Church on Conway
by KimTheilmann1 - 31st Mar 2024 3:34pm
Tall Brick Chimneys
by diggingdeeper - 16th Mar 2024 12:56pm
Through the Window: GWR Paddington to Birkenhead
by yoller - 16th Aug 2017 7:09pm
Old Hall in Higher Bebington
by Rhoobarb - 25th May 2010 6:55pm
Top Posters(30 Days)
bert1 5
casper 4
Topic Replies
Restaurant/pub with outdoor seating - Bromborough
by capitulinagarage - 17th Apr 2024 12:52pm
recommendation, please
by muzzy2 - 16th Apr 2024 7:39pm
Car paint jobs
by PaulRobson - 15th Apr 2024 9:54pm
Hi to everyone
by PaulRobson - 15th Apr 2024 1:18pm
Traffic Wardens
by diggingdeeper - 14th Apr 2024 2:42pm
West Kirby flood defences
by Excoriator - 13th Apr 2024 3:35pm
Lost river (Well, brook really)
by diggingdeeper - 10th Apr 2024 11:00pm
Any Decent Restaurant Open On a Mon Evening.
by Abakumss - 8th Apr 2024 9:04am
Paddle Steamer Waverley
by casper - 6th Apr 2024 9:09am
April
M T W T F S S
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30
Top Likes Received (30 Days)
casper 1
cools 1
Kylix 1
Top Likes Received
bert1 14
Mark 4
casper 4
Gibbo 3
Previous Thread
Next Thread
Print Thread
#219419 1st Apr 2008 7:55pm
Joined: Nov 2003
Posts: 21,269
Likes: 4
Mark Offline OP
Wiki Master
OP Offline
Wiki Master
Joined: Nov 2003
Posts: 21,269
Likes: 4
Safari browser allows Mac to be easily taken over at hacker convention, Vista, Ubuntu machines survive the day

It has not been a good couple weeks for Apple and Safari. First Opera knocked it from its position as sole 100 percent compatible Acid3 browser. Then it tried to force iTunes users to unintentionally download the browser as part of an iTunes update, which included a pre-checked install option for Safari. The move was met with broad criticism, including from Mozilla's CEO, who commented that Apple was bordering "on malware distribution practices." Finally, Safari users who updated to v3.1 reported many bugs and crashes.

Now the browser, which Apple CEO Steve Jobs once called the "most innovative browser in the world and the most powerful browser in the world", has had more bad news. At the CanSecWest Show, an annual security conference, it was found that the Safari browser was surprisingly insecure, allowing successful attacks on Mac computers.

CanSecWest sponsors an annual hacking contest, which seeks to recognize vulnerabilities and give a comparative analysis of OS security. A Mac, Vista machine, and Ubuntu box survived the first round, which only allowed pre-authentication attacks – a successful attack would have yielded a $20,000 prize. However, on the second day, the flood gates were opened and hackers were allowed to use default-installed client applications.

The Mac fell within minutes, hijacked by security researcher Charlie Miller. Miller compromised the computer through security flaws in the new Safari 3.1 browser, which he declined to make public. For his takeover via the new vulnerability, Miller netted a sweet prize of $10,000. Surprisingly, the hackers were unable to gain control of the Vista or Ubuntu machines that day.

On the third day, hackers were allowed to exploit popular third-party applications. Hackers found the Vista machine surprisingly hard to crack in what they thought would be an "easy pickings" day. The improved security is likely owing largely to SP1, perhaps because of NX support for heap memory. In the end it was taken down by a cross-platform Flash Player attack. The Ubuntu machine survived the day.

Some point that the Mac and others may be even more vulnerable than the show indicates as some have noted that a pre-authentication vulnerability might command a price of $50,000 or more elsewhere, making an exploit at the show unprofitable. According to eWeek's security analysts, "Safari is prone to a remote code-execution vulnerability because it fails to adequately handle regular expressions with large, nested repetition counts. Inaccurate compilation lengths are calculated, and an overflow results."

Miller didn't even have to use new vulnerabilities also known for Safari. The first is a simple overflow attack using zip files. The second attack allows injection of content in a window belonging to a trusted site.
A recent independent analysis confirmed that Apple patches its vulnerabilities slower than Microsoft. The analysis followed a controversial Microsoft report by Jeff Jones, known for trashing Firefox for its bugs. The report indicated that 36 vulnerabilities in Vista were fixed over a total of nine patching events, and 30 unpatched vulnerabilities remained, while a total of 116 vulnerabilities were fixed in OS X over 17 patching events, with 41 unpatched vulnerabilities.

Apple's patches last year indicated Apple's slower than acceptable patching pace. It included patches for four vulnerabilities known since 2006 and two known since 2005. The oldest of these, a vulnerability in Apache, had a fix released by Apache in 2005.

Security experts point out that despite Apple's poor security, its machines remain less attacked than Windows machines. Many believe this is simply a matter of market share. With Mac sales on the rise, there may soon be a large increase in Apple-targeted malware and takeovers with the Safari browsing taking the brunt of the attacks.


Sourced from Daily Tech

Google Ads
Mark #219474 2nd Apr 2008 5:06am
Joined: Aug 2004
Posts: 22,315
Wiki Master
Offline
Wiki Master
Joined: Aug 2004
Posts: 22,315
This reminded me to check a new site I just built in Safari... I like Safari, I hope they sorted the memory usage in the latest release as that was the only issue I had with 3.0.

Security issue's or not, it probably doesnt have as many as IE and FireFox, and it's certainly a nicer browser to use, as is Opera, but that's just a pain the way it render's site's so strictly to W3C standards sometimes. Safari does'nt seem to suffer from these problems.

Apple tbh are doing quite well to get to grips with Safari on Windows imho. I think out of preference, I would use Safari or Opera before IE or Firefox, but unfortunatly Safari had memory problems in 3.0 for Windows and Opera is just too W3C compliant, so until they get it right, im stuck with IE7, which I must admit I like overall, but its not as good in a lot of respects.

I use Opera on my gf's laptop though (so she can have IE7 all to herself) and it work's a treat... tried Safari 3.0 on there originally and it was a bit lacking the memory to deal with it's leakage; maybe this new release has sorted that hehe.

Anyway, im pleased to not my new website has passed the IE6, IE7, FireFox 2 & 3, Opera 9 and now Safari 3.1 test's; any other browser people actually use??

Cheers!

smile


Moderated by  Mark 

Link Copied to Clipboard
Random Wirral Images

Click to View Topic.
Newest Topics
recommendation, please
by muzzy2 - 16th Apr 2024 7:39pm
Car paint jobs
by PaulRobson - 15th Apr 2024 9:54pm
Hi to everyone
by PaulRobson - 15th Apr 2024 1:18pm
Traffic Wardens
by Excoriator - 11th Apr 2024 4:11pm
West Kirby flood defences
by Excoriator - 10th Apr 2024 10:45pm
For Sale & Free
Wisper electric bike. 36v .
by Dilly - 21st Mar 2024 8:36pm
This is Elvis
by GingerTom - 17th Mar 2024 3:37pm
Member Spotlight
Dilly
Dilly
wallasey
Posts: 8,973
Joined: July 2011
Today's Birthdays
There are no members with birthdays on this day.
New Wirral Info
recommendation, please
by muzzy2 - 16th Apr 2024 7:39pm
Traffic Wardens
by Excoriator - 11th Apr 2024 4:11pm
Paddle Steamer Waverley
by diggingdeeper - 5th Apr 2024 7:57am
Wirral waters
by casper - 2nd Apr 2024 11:32am
Facial recognition coming in supermarkets?
by Excoriator - 27th Mar 2024 11:52am
News : New Topics
West Kirby flood defences
by Excoriator - 10th Apr 2024 10:45pm
Lost river (Well, brook really)
by Excoriator - 10th Sep 2019 9:50am
New Enthusiast Forums
Car paint jobs
by PaulRobson - 15th Apr 2024 9:54pm
Netflix 3 Body Problem.
by BultacoAstro - 22nd Mar 2024 9:04am
Any Decent Restaurant Open On a Mon Evening.
by Uffda - 21st Oct 2012 7:16pm
What song are you listening to?
by - 24th Jun 2007 10:06am
Popular Topics(Views)
5,071,215 WIKI WALK CHAT
4,017,297 Spotted!
Powered by UBB.threads™ PHP Forum Software 7.7.5