Get all your news in one place.
100’s of premium titles.
One app.
Start reading
The Guardian - UK
The Guardian - UK
Technology
Jack Schofield

Malware writers may be delighted with Safari for Windows

Safari for Windows is only a public beta, which is just as well. Security researchers and malware writers explored it with some relish, and Thor Larholm proclaimed: Safari for Windows, 0day exploit in 2 hours. He notes:



URL protocol handlers on the Windows platform work by executing a process with specific command line arguments. When Apple released Safari for the Windows platform they neglected to implement a proper level of input validation for these arguments, which means that you can break out of the intended confines and wreak havoc.



David Maynor at Errata Security reports that "Using publicly available tools we had a DoS in no time."



I'd like to note that we found a totl of 6 bugs in an afternoon, 4 DoS and 2 remote code execution bugs. We have weaponized one of those to be reliable and its diffrent that what Thor has found. The exploit is robust mostly thanks to the lack of any kind of adanced security features in OS X.



Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.