Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > News and Article Discussion > MacRumors.com News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread  
Old Jan 13, 2009, 08:39 AM   #1
Habakuk
macrumors 6502
 
Join Date: Jul 2007
Location: Vienna Austria Europe
Vulnerability in Safari

http://www.heise-online.co.uk/news/V...afari--/112402
__________________
Blog: Die besten iPhone-Tipps (German-language)
Details on my MacBook Pro and iPhone 3G
Habakuk is offline   Reply With Quote
Old Jan 13, 2009, 09:36 AM   #2
Tallest Skil
Banned
 
Join Date: Aug 2006
Location: 1 Geostationary Tower Plaza
Here's my opinion: We'll be getting a Safari update soon! Yay!
Tallest Skil is offline   Reply With Quote
Old Jan 13, 2009, 09:47 AM   #3
r.j.s
macrumors Demi-God
 
r.j.s's Avatar
 
Join Date: Mar 2007
Location: Margaritaville
Good thing I don't use Safari to handle my RSS feeds.
r.j.s is offline   Reply With Quote
Old Jan 13, 2009, 12:10 PM   #4
MacRumors
macrumors bot
 
Join Date: Apr 2001
Security Vulnerability Found in Safari RSS



Open source programmer Brian Mastenbrook has discovered a security flaw in the way that Safari handles RSS feeds. The vulnerability, which affects both Mac and Windows versions of Safari, could allow a malicious website to gain access to sensitive user data.

Quote:
I have discovered that Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention. This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites. The vulnerability has been acknowledged by Apple.
Mastenbrook reports that all OS X 10.5 Leopard users, regardless of whether they use Safari or RSS feeds, should protect themselves by choosing an application other than Safari for reading RSS feeds, an option available in the "RSS" tab of Safari's Preferences. Safari for Windows users should utilize a different browser until Apple issues a patch. Mastenbrook, who has received credit from Apple for reporting a number of security issues over the past year, says that Apple has not given a timeframe for a fix.

Article Link: Security Vulnerability Found in Safari RSS
MacRumors is offline   Reply With Quote
Old Jan 13, 2009, 12:12 PM   #5
plumbingandtech
macrumors 68000
 
Join Date: Jun 2007
The temp fix is very easy. Everyone should do so now:


Quote:
Open Safari and select Preferences... from the Safari menu.
Choose the RSS tab from the top of the Preferences window.
Click on the Default RSS reader pop-up and select an application other than Safari.
__________________
The Palm Pre is the new Sarah Palin.
plumbingandtech is offline   Reply With Quote
Old Jan 13, 2009, 12:13 PM   #6
chainprayer
macrumors 6502
 
Join Date: Feb 2008
Send a message via AIM to chainprayer
Scary. Its amazing what people can do today. Everything was so simple before the internet :P
__________________
Pray365.net - Post prayer requests on our board (no registration needed) or text/call prayer requests to 623-252-5734.
chainprayer is offline   Reply With Quote
Old Jan 13, 2009, 12:17 PM   #7
Jayomat
macrumors 6502
 
Join Date: Jan 2009
Location: Rainy-Town
I hope people start realizing that Safari isn't, as apple puts it, "the world's best browser".......
Jayomat is offline   Reply With Quote
Old Jan 13, 2009, 12:18 PM   #8
pimentoLoaf
macrumors Demi-God
 
pimentoLoaf's Avatar
 
Join Date: Dec 2001
Location: The SimCity Deli
So ... who makes the best RSS reader?
__________________
A pate is nothing more than a French meat loaf that's had a couple of cocktails....Carol Cutler
pimentoLoaf is offline   Reply With Quote
Old Jan 13, 2009, 12:22 PM   #9
Spades
macrumors 6502
 
Join Date: Oct 2003
If this doesn't affect Mail, you can switch to that as your RSS reader. I've been using Mail as my RSS reader since Leopard came out. Works better than Safari did.
Spades is offline   Reply With Quote
Old Jan 13, 2009, 12:25 PM   #10
Drumjim85
macrumors 68020
 
Drumjim85's Avatar
 
Join Date: Oct 2007
Location: DFW, TX
Quote:
Originally Posted by pimentoLoaf View Post
So ... who makes the best RSS reader?
google?
__________________
Creative Commons - because copyright is broken.
Drumjim85 is offline   Reply With Quote
Old Jan 13, 2009, 12:35 PM   #11
fendol
macrumors 6502
 
Join Date: Nov 2008
I don't use RSS, but for those who do this looks like something serious as they can access your hardrive just like that. Remember this is for both Windows and Mac safari users
__________________
[...] the ones who are crazy enough to think that they can change the world, are the ones who do. - Steve Jobs
fendol is offline   Reply With Quote
Old Jan 13, 2009, 12:37 PM   #12
J the Ninja
macrumors 65816
 
J the Ninja's Avatar
 
Join Date: Jul 2008
Quote:
Originally Posted by pimentoLoaf View Post
So ... who makes the best RSS reader?
Firefox. Live bookmarks!
__________________
"My fall will be for you. My love will be in you. You were the one to cut me, so I'll bleed forever..."
J the Ninja is offline   Reply With Quote
Old Jan 13, 2009, 12:39 PM   #13
acxz
macrumors regular
 
Join Date: Nov 2007
They say switch to an alternative RSS reader, but surely if you stick to reputable feeds this won't be an issue?

Should be interesting to see how long it takes Apple to release a patch anyhow.
acxz is offline   Reply With Quote
Old Jan 13, 2009, 12:39 PM   #14
andiwm2003
macrumors Demi-God
 
andiwm2003's Avatar
 
Join Date: Mar 2004
Location: Boston, MA
thats bad for mac users. windows users are used to such things anyway.

i hope apple fixes that soon. i'm actually surprised that OS X allows that to happen. i guess lots of other apps have similar gaps.
andiwm2003 is offline   Reply With Quote
Old Jan 13, 2009, 12:41 PM   #15
EmperorDarius
macrumors 6502a
 
Join Date: Jan 2009
Quote:
Originally Posted by Jayomat View Post
I hope people start realizing that Safari isn't, as apple puts it, "the world's best browser".......
Why not? No browser is immune to vulnerabilities.
EmperorDarius is offline   Reply With Quote
Old Jan 13, 2009, 12:44 PM   #16
lowbatteries
macrumors regular
 
Join Date: Mar 2008
Quote:
Originally Posted by pimentoLoaf View Post
So ... who makes the best RSS reader?
It depends on how you use RSS feeds. If you read them like email, where each post deserves your attention, use Mail. If you use them just to see what's the latest on a particular website, Firefox live bookmarks are nice.

I use NetNewsWire just so I have syncing between my Mac and my iPhone.

First though I would see what programs are already in your Dock and check on their RSS options - if you already have Firefox, Safari, Mail, Thunderbird, or any other browser or mail program running, use those. No use in running another always-on program if you don't need to.

Like another poster said, if you are only getting RSS feeds from reputable sites (and no comments feeds - those could be bad), Safari should be fine.

Last edited by lowbatteries : Jan 13, 2009 at 12:49 PM. Reason: adding in Thunderbird as an option
lowbatteries is offline   Reply With Quote
Old Jan 13, 2009, 12:45 PM   #17
NATO
macrumors 65816
 
NATO's Avatar
 
Join Date: Feb 2005
Location: Northern Ireland
Does this mean you'd have to subscribe to an 'infected' RSS feed in order to be vulnerable? ie, would you be okay to continue using Safari for RSS if you're only using reputable feeds, eg. MacRumors?

Edit - Whoops, skimmed through the posts and managed to miss the one that actually seemed to answer my question.. doh
__________________
iMac 27" 3.06GHz Core 2 Duo 4GB RAM
MacBook Pro 17" (Unibody) 2.66GHz Core 2 Duo 4GB RAM
Mac Mini 1.66Ghz Core Duo
iPhone 3G S 32GB
NATO is offline   Reply With Quote
Old Jan 13, 2009, 12:47 PM   #18
lowbatteries
macrumors regular
 
Join Date: Mar 2008
Quote:
Originally Posted by Jayomat View Post
I hope people start realizing that Safari isn't, as apple puts it, "the world's best browser".......
I think its a matter of opinion what the BEST browser is. I think its safe to say what the world's WORST browsers are, in order:

1. IE6
2. IE7
3. IE8

So I think the "world's best browser" is ANY browser that isn't IE.

EDIT: I just realized that most standard cell phone browsers should be in that list too.

Last edited by lowbatteries : Jan 13, 2009 at 12:52 PM.
lowbatteries is offline   Reply With Quote
Old Jan 13, 2009, 12:53 PM   #19
Sehnsucht
macrumors 65816
 
Join Date: Sep 2008
Quote:
Originally Posted by lowbatteries View Post
EDIT: I just realized that most standard cell phone browsers should be in that list too.
IE mobile (for WinMo) sucks ass. I used to have a Motorola Q and threw that thing as far as I could.
__________________
Farewell...
Sehnsucht is offline   Reply With Quote
Old Jan 13, 2009, 01:06 PM   #20
lkrupp
macrumors member
 
Join Date: Jul 2004
Quote:
Originally Posted by Jayomat View Post
I hope people start realizing that Safari isn't, as apple puts it, "the world's best browser".......
Let's see now. You joined MacRumors just this month and are already trolling away. So why are you here anyway? Are you a Mac user? A Windows fanboy?

So should we all crawl under our beds in fear now? I, for one, don't plan on doing anything. Notice that the "researchers" always use words like "might", "could", "maybe", "under certain conditions"? Isn't the only thing we have to fear supposed to be fear itself? Chicken Little's are always ready to wring their hands and fret. What a way to live one's life, in constant fear.
lkrupp is offline   Reply With Quote
Old Jan 13, 2009, 01:09 PM   #21
settledown
macrumors regular
 
Join Date: Feb 2003
Location: pittsburgh
My RSS reader...

I have set Chess to be my RSS feed reader.

I think that should fix it.
__________________
sig.'s waste time and brain bandwidth
settledown is offline   Reply With Quote
Old Jan 13, 2009, 01:10 PM   #22
MarkMS
macrumors 6502a
 
Join Date: Aug 2006
Straight from Brian Mastenbrook's website:
Quote:
... users of Mac OS X Leopard should protect themselves until a fix is issued by Apple by choosing a default feed reader other than Safari, such as Mail.

So those who don't use RSS apps can just link up to Mail.app and be okay for now.
MarkMS is offline   Reply With Quote
Old Jan 13, 2009, 01:13 PM   #23
lkrupp
macrumors member
 
Join Date: Jul 2004
Quote:
Originally Posted by r.j.s View Post
Good thing I don't use Safari to handle my RSS feeds.
So how do you know that what you do use isn't just as vulnerable, hmmmm?
lkrupp is offline   Reply With Quote
Old Jan 13, 2009, 01:24 PM   #24
SFStateStudent
macrumors Demi-God
 
SFStateStudent's Avatar
 
Join Date: Aug 2007
Location: San Francisco California, USA
Send a message via AIM to SFStateStudent Send a message via Yahoo to SFStateStudent Send a message via Skype™ to SFStateStudent
Has Safari 4.0 addressed this issue? I've already defaulted RSS to FF, though I've never used RSS...
__________________
MBP 2.5GHz 250GB Mac Pro 3G S⃣ iPhone 32GB Black
SFStateStudent is offline   Reply With Quote
Old Jan 13, 2009, 01:32 PM   #25
thejadedmonkey
macrumors 68040
 
thejadedmonkey's Avatar
 
Join Date: May 2005
Location: Pa
Send a message via AIM to thejadedmonkey
Quote:
Originally Posted by lowbatteries View Post
I think its a matter of opinion what the BEST browser is. I think its safe to say what the world's WORST browsers are, in order:

1. IE6
2. IE7
3. IE8

So I think the "world's best browser" is ANY browser that isn't IE.

EDIT: I just realized that most standard cell phone browsers should be in that list too.
Dude, I'm using IE8 right now, and aside from some minor bugs, it's really nice. I don't see how you can complain about something that's not even out of beta yet!

You're also forgetting that when IE6 came out, it was a really good browser. There were no CSS issues because there were no browser wars- IE6 was the internet.

Don't forget about IE for mac. That was one of the BEST browsers out there, for quite some time.
__________________
Mac Mini G4 • MacBook Pro • iPod Nano
"Good judgement comes from experience,
experience comes from bad judgement.
- Mark Twain
thejadedmonkey is offline   Reply With Quote

Reply

Mac Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:54 PM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC