MacOS X 10.3 security chasm
PSA courtesy
jazzfish:
It seems OSX 10.3 [Panther] has a simple, easily-fixed, and gaping security hole.
"It is possible to write a URL that, when invoked from one’s default browser, invokes Apple’s Help program, which is itself a mini-browser which uses a subset of HTML. The trouble is that unlike a well-written, full-fledged, OSX browser, the Help program is (a.) fully scriptable; and (b.) fully capable of running any application or command for which the user has privileges."
Watched Gilmore Girls season finale. Action-packed!
![[livejournal.com profile]](https://www.dreamwidth.org/img/external/lj-userinfo.gif)
It seems OSX 10.3 [Panther] has a simple, easily-fixed, and gaping security hole.
"It is possible to write a URL that, when invoked from one’s default browser, invokes Apple’s Help program, which is itself a mini-browser which uses a subset of HTML. The trouble is that unlike a well-written, full-fledged, OSX browser, the Help program is (a.) fully scriptable; and (b.) fully capable of running any application or command for which the user has privileges."
Watched Gilmore Girls season finale. Action-packed!
no subject
no subject
I hope Lorelai sics someone vicious on Dean.
no subject
no subject
no subject
Man, I never thought Jess would look so good as a prospect for a good, solid relationship.
no subject
no subject
no subject