Home Microsoft warns of Safari for windows blended threat

Live Assistant

Welcome to Omigaman Live Assistant.

live chat

Do you have any questions about our Business Management Software?

Name:
Microsoft warns of Safari for windows blended threat PDF Print E-mail
Written by Administrator   
Tuesday, 03 June 2008 00:00

Microsoft has issued an advisory warning for Windows users who have installed Apple’s Safari for Windows browser that their systems may be susceptible to attack.

The Vulnerability was first reported last month by Nitesh Dhanjani and later dismissed by Apple as not to be a security threat.

Robert Vamosi says in his cnet.com blog

“The Safari "carpet bombing" attack was first described by Nitesh Dhanjani last month, but dismissed by Apple as a serious threat. Under Dhanjani's scenario, a user would surf using Apple Safari for Windows to a maliciously crafted Web site such as http://malicious.example.com/. Dhanjani says Safari does not know how to render content-type of blah/blah, so it starts downloading carpet_bomb.cgi, executing the downloaded files with the same rights as the logged-on user. The end result is the victim's desktop is populated with a variety of malicious files.”

Microsoft says that the threat is

“A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed. Safari is available as a stand-alone install or through the Apple Software Update application.”


“An attacker could trick users into visiting a specially crafted Web site that could download content to a user’s machine and execute the content locally using the same permissions as the logged-on user.”

Microsoft suggests in its advisory that Windows users who have installed Apple Safari should restrict the use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple.

Microsoft have put forward the following workaround for users who wish to continue using the Safari browser.

Change the download location of content in Safari to a location other than ‘Desktop’

Launch Safari. Under the Edit menu select Preferences.

At the option where it states Save Downloaded Files to:, select a different location on the local drive.

 

Where to next?

Omigaman Ltd Business Software as a Service Home

Back to the home page
Take me back to the beginning of the Omigaman website

Omigaman Ltd Business Software as a Service about us

Find out more about Omigaman Ltd
We are driven by our passion to create innovative applications through technology. Come and find out more about us

 
Omigaman Ltd Business Software as a Service about tactic

Scalable business software solutions
Omigaman seeks to understand its clients rather then just respond to them. Click here to find out how TacTic can meet your needs

Omigaman Ltd Business Software as a Service industry news

Industry news and events
click here to read the latest industry news and events

 
Omigaman Ltd Business Software as a Service demo video

Request a Live Demo Tour
Our live demo team are available to give you a guided tour of TacTic and discuss how our software can meet your requirements. Click here to request a Live Demo

Omigaman Ltd Business Software as a Service screen shots

One picture is worth ten thousand words
Click here to view a collection of screen shots of TacTic applications

 
Omigaman Ltd Business Software as a Service free tactic trial

Try TacTic Free For 30 Days
Click here to test Drive our software before you buy it

   
Last Updated ( Friday, 04 July 2008 14:46 )
 
 

Evolution of Business Software as a Service

In the old days, you bought the software licenses, installed the applications on your computers (or server), paid a great deal for the maintenance contract, incurred variable support costs and suffered through a seemingly perpetual cycle of time-consuming, productivity-killing, money-devouring upgrades.

Omigaman’s modern way: you pay a monthly fee for the business application and we maintain everything (the application, the database, the hardware, backups, security, support and business continuance). Best of all, you will access it all via the Internet.

Read More...