 |
|
|
|
 |
|
 |
 |
Stilez
RealTalk & Srsbidniz

Registered: Dec 2001
Location: here & there
|
|
|
| quote: | Description:
Juan Pablo Lopez Yacubian has discovered two vulnerabilities in Safari, which can be exploited by malicious people to conduct spoofing attacks or potentially compromise a user's system.
1) An error when downloading e.g. a .ZIP file with an overly long filename can be exploited to cause a memory corruption.
Successful exploitation may allow execution of arbitrary code.
2) An error in the handling of windows can be exploited to display arbitrary content while showing the URL of a trusted web site in the address bar.
The vulnerabilities are confirmed in version 3.1 for Windows. Other versions may also be affected.
Solution:
Do not browse untrusted web sites.
Provided and/or discovered by:
Juan Pablo Lopez Yacubian
|
SOURCE
Another quote:
| quote: | The hack came during the Pwn2Own contest, which is being held at the CanSecWest conference in Vancouver. The competition took place in a conference room overlooking the city's Burrard Inlet, a harbor where pontoon planes took off and disappeared into black rain clouds shrouding nearby Grouse Mountain. A small round of applause broke out immediately after contest officials confirmed Miller's exploit was legit.
At time of writing, the Windows and Linux machines were still standing.
Under contest rules, Miller was forbidden from providing specifics of his hack. He said he chose Apple over the other machines because "I thought of the three it was the easiest". He said he didn't test the exploit on any other platform. As a Mac user, he added, he felt an incentive to exploit the system because he believes it will help make the platform stronger. Miller, who works for Independent Security Evaluators, received help from co-workers Jake Honoroff and Mark Daniel. |
___________________
Real Eyes, Realize, Real Lies.
Twitter | YouTube | Instagram | Soundcloud | MixCloud | BLOG
|
|
Mar-30-2008 01:58
|
|
|
 |
All times are GMT. The time now is 18:25.
Forum Rules:
You may not post new threads
You may not post replies
You may not edit your posts
|
HTML code is ON
vB code is ON
[IMG] code is ON
|
|
|
|
|
|
Contact Us - return to tranceaddict
Powered by: Trance Music & vBulletin Forums
Copyright ©2000-2026, Jelsoft Enterprises Ltd.
Privacy Statement / DMCA
|