x404.co.uk http://www.x404.co.uk/forum/ |
|
Safari security issues http://www.x404.co.uk/forum/viewtopic.php?f=3&t=12961 |
Page 1 of 1 |
Author: | bobbdobbs [ Thu Mar 10, 2011 8:34 am ] | ||||||||||||||||||
Post subject: | Safari security issues | ||||||||||||||||||
Just to balance CC ![]() Safari/MacBook first to fall at Pwn2Own 2011 clicky
and he won 15k plus a mac book air. |
Author: | HeatherKay [ Thu Mar 10, 2011 8:39 am ] |
Post subject: | Re: Safari security issues |
I have a feeling this was patched yesterday. Don't quote me on that, though. |
Author: | adidan [ Thu Mar 10, 2011 9:04 am ] |
Post subject: | Re: Safari security issues |
I had visions of a monkey shield. |
Author: | MrStevenRogers [ Thu Mar 10, 2011 9:17 am ] | |||||||||||||||||||||||||||
Post subject: | Re: Safari security issues | |||||||||||||||||||||||||||
well done that man and have just updated ... |
Author: | big_D [ Thu Mar 10, 2011 9:31 am ] |
Post subject: | Re: Safari security issues |
The problem is, OS X has pretty much stood still, in terms of security measures over the last 5 years and now lags behind Windows 7. The Apple implementation of DEP and ASLR are fundamentally flawed, which was pointed out, when it came out in 2008, and Apple haven't addressed the issue in the interviening time, even Lion doesn't address the flaws in the implementation of ASLR. Basically, ASLR should randomise where programs are loaded in memory. In Windows, this includes the underlying operating system and key libraries as well. Under OS X, it only applies to applications, not to system libraries and the OS itself. This means, that, once you have an exploit in an application, like Safari, you can't attack its memory or the memory of 3rd party applications, but if you also have a flaw in the base OS, you can exploit it, because you know where it is... It is interesting, OS X has gone from secure plus security through obscurity (there aren't enough devices out there to warrant developing exploits for it), to just security through obscurity... And with increasing market share, they are also becoming less obscure. That isn't to say that Microsoft don't have problems, just that they have addressed a lot of the key technologies which were causing problems and have toughened up the default security. In contrast, Apple seem to be sitting on security issues, until it is pointed out that they haven't patched a bug - a lot of the bugs that have been patched recently are in open source software, where the open source projects themselves (often projects run by Apple!) have released patches up to 18 months ago, but Apple haven't "bothered" to implement them, until they get bad press... |
Author: | steve74 [ Thu Mar 10, 2011 9:35 am ] |
Post subject: | Re: Safari security issues |
Apple issued the Safari 5.0.4 yesterday and also some Java Updates to address security issues. I wonder if they intentionally didn't download these before they started? Not that this makes it OK, as there must have been vulnerabilities there before these patches, but Apple's release date implies that they were issued because they knew this event was coming this week. I wonder if they were using Safari 5.0.4 or the older 5.0.3? |
Author: | jonbwfc [ Thu Mar 10, 2011 11:26 am ] | ||||||||||||||||||
Post subject: | Re: Safari security issues | ||||||||||||||||||
It may possibly be that the patches were released within the timescale of the competition being active, so the effect you get is the hack can be used to win the competition but by the time it's publicized it's no longer as useful. I'd imagine all parties involved would be fairly happy with that. Jon |
Author: | bobbdobbs [ Thu Mar 10, 2011 12:15 pm ] | ||||||||||||||||||
Post subject: | Re: Safari security issues | ||||||||||||||||||
clicky
clicky |
Author: | big_D [ Sat Mar 12, 2011 11:50 am ] |
Post subject: | Re: Safari security issues |
Just to balance things, Apple's update to iTunes has fixed over 50 bugs, many critical, in Webkit... |
Page 1 of 1 | All times are UTC |
Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ |