• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Malicious Web Pages Can Install Dashboard Widgets

Status
Not open for further replies.

goodcow

Member
Malicious Web Pages Can Install Dashboard Widgets
Security
OS X
Apple
Posted by timothy on Sunday May 08, @05:49PM
from the not-good dept.
bonch writes "If you're running Safari on OS X Tiger and go to this website, a 'slightly evil' Dashboard widget will be automatically downloaded and installed and can't be removed without manually removing the file from the Library folder and rebooting the computer. The widget is called Zaptastic and is a demonstration by the author of how easy it is to exploit Dashboard for nefarious purposes. The essay, released under the Creative Commons License, goes on to describe the many ways users can be taken advantage of--imagine porn sites auto-installing adware widgets without your knowledge." So if you're on a Mac, it would be smart to view that page with something other than Safari.
 

Phoenix

Member
Start the timer, lets see how long it will be before Apple patches this one. This is a fairly serious exploit in my opinion since Dashboard widgets don't live in a permission sandbox.
 

Phoenix

Member
Matlock said:
Man it's great to have an OS that's not vulnerable like windows oh wait


Hehe - yeah, disconnect your box from your firewall, plug in directly into the internet and then make that comment :)
 

AB 101

Banned
Weeks? :lol


Well, Apple is not quite as efficient as MS in doing updates.

MS has gotten good. Well, they have to do almost daily security fixes for the massive breach of security Windows is. :lol
 
Status
Not open for further replies.
Top Bottom