ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Apple patches Safari phishing flaw

Published: 22 Mar 2005 09:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple has released nearly a dozen fixes for flaws in its Mac OS operating system, including a script for preventing phishers from fooling users of its Safari browser.

The script, released Monday, tackles a pernicious phishing problem in browsers. The loophole could allow an attacker to use certain characters from different languages to create legitimate-looking Web addresses that actually send victims to malicious Web sites. The security problem affected all browsers that supported Internationalised Domain Names, or IDN, and is not Apple-specific.

"For example, the Cyrillic letter 'a' could be used in place of the Latin letter 'a,' making it difficult for a user to tell if they are at www.apple.com or a malicious imposter website that's designed to look like the real one," the company said in an advisory discussing the problem. "These sites can be used to collect account numbers, passwords and other personal information."

Other browsers affected by the IDN security issue include the Mozilla Foundation's Mozilla and Firefox, and Opera. Both Mozilla and Opera Software have issued fixes for the problem. Microsoft's Internet Explorer does not support IDN, so it is not vulnerable to such attacks. However, plug-ins that add IDN functionality to Internet Explorer do put it at risk.

The newly released patches take care of flaws in the Apple Filing Protocol server and the Samba filing-sharing server, as well as multiple issues with the Cyrus authentication software, Mailman, SquirrelMail and Cyrus mail software.

The patches can be downloaded from Apple's Web site or automatically installed via Apple's Software Update tool.

Apple has moved to a regular release schedule, publishing fixes every month. The first major company to embrace a monthly patch process was Microsoft, and database maker Oracle has also moved to regular releases, but on a quarterly basis.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
53 out of 130 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Systems Support Analyst

Novell NetWare, Linux, and Apple Mac OS - Experience of remote computer systems management Desirable Requirements Include: - Knowledge of Novell ...

Senior Software Engineer

To apply, please email your CV and covering letter, quoting ref: SC08/ITJB, to Nicola Anderson, European Recruiter, at: recruitment@accelrys.com ...

Core VOIP Analyst / VOIP / Avaya / Cambridge

Please send your CV, along with a brief email (Covering letter) on why this is the right opportunity for you, along with your current salary and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Open Source: A Torrent of Impli...

Mobile Open Source: A Torrent of Implication Author: Eric Everson, Founder MyMobiSafe.com There is a change working its way through the wireless industry that is fraught with the... More

Post a comment

WinMo Handsets Get Facebook: Shhh Don’...

WinMo Handsets Get Facebook: Shhh Don’t Tell Your Boss! Eric Everson, Founder MyMobiSafe.com For those whose lives have come to revolve around their social networking it would seem... More

Post a comment

Nokia and Open Source Symbian

Nokia and Open Source Symbian By: Eric Everson, Founder MyMobiSafe.com So Nokia picked up the exclusive rights to the Symbian OS recently at a relative bargain (considering the... More

Post a comment