OSX 10.3 [Panther] service announcement
May. 19th, 2004 01:25 am![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
Doubtless those of you to whom this applies have seen it already, but just in case you haven't, there's a security hole in Panther that wants patching.
"It is possible to write a URL that, when invoked from one’s default browser, invokes Apple’s Help program, which is itself a mini-browser which uses a subset of HTML. The trouble is that unlike a well-written, full-fledged, OSX browser, the Help program is (a.) fully scriptable; and (b.) fully capable of running any application or command for which the user has privileges."
"It is possible to write a URL that, when invoked from one’s default browser, invokes Apple’s Help program, which is itself a mini-browser which uses a subset of HTML. The trouble is that unlike a well-written, full-fledged, OSX browser, the Help program is (a.) fully scriptable; and (b.) fully capable of running any application or command for which the user has privileges."
no subject
Date: 2004-05-18 10:39 pm (UTC)no subject
Date: 2004-05-19 04:58 am (UTC)With Safari open and the foremost application, select "Preferences" from the "Safari" menu. Click the "General" icon, and make sure "Open 'safe' files after downloading" is unchecked. Boom, vulnerability gone.
no subject
Date: 2004-05-19 11:04 am (UTC)Well, I was...
Date: 2004-05-19 11:42 am (UTC)So I just downloaded the More Internet freeware control panel from versiontracker.com, and set the handler for "help" documents to my Chess program. Not a perfect solution, but it'll keep me safe until the hole is patched.
no subject
Date: 2004-05-19 07:40 am (UTC)Jonathan
no subject
Date: 2004-05-19 11:43 am (UTC)no subject
Date: 2004-05-19 12:04 pm (UTC)