Bugtraq mailing list archives
Re: Apple Safari on MacOSX may reveal user's saved passwords
From: David Cantrell <d.cantrell () outcometechnologies com>
Date: Tue, 15 May 2007 23:15:26 +0100
Injecting Javascript into a browser like this does *not* require that the attacker be on the local console. To run Applescript while logged inremotely using ssh, you can use the 'osascript' utility.
It works for: the same user using ssh as is on the console; the root user using ssh (or someone who can sudo) can inject Javascript into the console user's browser; a different non-root user on the console can do it tooThat last one is particularly worrying, although I've not taken the time to figure out precisely what works and what doesn't. My test was to simply open a Terminal and 'su - foo' before using osascript, but it might, for instance, be exploitable by a setuid application.
At first glance, Firefox doesn't seem to be vulnerable (although I'm far from being an Applescript expert) to exactly this attack, but it does expose at least *some* functionality to Applescript.
-- David Cantrell
Current thread:
- Apple Safari on MacOSX may reveal user's saved passwords poplix (May 14)
- RE: Apple Safari on MacOSX may reveal user's saved passwords Lucas, Mark J. (May 14)
- Re: Apple Safari on MacOSX may reveal user's saved passwords stephen joseph butler (May 16)
- <Possible follow-ups>
- RE: Apple Safari on MacOSX may reveal user's saved passwords mailbox () martinelli com (May 14)
- RE: Apple Safari on MacOSX may reveal user's saved passwords samelinux (May 15)
- Re: RE: Apple Safari on MacOSX may reveal user's saved passwords poplix (May 15)
- Re: Apple Safari on MacOSX may reveal user's saved passwords David Cantrell (May 16)
- Re: Apple Safari on MacOSX may reveal user's saved passwords graham . coles (May 16)
- Re: Apple Safari on MacOSX may reveal user's saved passwords Ian Ward Comfort (May 16)
- Re: Apple Safari on MacOSX may reveal user's saved passwords David Cantrell (May 17)
- Re: Apple Safari on MacOSX may reveal user's saved passwords graham . coles (May 17)
- Re: Apple Safari on MacOSX may reveal user's saved passwords poplix (May 18)
- Re: Apple Safari on MacOSX may reveal user's saved passwords Kevin Finisterre (lists) (May 18)
- Re: Apple Safari on MacOSX may reveal user's saved passwords poplix (May 19)
- Re: Apple Safari on MacOSX may reveal user's saved passwords David Cantrell (May 16)
- RE: Apple Safari on MacOSX may reveal user's saved passwords Lucas, Mark J. (May 14)
- Re: Apple Safari on MacOSX may reveal user's saved passwords Mark Senior (May 17)