Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Safari (Apple browser) URL-spoofing vuln reveals how fanbois can be led astray
The Register ^ | May 20, 2015 | Alexander J Martin

Posted on 05/20/2015 8:05:38 PM PDT by dayglored

A recently published exploit for the Safari browser demonstrates a URL spoofing mechanism which might convince users they are visiting a legitimate website, when they are actually visiting another site which may be phishing their details.

Deusen researchers have disclosed a vulnerability which may be exploited by hackers to hijack user accounts on a range of websites, from social media to banking.

The proof-of-concept invites users to visit what appears to be the Daily Mail website – however, a script will execute the loading of another URL before the page users are directed to can be displayed.

Tested using Safari on the iPad, the example address-spoofing script causes the Safari browser to display dailymail.co.uk whilst the browser displays content from deusen.co.uk, although the latter can be substituted for a malicious site, say Deusen's researchers.

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: apple; ios; osx; safari
Proof of concept here -- explore at your own risk:
http://www.deusen.co.uk/items/iwhere.9500182225526788/
Thanks to tacticalogic for the heads up on this one!
1 posted on 05/20/2015 8:05:39 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Swordmaker; tacticalogic
Swordmaker: for your list (sorry about the "fanbois", it's the original title...)

Tacticalogic: I chose to post the Register's version, the Hacker News version page creeped me out, their massive script ran forever on my Firefox.

2 posted on 05/20/2015 8:07:18 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

bfl


3 posted on 05/20/2015 9:26:27 PM PDT by TEXOKIE (We must surrender only to our Holy God and never to the evil that has befallen us.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored
Swordmaker: for your list (sorry about the "fanbois", it's the original title...)

It only hurts when it's true.


4 posted on 05/20/2015 9:50:42 PM PDT by 867V309 (Boehner is the new Pelosi)
[ Post Reply | Private Reply | To 2 | View Replies]

To: 867V309

So true.


5 posted on 05/20/2015 10:49:01 PM PDT by Scutter
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ..
WARNING A german Security Site has discovered a vulnerability in the DNS structure on Safari and Chrome browsers on Apple OS X, iOS, and also Chrome on Android. Google has patched Chrome so download a new version. Apple has yet to fix the vulnerability. The proof-of-concept is extremely simple… it uses JavaScript to load up a website (dailymail), every 10 micro-seconds, which is not enough time for the website to begin loading. So it’s displaying that website address, but hasn’t actually loaded it yet. Meanwhile, it’s on a different website, which could have active malware.

As a quick fix, go to Safari Menu, Preferences, Security, uncheck Webcontent: Enable JavaScript. Problem Solved! However, you may not be able to use some sites which require JavaScript to operate. — PING!


Apple Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

Still working on the Freepathon. . . I challenge the members of the Apple ping list to each donate at least $10 each to the latest Freepathon. I HAVE donated $100. Many members of the Apple Ping list are already rising to the challenge. Join them. Let's show the power of the Apple Ping list in supporting Freerepublic!

If you have ordered an Apple Watch,
MAKE A DONATION TO THE FREEPATHON!

6 posted on 05/21/2015 1:11:56 AM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored; Swordmaker; tacticalogic

Fanbois is a French term, pron. “fon-bwa”, means “intellectual” I think. ;’)


7 posted on 05/21/2015 3:58:37 AM PDT by SunkenCiv (What do we want? REGIME CHANGE! When do we want it? NOW!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: SunkenCiv
Fanbois is a French term, pron. “fon-bwa”, means “intellectual” I think. ;’)

Imagine spending an evening with a bunch of French "intellectuals".

8 posted on 05/21/2015 4:09:18 AM PDT by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Apple fanbois can be led astray..... goes on all the time as they toss their money down an obsessive rathole buying overpriced Apple watches etc. They hang on Tim Kooks every word and before that Steve Jobs.


9 posted on 05/21/2015 4:15:03 AM PDT by dennisw (The first principle is to find out who you are then you can achieve anything -- Buddhist monk)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dennisw

Ah, thank you Dennis, I knew we could count on you to hold down your end of the spectrum with surety and aplomb.


10 posted on 05/21/2015 6:08:10 AM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Swordmaker; dayglored; tacticalogic
A German Security Site has discovered a vulnerability in the DNS structure on Safari and Chrome browsers on Apple OS X, iOS, and also Chrome on Android . . . Apple has yet to fix the vulnerability.

As a quick fix, go to Safari Menu, Preferences, Security, uncheck Webcontent: Enable JavaScript. Problem Solved! However, you may not be able to use some sites which require JavaScript to operate.

Thanks to tacticalogic for the heads up on this one! - dayglored
Thanks, SM, DG, and TL.

11 posted on 05/21/2015 10:32:40 AM PDT by conservatism_IS_compassion ('Liberalism' is a conspiracy against the public by wire-service journalism.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: tacticalogic; SunkenCiv
>> Fanbois is a French term, pron. “fon-bwa”, means “intellectual” I think. ;’)

> Imagine spending an evening with a bunch of French "intellectuals".

Ben Franklin spend considerable time in the company of French intellectuals, and it appears to have done him little or no damage.

OTOH, he also reportedly spent numerous evenings in the company of French whores. Whether it did the good Doctor any harm or not was not recorded for posterity.

12 posted on 05/21/2015 2:32:38 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: dayglored
Ben Franklin spend considerable time in the company of French intellectuals, and it appears to have done him little or no damage.

Ben himself would have been among the intellectuals of his day. Intellectualism I fear, ain't what it used to be.

13 posted on 05/21/2015 2:35:23 PM PDT by tacticalogic ("Oh, bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: tacticalogic
> Ben himself would have been among the intellectuals of his day. Intellectualism I fear, ain't what it used to be.

You sure got that right, FRiend. :)

14 posted on 05/21/2015 2:42:09 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 13 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson