image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #1  
Old March 2nd, 2006, 09:22 AM
sirstaunch's Avatar
Registered User
 
Join Date: May 2005
Location: Australia
Posts: 510
Thanks: 0
Thanked 0 Times in 0 Posts
sirstaunch is on a distinguished road
Security Check

Hope this is the right spot, but this is a vunerability check on your OS, I did the Security update today so it passed on me so wonder if it happens on someone elses machine who hasn't updated. Should be harmless but I take no responsibility

Quote:
Apple Mac have had a bad press last few weeks over security. Here a little test to see if you are vulnerable to a weakness in Safari and Mail.

http://secunia.com/mac_os_x_command_...rability_test/

Follow the instructions regarding the link and if you have the application calculator open then you are vulnerable and therefore should run you software update and download the latest security update from apple named Apply Security Update 2006-001.

Be interesting to know if this test is real or not??
__________________
PowerPC5200 48mb 80mhz OS8.6
PowerPC7500 192mb 180mhz OS9.2.2
eMac 1.42ghz (now) 1GIG Ram (just added extra 512mb 30/8/07) OSX10.4.10
It Keeps Getting Better!!!
Reply With Quote
  #2  
Old March 2nd, 2006, 10:07 AM
Registered User
 
Join Date: May 2005
Posts: 1,339
Thanks: 0
Thanked 1 Time in 1 Post
barhar is on a distinguished road
01. The file 'Secunia.mov.zip' is downloaded to your Macintosh.

Now, all the 'ifs' ...

02. If 'Safari' is your web browser, and if its 'Preferences', 'General' tab panel's 'Open "safe" files after downloading' check box is check marked, then the '.zip' file will be automatically de-compressed (to 'Secunia.mov'). However, the '.mov' file has the permissions of '-rwxr-x--x'; therefore, MacOS X will run (open, launch, execute) the executable file.

What is in the 'Secunia.mov' file? ...

/Applications/Calculator.app/Contents/MacOS/Calculator; exit

. Naturally, nowhere on the Secunia web page or its 'What should you do?' linked web page - is it stated to uncheck the 'Open "safe" files after downloading' check box.

-----

Summary:

By not having 'Safari's 'Preferences' 'General' tab panel's 'Open "safe" files after downloading' check box check marked; and / or any other web browser's 'Preferences' set similarly; and, having ones download folder set to List view - one would immediately note the 'kind' of the 'Secunia.mov' file as 'Terminal document', instead of 'QuickTime Movie'.

---

The same advise was made around April 2004 when the 'MP3Concept' MacOS X Trojan horse was released. Oops, sorry - the 'proof of concept' '.mp3' file was noted by the security firms [(1), (2), etc.], press [(1), (2), etc.], and lesser informed [those who have posted to macosx.com and similar web sites, stating - I have virus, worm, or trojan horse ...]. In that particular case, the List view 'kind' of the .mp3' file was 'Application', instead of 'Preview', 'GraphicConverter', etc.

---

Apple's 'Mail' is not my primary e-Mail'er application; therefore, I have no say as to its actions related to the 'Secunia.mov.zip' file.

Supposedly, the recent 'Security Update 2006-001', at Apple Downloads, as by 'MacWorld' - resolves such issues.

Last edited by barhar; March 3rd, 2006 at 09:30 PM.
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Check this out: bobbo Bob's Place 1 October 26th, 2004 09:47 PM
Site Check/ Opnion Check Browni Design & Media 9 October 10th, 2004 03:26 PM
Check This Dris Design & Media 13 August 5th, 2003 05:33 PM
NEW VCD app- Check this out!!! Floyd Design & Media 0 April 23rd, 2003 07:12 PM


All times are GMT -5. The time now is 01:36 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.