Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Apple
Re: .dmg file exploit Nov 21 2006 09:08PM
mfossi securityfocus com (2 replies)
Re: .dmg file exploit Nov 22 2006 03:05AM
Jason (security brvenik com) (1 replies)
Re: .dmg file exploit Nov 22 2006 04:04PM
Martin Roesch (roesch sourcefire com)
Re: .dmg file exploit Nov 21 2006 09:49PM
Roland Dobbins (rdobbins cisco com) (2 replies)
DNSSEC validation Sep 24 2008 07:20PM
Dave Piscitello (dave corecom com)
Re: .dmg file exploit Nov 22 2006 03:25PM
mfossi securityfocus com (1 replies)
Right. What I'm saying is that if you had that enabled and visited a
malicious site with something like a metarefresh hosting a small .dmg file
you could be exploited before you know what's going on. It'd be a bit more
like a "drive by download". In that sort of case a novice user might be
less likely to realize that something bad just happened and chalk the
reboot up to a random occurence.

You're definitely correct that the Safari thing is more of a mitigation
than anything and this needs to be fixed properly.

Marc Fossi
Symantec Corp.
www.symantec.com

On Tue, 21 Nov 2006, Roland Dobbins wrote:

>
> On Nov 21, 2006, at 1:08 PM, mfossi (at) securityfocus (dot) com [email concealed] wrote:
>
>> Yes, it's just that if 'Open "safe" files after downloading' is ebabled it
>> would be slightly more automatic. While not likely to make a difference to
>> advanced users, it would probably make it easier for novice users to be
>> exploited.
>
> I understand what you're saying, but I don't think it makes a difference.
> Ordinary users often download .dmg files to their desktops and then just
> click on them.
>
> The real fix is to alter the way OSX handles the mounting of .dmg filesystems
> (I wonder if this same class of issues exists in OSX when mounting other
> types of filesystems?). The Safari thing is a band-aid/distraction which
> actually promotes a false sense of security, IMHO.
>
> -----------------------------------------------------------------------
> Roland Dobbins <rdobbins (at) cisco (dot) com [email concealed]> // 408.527.6376 voice
>
> All battles are perpetual.
>
> -- Milton Friedman
>
>
>

[ reply ]
Re: .dmg file exploit Nov 22 2006 04:04PM
Roland Dobbins (rdobbins cisco com) (1 replies)
Re: .dmg file exploit Nov 22 2006 06:02PM
Martin Roesch (roesch sourcefire com) (3 replies)
Re: .dmg file exploit Nov 22 2006 11:25PM
Eric Hall (securityfocus darkart com)
Re: .dmg file exploit Nov 22 2006 06:40PM
Jeramey Valley (ValleyJR mps k12 mi us) (1 replies)
Re: .dmg file exploit Nov 22 2006 08:23PM
Martin Roesch (roesch sourcefire com) (1 replies)
Re: .dmg file exploit Nov 22 2006 10:44PM
stephen joseph butler (stephen butler gmail com)
Re: .dmg file exploit Nov 22 2006 06:37PM
Roland Dobbins (rdobbins cisco com) (1 replies)
Re: .dmg file exploit Nov 22 2006 08:29PM
Martin Roesch (roesch sourcefire com) (2 replies)
Re: .dmg file exploit Nov 23 2006 04:12AM
K F \(lists\) (kf_lists digitalmunition com)
Re: .dmg file exploit Nov 22 2006 08:45PM
Roland Dobbins (rdobbins cisco com) (1 replies)
Re: .dmg file exploit Nov 23 2006 10:15AM
Simon Slavin (s slavin lancaster ac uk) (1 replies)
Re: .dmg file exploit Nov 23 2006 07:53PM
K F \(lists\) (kf_lists digitalmunition com) (1 replies)
Re: .dmg file exploit Nov 23 2006 09:30PM
Howard Oakley (h oakley btconnect com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:12AM
K F (lists) (kf_lists digitalmunition com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:05PM
Simon Slavin (s slavin lancaster ac uk) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:51PM
David Maynor (dmaynor gmail com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:56PM
Simon Slavin (s slavin lancaster ac uk)







 

Privacy Statement
Copyright 2009, SecurityFocus