Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Apple's Dashboard Hacked
Top Tech News ^ | May 9, 2005

Posted on 05/09/2005 10:51:17 PM PDT by Stoat

Apple's Dashboard Hacked

Apple's Dashboard Hacked

What makes the issue particularly difficult to deal with, according to Stephan.com, is Apple's decision not to provide a documented way to remove Widgets once installed. In fact, Apple's Mac OS X Help files state specifically that "You cannot remove widgets from the Widget Bar or change their order."
 
A developer has demonstrated a Dashboard exploit in Mac
OS X Latest News about OS X 10.4 "Tiger" that a malicious Web site owner could use to install Widgets you might not want on your Mac.

Writing under the name of Stephan.com, the developer said that a combination of Apple's Latest News about Apple lack of documentation for removing Widgets, Safari's download controls, and a Widget feature all make it possible for the bad guys to use Dashboard to take you to any Web site of their choosing, hijacking Dashboard for their nefarious purposes.

At issue is a feature in Safari called "Open safe files" that is turned on by default.

This feature allows your Mac to automatically open image files, PDFs, movies, disk images and other files considered safe when downloaded. Unfortunately, this also includes Widget files downloaded, which are installed when opened.

When combined with the ability to automatically download a file when visiting a Web page (an HTML feature not limited to Safari), Stephan.com demonstrated how easy it is for a Web site operator to autoinstall a Dashboard Widget without the consent of the user.

 


Where this really becomes a problem, however, is what the designer of the Widget does. According to Stephan.com, a Widget can be made to do such things as automatically send the user to a given Web page whenever the Widget is clicked on, and even when a user simply switches to Dashboard.

"This could be taken further, of course," wrote Stephan.com, "using all the nasty tricks developed by the [porn] industry over the last few years -- opening hundreds of different pages in a few seconds, or moving the close box around quickly. I haven't tried this, but it looks like you can trivially make a Dashboard widget continue to execute even when Dashboard isn't open."

What makes the issue particularly difficult to deal with, according to Stephan.com, is Apple's decision not to provide a documented way to remove Widgets once installed. In fact, Apple's Mac OS X Help files state specifically that "You cannot remove widgets from the Widget Bar or change their order."

The work around for this is to manually remove any particular Widget from your ~Library/Widget directory, and rebooting your Mac, but this is something that many, if not most, users won't know. That means that for many people, once a malicious Widget is installed, it's going to stay installed.

He details further examples of areas of potential problem at his Web site. Please note that visiting the demonstration page with Safari in Tiger with the "Open safe files" option turned on will install his demonstration Widget, called Zaptastic, into your Dashboard panel.

Warning: In his discussion of the issue, Stephan.com links to (but does not display) a porn image that many will find offensive and/or disturbing.



TOPICS: Business/Economy; Miscellaneous; News/Current Events; Technical
KEYWORDS: apple; dashboard; hacking; mac; macattack; secure; tiger; unhackable; widgets
Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 last
To: Swordmaker

Yes, some widgets were copied into my home library widgets folder.


41 posted on 05/10/2005 7:58:04 PM PDT by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 39 | View Replies]

To: bwteim; HAL9000
As I Freepmailed bw, I just found the problem with seeing the Widgets... I was seeking "widgets" plural, when I should have been seeking "widget" singular. Early onset of OldTimer's Disease!

On the question of the user Widget folder... mine has yet to create one in any of the sub users' directories on my computer. I logged onto another user ID and downloaded a widget... THEN it created a Widget folder in the User's library. I tried it in a user with administration privileges... and the widget went into the system's Library and did not create a user's Library. Strange. I can't find a setting that controls this behavior.

I also found that it can take some time between the installation of a widget in the Library/Widgets folder and its appearance in the Widgets dock in Dashboard... One widget I downloaded and installed took over 25 minutes before it appeared in the Widget Dock! I am beginnig to think that there is some flakiness with the widget handlers. One of the test widgets from the Zaptastic website took about 5 minutes to disappear from the Widget Dock after I had dragged it to the Trashcan and emptied the Trash. Even quitting and restarting the Dashboard didn't seem to force a change. Its icon even survived a system restart after deletion but it would not run or install on the Dashboard.

In addition, Spotlight doesn't always go away as quickly as it should... and this is a problem because if you have the spotlight show-all window open and click on another app, the Spotlight showp-all window is unfocused in favor of the window you clicked on but the Spotlight summary or search window is still active and pre-empting Finder. To get rid of it, you have to click in the search field and THEN click elsewhere.

I think Spotlight needs some interface tweaking. Are you guys experiencing this or is it just my G5?

42 posted on 05/10/2005 9:18:21 PM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: bwteim; HAL9000
I just downloaded a widget in a subuser's account. The ~/Library/Widgets folder was created and the new widget was installed there. I then returned to my Admin account and the new widget was not available. So individual users can have unique widgets on their account as well as access to those the administrator accounts download.

Incidentally, the widget appeared in the user's widget dock immediately. No delay at all. hmmmmm. I have to try again today and see if there is any delay in a widget downloaded to the Admin account... or was that some artifact of yesterday?

43 posted on 05/10/2005 9:29:52 PM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 42 | View Replies]

To: Swordmaker
The widgets may have gotten installed in my home directory by downloading and launching them from the Desktop.

I just looked at the Dashboard API in XCode, and it seems relatively simple to develop a widget. Perhaps someone will develop a FreeRepublic Dashboard widget to show latest posts, show pings, start a new thread, etc.

44 posted on 05/10/2005 9:30:05 PM PDT by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 42 | View Replies]

To: Swordmaker
Have you tried FreeRepublic's RSS feed on Safari? -

http://www.freerepublic.com/focus/f-news/browse.rss

45 posted on 05/10/2005 9:36:52 PM PDT by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 43 | View Replies]

To: bwteim; HAL9000

The Widget handler has not problem with having a widget in both the System Library and the User's library... that's good. BUT a couple of widgets from the system library in the user's doc have incomplete icons. The Brittanica icon is complete in my account but is merely a blue square in the users account. It works both places but something is broke.

Interesting.

As to the RSS feed from FreeRepublic... Not yet but I will. Thanks for reminding me.


46 posted on 05/10/2005 9:51:18 PM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 44 | View Replies]

To: HAL9000; bwteim
I found a strange... and a possible explanation. I was trying to find out why the Safari in my account was acting differently in handling the widgets than the Safari's were in sub-users' accounts. I think I found it. A couple of years ago I tried out Speed Downloader... but didn't like it. I uninstalled it and forgot about it.

Searching for differences in the Safari's I found that MINE still had a plug-in for Speed Downloader and that somehow interfered with the proper downloading on my account. This apparently has only impacted the Widget installation... after I located this plug-in in my user (~/Library/Internet Plug-ins) Library and removed it, the download created a ~/Library/Widgets folder and placed a downloaded widget into it! With the plug-in, it placed it in the System widget folder. STRANGE.

47 posted on 05/10/2005 10:27:05 PM PDT by Swordmaker (tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 45 | View Replies]

To: Petronski

>>
Well, I guess OS 10.4.1 is coming very soon. LOL
<<

I hope so. Tiger blows.


48 posted on 05/11/2005 9:38:17 AM PDT by noblejones
[ Post Reply | Private Reply | To 3 | View Replies]

To: John Valentine

I installed a little freeware program, "Widget Manager". Soles any potential problems.


49 posted on 05/11/2005 9:40:37 AM PDT by MrLee
[ Post Reply | Private Reply | To 13 | View Replies]

To: noblejones
Tiger blows.

Is it really that bad? I'm still at 10.2. (I forget which cat that was) I was thinking of finally upgrading the OS on my G4 along with installing a Radeon 9K card and more memory.

What's your beef with Tiger? Would it be better to hold off?

50 posted on 05/11/2005 9:43:25 AM PDT by avg_freeper (Gunga galunga. Gunga, gunga galunga)
[ Post Reply | Private Reply | To 48 | View Replies]

To: avg_freeper

>>
What's your beef with Tiger? Would it be better to hold off?
<<

It's messed up all of my apps. I think this is an exteme case, but I am certainly not pleased. If I were you, I'd wait 'til the 10.4.1 update is ready.


51 posted on 05/11/2005 11:54:38 AM PDT by noblejones
[ Post Reply | Private Reply | To 50 | View Replies]

To: Swordmaker
Tiger is not installed on the machine I bought, but they gave me a copy to download.

Does the mini have any software on it that would compare to Microsoft Office?

I really know nothing about macs and am lost. The help section leaves a little to be desired. Is there a mac's for dummy's anywhere? :)

BigMack

52 posted on 05/11/2005 12:51:32 PM PDT by PayNoAttentionManBehindCurtain (Don't be afraid to try: Remember, the ark was built by amateur's, and the Titanic by professionals.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: PayNoAttentionManBehindCurtain
Does the mini have any software on it that would compare to Microsoft Office?

I believe the mini includes an application called AppleWorks. It is relatively old, but it works okay and includes word processing, a spreadsheet, graphic design and database processing.

Apple has a new program for $79 called iWork which includes a word processor and a presentation design program.

53 posted on 05/14/2005 12:00:28 AM PDT by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 52 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-53 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson