The Mac Observer

Skip navigational links

Featured Article: Hidden Dimensions - Another Christmas Arrives, Same Old Apple TV

Mac Security Alert - Exploit May Cause Safari To Toss Its Cookies

by , 1:00 PM EST, November 26th, 2003

The information technology security company, Secunia, has released an advisory about a vulnerability in Safari, Apple's Web browser. The exploit can be used remotely to trick the browser into sending a user's private cookie information for a website. Cookies are bits of information stored on a person's computer that are pertinent to that specific person. Their main purpose is to identify visitors so a certain Web site can be customized for them. From the Secunia advisory page:

A vulnerability has been reported in Apple Safari, which can be exploited by malicious people to steal a user's cookies. The vulnerability is caused due to an error when handling URLs. This can be exploited to disclose a user's cookie information for an arbitrary website by including a NULL character ("%00") in the URL. The vulnerability has been reported in versions 1.0 (v85) through 1.1 (v100.1).

The vulnerability carries a threat level of 4 on a scale of 1-5. That level is characterized by the existence of easy to exploit flaws, no solutions being available, no public awareness or workarounds requiring high technical skills, and the exploit being out "in the wild."

Secunia suggests using another browser to avoid being exposed to the security hazard.

Observer Comments

Show: Subjects Only | Full Comments
Comment on this Article

Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Friday, November 21st, 2008

Fri., 7:15 PM
iPO Free on iTunes - Photography Specials
6:35 PM
Khronos Group Shows Off OpenCL Standard
5:15 PM
John Martellaro's Blog: StrangeCharm - HD, DRM & iTunes
4:30 PM
iPO iPhone Gaming News - EA Reveals Plans For SimCity on iPhone
4:00 PM
Psystar Lawsuit Filings Reveal Potential Document Policy Problems at Apple
2:40 PM
Mac Gaming News - Puzzle Adventure Game Book of Legends Comes to the Mac
2:20 PM
TMO's DealsOnTheWeb.com - Philips 8.5" Widescreen Portable DVD Player With iPod Dock: $129.99 Delivered
12:05 PM
The Simplified Guide to Buying a New HDTV System
10:20 AM
PopChar X 4.1.1 Improves FreeHand 10 Support
9:35 AM
iPodObserver - Apple Rolls out iPod touch Software 2.2 with Podcast Downloads
8:55 AM
New Mac Malware Surfaces
8:35 AM
Apple Releases Pro Applications Update 2008-004
8:00 AM
iPO Review - Clusterball Arcade
7:35 AM
iPodObserver - iTunes 8.0.2 Improves VoiceOver, More
6:55 AM
iPodObserver - iPhone Software 2.2 Adds Google Street View, Podcast Downloads
 

The Mac Observer Reader Specials

  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Macworld Expo - Hotel Deal
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!

Apple Stock Quote

  • AAPL: $82.58. Change Today: +2.09.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb