Back to list
Apple Safari on MacOSX may reveal user's saved passwords
May 14 2007 01:50PM
poplix papusia org
It seems that safari fails to validate the source of injected code, however apple belives this is the correct behaviour so no fixes will be made available.
this proof of concept scpt file will display the password loaded by safari into an html object named "password":
tell application "Safari"
comments are welcome
[ reply ]
RE: Apple Safari on MacOSX may reveal user's saved passwords
May 14 2007 08:58PM
Lucas, Mark J. (mjlucas caltech edu)
Re: Apple Safari on MacOSX may reveal user's saved passwords
May 16 2007 03:53PM
stephen joseph butler (stephen butler gmail com)
Copyright 2010, SecurityFocus