On CBS News: Tracking terror activity worldwide
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos, News.com
Posted on ZDNet News: Mar 22, 2005 1:18:00 AM

Apple Computer has released nearly a dozen fixes for flaws in its Mac OS operating system, including a script for preventing phishers from fooling users of its Safari browser.

The script, released Monday, tackles a pernicious phishing problem in browsers. The loophole could allow an attacker to use certain characters from different languages to create legitimate-looking Web addresses that actually send victims to malicious Web sites. The security problem affected all browsers that supported Internationalized Domain Names, or IDN, and is not Apple-specific.

Related feature
Have you been phished?
Check here to see whether an e-mail that appears to be from your bank or an online merchant is actually an attempt to defraud you.

"For example, the Cyrillic letter 'a' could be used in place of the Latin letter 'a,' making it difficult for a user to tell if they are at www.apple.com or a malicious imposter website that's designed to look like the real one," the company said in an advisory discussing the problem. "These sites can be used to collect account numbers, passwords and other personal information."

Other browsers affected by the IDN security issue include the Mozilla Foundation's Mozilla and Firefox, and Opera. Both Mozilla and Opera Software have issued fixes for the problem. Microsoft's Internet Explorer does not support IDN, so it is not vulnerable to such attacks. However, plug-ins that add IDN functionality to Internet Explorer do put it at risk.

The newly released patches take care of flaws in the Apple Filing Protocol server and the Samba filing-sharing server, as well as multiple issues with the Cyrus authentication software, Mailman, SquirrelMail and Cyrus mail software.

The patches can be downloaded from Apple's Web site or automatically installed via Apple's Software Update tool.

  • Talkback
  • Most Recent of 49 Talkback(s)
Excellent Point
It's interesting to see how the two zealots go about their camps. "Macs suck because they don't have a market share", and "Windows sucks because it's insecure". The real point is that each have thei... (Read the rest)
Posted by: FoxFord Posted on: 04/04/05 You are currently: Logged In | Log out
Only for OS X 10.3 Fred Fredrickson   | 03/21/05
RE: Only for OS X 10.3 thetargos   | 03/22/05
Dunno Fred Fredrickson   | 03/22/05
Hmm.. Didn't this vulnerabilty emerge timpin1@...   | 03/23/05
Phishing? Reverend MacFellow   | 03/22/05
Re: Phishing? clownside_down   | 03/22/05
Still would prefer a Maccy over a Windows box any day if.. Jeff Spicoli   | 03/22/05
But why? Qbt   | 03/22/05
Oh, really? BitTwiddler   | 03/22/05
Slow down there Peter Eater Jeff Spicoli   | 03/22/05
Too Late! ShadeTree   | 03/22/05
A popular girl you have there Petey... Zoraster   | 03/22/05
8.5 Linux User 147560   | 03/22/05
Do you actually BELIEVE what you just wrote? MacGeek2121   | 03/22/05
Actually I believe most Mac users will ... ShadeTree   | 03/22/05
experiencing onslaughts MTMacPhee   | 03/22/05
Duh Qbt   | 03/22/05
HA HA timpin1@...   | 03/23/05
RE: But why? richdave   | 03/22/05
You claimed that OSX is "JUST" as whole ridden as Laff   | 03/22/05
Re: But Why? GothicChessDotOrg   | 04/01/05
Of course you would.. vdraken   | 03/22/05
Still in your state of denial?(nt) ShadeTree   | 03/22/05
The only thing I've consistently denied.. Jeff Spicoli   | 03/22/05
Tsk, Tsk .... ShadeTree   | 03/22/05
Ya got me Jeff Spicoli   | 03/22/05
Easy target ShadeTree   | 03/22/05
Nope Jeff Spicoli   | 03/22/05
Please post your 'Mac OS is impervious' stories here (NT) relictele   | 03/22/05
Not sure... TheCrow_z   | 03/22/05
Check the Apple link PA-ITGuy   | 03/22/05
Bull! everyone knows only windows has flaws! TechType   | 03/22/05
Posters: 2 Strawman: 0 the_doge   | 03/22/05
Simply untrue NonZealot   | 03/22/05
I disagree voska   | 03/22/05
Of course you disagree and you are... ShadeTree   | 03/22/05
YEAH! Jeff Spicoli   | 03/22/05
It wasn't Microsoft engineers ... ShadeTree   | 03/22/05
WIN NT not Multi-User mrlinux   | 03/22/05
It certainly was multi-user NonZealot   | 03/22/05
WINDOW98 recognizes different users mrlinux   | 03/22/05
Did you bother to read my reply at all? NonZealot   | 03/22/05
Really? flatliner   | 03/22/05
I think the point is.... middle of nowhere   | 03/22/05
The real point is! ShadeTree   | 03/22/05
Excellent Point FoxFord   | 04/04/05
(GASP!!!) Mac OS? FLAWS??? OMG!!!! Thuss80   | 03/22/05
Journalistic excellence MTMacPhee   | 03/22/05
RE: Journalistic excellence richdave   | 03/22/05

What do you think?

advertisement
advertisement