Newsgab  
     

Left Nav Register FAQ Members List Calendar Search Today's Posts Mark Forums Read Right Nav

Left Container Right Container
 

Go Back   Newsgab » News » Tech News

Notices

About this page:

Discuss the post Safari 'carpet Bomb' Attack Code Released made within our Tech News forum; Post Snippet: Safari 'carpet Bomb' Attack Code Released Robert McMillan, IDG News Service 29 minutes ago A ...

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10th June 2008, 11:42 PM
tjw61's Avatar
Super Moderator


 
Join Date: May 2006
Location: New Jersey U.S.A.
Posts: 4,002
Rep Points : 4146
Rep Power: 28
tjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond repute
Default Safari 'carpet Bomb' Attack Code Released

Safari 'carpet Bomb' Attack Code Released
Robert McMillan, IDG News Service
29 minutes ago


A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers.


The source code, along with a demo of the attack, was posted Sunday on a computer security blog. It can be used to run unauthorized software on a victim's machine, and could be used by criminals in Web-based computer attacks, security experts say.


Now that there is a public example of the attack code, Safari users running the Windows operating system should be concerned, said Eric Schultze, chief technical officer at Shavlik Technologies. "This is a bad thing. If you've got Safari, you're in trouble," he said.


The Safari bug, originally disclosed on May 15 by security researcher Nitesh Dhanjani, allows attackers to litter a victim's desktop with executable files, an attack known as "carpet bombing."


Two weeks later, security researcher Aviv Raff said that if this flaw is exploited in combination with bugs in Windows and Internet Explorer, attackers can run unauthorized software on a victim's computer.


Apple has reportedly said that it has no plans to patch the Safari flaw, but Microsoft released a security advisory on the problem on May 30, a sign that it may be working on a patch.


Microsoft's advisory says that the vulnerability has to do with the way Windows handles desktop executables and recommends that Windows users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple."


The attack affects all versions of Windows XP and Vista, Microsoft said in its advisory.


Apple could not be reached for comment on this story. Microsoft Security Response Team members were in meetings and unable to comment on this issue, a spokesman with the company's public relations agency said
__________________
''Life's tough........it's even tougher if you're stupid.'' -John Wayne

"The main difference between the wise man and a fool is that a fool's mistakes never teach him anything." -Unknown

"With age comes the realization of mortality" -Tom Woods
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote


Reply

Tags
attack, bomb, carpet, code, released, safari

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hackers Find Use For Google Code Search wildwood Tech News 0 8th October 2006 09:49 PM
Attack Code Targets New IE Hole Gab Bot Latest Gabs 0 19th September 2006 12:39 PM


All times are GMT +1. The time now is 06:56 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
 
 




1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32