On CBS MoneyWatch: Which Credit Cards are Best?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Jo Best
Posted on ZDNet News: May 10, 2005 12:20:00 AM

Dashboard, one of the much-publicized features of Apple Computer's latest OS, Tiger, could be ripe for exploitation by porn scammers.

Apple has been encouraging developers to create new widgets for Tiger's Dashboard--a semi-transparent layer of everyday, often-used applications such as a calculator or currency converter that appears over the user's desktop--but within days of its public release, one developer claims to have already found a way to turn widgets into potential malicious software.

Developer Stephan, who has posted the widgets to his blog, has created two mini-apps which he describes as "slightly evil." One widget, he says, will automatically install itself on users' desktops when his "Zaptastic" Web site is visited using Apple's Safari browser.

This, according to Stephan, is a golden opportunity for porn scammers, enabling them to auto-install widgets that can hijack browsers.

According to Stephan's blog: "I happen to like (auto-install). I think it's a great thing. But, as I have demonstrated here, it has the side effect of setting up a situation where a user can be given an application without their knowledge.

"That's not such a big deal; by default, widgets can't do much damage, and they can't run unless you drop them into your dashboard. The funny thing is that once that widget is there, according to Apple, you CANNOT remove it."

Widgets cannot be removed directly from the toolbar, but they can however be deleted from the Library folder.

"The average user, who can't find their Library folder with two mice and a spotlight, is stuck. It would take all of 30 seconds for me to pick out a nice porn image, make it the icon of a widget, drop it in your dashboard and you're stuck with it. It doesn't even need any Javascript," Stephan added.

Stephan has also created the zaptastic_evil widget, which redirects the user's browser to a Web site every time the widget Dashboard is launched--and drops the user out of Dashboard, preventing the widget from being closed.

A fellow blogger, going by the name of Aaron, has created a series of widgets that closely resemble Apple's own set of widgets and can be used to displace the genuine ones. One of these fake widgets can run with full system access without the user's express permission.

Apple declined to comment for this report.

Despite the potential for mayhem, Mac users can simply kill the widgets by deleting them from their Library folder, and using Activity Monitor to kill any instance of the widget already running.

Jo Best of Silicon.com reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 61 Talkback(s)
Ummm....
okay....but Jim...and others below..I have no love(or hate) for any OS. I'm not a big fan of Jobs nor am I big fan of Gates. If it were MS(or anyone else) I'd say the same. I was just commenting on th... (Read the rest)
Posted by: IT Scion Posted on: 05/12/05 You are currently: a Guest | | Terms of Use
Apple declined to comment for this report.  nikoli | 05/09/05
Probably too busy  Ken_z | 05/09/05
Safari Prefs  hellkitten | 05/10/05
Easy Fix  tic swayback | 05/10/05
Ouch  IT Scion | 05/09/05
How so? I myself never claimed Apple or OSX was PERFECT!  Laff | 05/10/05
The WinMonkeys will fight for their Fisher Price GUI til the earth IMPLODES  Jeff Spicoli | 05/10/05
And the MacAsses  rsouza@... | 05/10/05
Why the hell are you even reading about Macs?...  YuridaMan | 05/10/05
re: Why...  Wolfie2K3 | 05/10/05
Ummm....  IT Scion | 05/12/05
Not much spin  openMind | 05/10/05
Just Like Email Viruses  nikoli | 05/10/05
Widgets=Active X  DarthRidiculous | 05/09/05
Not quite  Fred Fredrickson | 05/10/05
It's not auto-intsall  openMind | 05/10/05
Are you using a browser?  Len Rooney | 05/09/05
Apparently you do not read so well!  ShadeTree | 05/10/05
Ask Yourself Something  Harry Bardal | 05/10/05
Must of hit a nerve with you.  ShadeTree | 05/10/05
Don't Chicken Out  Harry Bardal | 05/10/05
Why do I have to pick a side.  ShadeTree | 05/10/05
There It Is  Harry Bardal | 05/10/05
Twist it any way you want!  ShadeTree | 05/10/05
Butt Shade how do you know that OSX had NEVER been  Laff | 05/10/05
There it is Again!  Harry Bardal | 05/10/05
Well since you trotted out ...  ShadeTree | 05/10/05
Backup  Harry Bardal | 05/10/05
RE: Backup  ShadeTree | 05/10/05
Old Stuff  Harry Bardal | 05/10/05
RE: Old Stuff  ShadeTree | 05/10/05
Arrogance?  Harry Bardal | 05/10/05
RE: Arrogance  ShadeTree | 05/10/05
More recent study supports Mac's advantage...  MacCanuck | 05/11/05
Link to Aussie police...  MacCanuck | 05/11/05
Help! help! a Mac Wigdet has got me!  Len Rooney | 05/10/05
Apparently you believe everything you read  openMind | 05/10/05
I don't believe I stated that I believed the article ...  ShadeTree | 05/10/05
Apparently you do not research so well  Len Rooney | 05/10/05
Your problem is with the article and not me.  ShadeTree | 05/10/05
Not acceptable  Richard Flude | 05/09/05
Did Mythbusters write today's ZDNet news?  Scrat | 05/10/05
Nah  Jeff Spicoli | 05/10/05
You can multiply those two by 100...  BitTwiddler | 05/10/05
That's the part they never throw in..  Jeff Spicoli | 05/10/05
True, but report them anyway  FilledOut | 05/10/05
Wow, don't you just love computing  FilledOut | 05/10/05
MS Trolls getting desperate!  Reverend MacFellow | 05/10/05
The WinMonkeys are pounding their coconuts!!  Jeff Spicoli | 05/10/05
Awww.Whats wrong?  vdraken | 05/10/05
You're forgetting something Victor  Jeff Spicoli | 05/10/05
Chill Sean Penn  FilledOut | 05/10/05
Ahh, go play with Longhorn. Besides, hy are you even reading a Mac article?  YuridaMan | 05/10/05
This story is NOT about nothing  alterego_z | 05/10/05
I Don't Care.  Anon_ymous | 05/10/05
Yada, yada...  gfeier | 05/10/05
None did, ?  jacrav | 05/10/05
How can you have....  dsentman@... | 05/12/05
Let face it  mabricen | 05/10/05
INCORRECT INFORMATION  TheCrow_z | 05/10/05
Quality of Talkback...  dsentman@... | 05/12/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here