SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Stop using Safari for now: Microsoft

Stop using Safari for now: Microsoft

By:  Gregg Keizer  On: 01 Jun 2008 For: ComputerWorld (US) Creator

Microsoft Corp. has advised Windows users not to use Safari for Web browsing until either Apple or Microsoft releases a security patch. Apple has nothing to say for now.

In an unusual move, Microsoft Corp. on Friday urged Windows users not to surf with Apple Inc.'s Safari browser until one of the companies makes a patch that plugs security holes.

One security researcher noted that Microsoft's public warning -- and Apple's silence on the subject -- are typical for the two rivals and illustrate their different approaches to security.

On Friday, the Microsoft Security Response Center (MSRC) issued a security advisory for what it called a "blended threat" caused by combination of a bug in Apple's Safari Web browser and a vulnerability in how Windows XP and Windows Vista handle executable files placed on the desktop.

"Microsoft is investigating new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple's Safari for Windows has been installed," said the advisory.

The Safari bug Microsoft referred to is the same one disclosed two weeks ago by researcher Nitesh Dhanjani, which Apple declined to treat as a security issue, said Andrew Storms, director of security operations at nCircle Network Security Inc. "Clearly, that's what they're talking about," said Storms.

In mid-May, Dhanjani posted information about what he dubbed a "carpet bomb" attack made possible because Safari lacks an option to require a user's permission to download a file. Attackers, Dhanjani claimed, could populate a malicious site with rogue code that Safari would automatically download to the desktop.

Apple told Dhanjani that it did not consider the problem a security issue, but might fix it in a future Safari update. The next week, the anti-malware group Stopbadware.org criticized Apple for that position. "We encourage Apple to reconsider its stance and treat this as the security issue that it is," said the group in a statement May 19.

Then on Friday, Microsoft also fingered Safari as a problem. "Restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple," the company told users in the advisory.

But Microsoft also admitted that a successful attack would require not only leveraging the Safari bug, but also exploiting a vulnerability in its own software. "A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user's machine without prompting, allowing them to be executed," said Microsoft.


Sign up for our Newsletters
Tags: Windows, Storms












Print |  Views: 1548   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Gregg Keizer Gregg Keizer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Microsoft promises 12 patches next week
Microsoft promises 12 patches next weekOf the dozen updates it sketched out in the advance notification issued Thursday morning, the software giant pegged seven as "critical," its highest threat rating
Apple's Leopard has security holes, experts say
Apple's Leopard has security holes, experts sayThe company's latest operating system upgrade is expected to be a sales success, but some features designed to protect user data may not be implemented completely. What to watch out for
Disable Windows ActiveX control for safety, says Microsoft
Disable Windows ActiveX control for safety, says MicrosoftMicrosoft is investigating reports of a vulnerability in a Windows ActiveX control that could allow an attacker to remotely take control of a computer, according to an advisory. One security company rated the vulnerability critical, while Microsoft said it allowed only limited attacks.
CanSecWest PWN to OWN 2008
so this is a rather interesting story, which beautifully lends itself to sensational press and great article titles like “macbook air hacked in two minutes” and “vista falls, linux holds strong”. this frankly, is exactly why tippingpoint and cansec
Latest Safari release could be “easy pickings”
the winner of the 2008 pwn2own hacking contest has his sights set on apple inc.’s newest launched safari 4 beta. security researcher charlie miller, who took home $10,000 for hacki
blog comments powered by Disqus