Apple's carpet-bomb Safari flaw can wreak havoc on Windows

A researcher has created a proof-of-concept site that graphically demonstrates the risk Windows users face when using Apple"s Safari browser. Microsoft"s security team already warned that a "blended threat" was so serious that Windows users should curtail their use of Safari until a security patch is available. This blog post from researcher Liu Die Yu makes it clear the warning was by no means overstated.

Clicking on this link with Safari using default settings automatically downloads a booby-trapped file onto a Windows user"s desktop with no prompting. The next time the user opens Internet Explorer, the force-fed file automatically causes the notepad.exe application to launch and open a non-existent file. Of course, miscreants could choose far more nefarious code.

When informed that its browser downloads files with no prompting, Apple said it may get around to changing this behavior at some point. In other words, this is no big deal from a security perspective, so let"s all move on. This demo suggests otherwise.

View: The full story @ The Register

Report a problem with article
Next Article

Bob Muglia to deliver Tech-Ed IT Professionals keynote today

Previous Article

Cyber-crooks hit one in five Europeans