Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Safari AutoFill flaw opens up Mac OS X address book to hackers
betanews ^ | July 22, 2010 | Ed Oswald

Posted on 07/23/2010 2:15:59 AM PDT by Leroy S. Mort

WhiteHat Security said Wednesday that it had found an issue in how Safari's AutoFill feature handles personal information, which could open up the personal information of a web surfer simply by visiting a malicious website.

Using a few lines of code, the hacker would be able to obtain the information without the user even knowing it occurred. The "Using info from my Address Book card" option would need to be checked in AutoFill preferences in order for the hack to work.

There is one positive: AutoFill does not work with fields starting with numbers, meaning street addresses and phone numbers would not be able to be accessed using publicly available code.

It is believed that the flaw resides within the WebKit engine that powers Safari. Grossman tried the exploit code on Google's Chrome browser which also uses the WebKit engine, but was unable to replicate the issue.

WhiteHat founder and CTO Jeremiah Grossman said in a blog post that he had attempted to contact Apple prior to disclosure of the vulnerability twice, but had received no response.

"I have no idea when or if Apple plans to fix the issue, or even if they are aware, but thankfully Safari users only need to disable AutoFill web forms to protect themselves," he mused.

While the flaw is not serious since it only seems to be able to steal a user's name, city, state, country, and e-mail, it still could open up the user to spam. Hackers could use additional techniques to phish further information on the victim if they so desired.


TOPICS: Crime/Corruption; Miscellaneous
KEYWORDS: apple; computers; drinkscornsyrup; drivesyuego; dumptsterdiver; getalife; getoffmycomputer; gorevoter; ipad; killspuppies; koskid; licksbuswindows; loveshillary; lovesmoslems; mac; moronposting; neverbaths; neverflushestoilet; offofmeds; petrock; postsatdu; poxonkeywordspammers; pugetsoundsoldiergay; ranoutofmeds; rattleingthecage; redmondemployee; slownight; smokescameldung; smokesvirginiaslims; trollingfordu; trypostingrealnews; webbrowsers; whocares; windozfanboy
Apple was notified of this flaw on June 17th. Hopefully a fix is forthcoming. Til then Safari users might be wise to disable AutoFill.
1 posted on 07/23/2010 2:16:01 AM PDT by Leroy S. Mort
[ Post Reply | Private Reply | View Replies]

To: Leroy S. Mort

Autofill is dangerous on any browser. Aside from the various remote hacks that have happened over the years, any casual passer-by can strip things like credit card numbers and other personal data from your machine if left alone with it for a few minutes - if Autofill is on.


2 posted on 07/23/2010 2:58:37 AM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leroy S. Mort
This cannot be! OSX and Safari are the safest things ever, they are invulnerable, nothing can access your information or compromise the system at all!

Next you're going to say that the App Store does not allow apps which do something other than what they purport to do!

HOW DARE YOU QUESTION THE INVINCIBILITY OF APPLE!

/sarc

3 posted on 07/23/2010 3:40:42 AM PDT by PugetSoundSoldier (Indignation over the Sting of Truth is the defense of the indefensible)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PugetSoundSoldier

Hater!


4 posted on 07/23/2010 3:46:18 AM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Leroy S. Mort
That damn unsecure Microsoft again!
5 posted on 07/23/2010 4:44:20 AM PDT by rightwingextremist1776
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leroy S. Mort

The headline is misleading. The flaw does not provide access to the “Mac OS X address book”, it can gain access to some of the information off of a single address book record (the user’s own), assuming the user has certain options enabled.


6 posted on 07/23/2010 4:55:58 AM PDT by kevkrom (De-fund Obamacare in 2011, repeal in 2013!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kevkrom

That’s kinda splitting hairs, isn’t it. How would you have written the headline for betanews?


7 posted on 07/23/2010 6:23:51 AM PDT by Leroy S. Mort
[ Post Reply | Private Reply | To 6 | View Replies]

To: Leroy S. Mort
That’s kinda splitting hairs, isn’t it. How would you have written the headline for betanews?

No, I don't think it is splitting hairs. There's a huge difference between exposing a specific piece of data and allowing access to the entire address book. (Not to minimize the actual flaw, which does appear to be a problem in need of fixing.)

A more honest headline would likely have read something like:

Safari AutoFill flaw exposes personal info to hackers

That would be honest and still point to a significant issue.

8 posted on 07/23/2010 7:12:12 AM PDT by kevkrom (De-fund Obamacare in 2011, repeal in 2013!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: kevkrom
OK, I'll buy that.

Wonder if Steve Jobs' solution will be "Just start your name with a number"?

99Leroy

9 posted on 07/23/2010 7:18:43 AM PDT by Leroy S. Mort
[ Post Reply | Private Reply | To 8 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson