You are Unregistered, please register to gain Full access.    

Go Back   SiNfuL iPhone > News > News > General News

Notices

Reply
Thread Tools

 Turn Off Your Safari AutoFill, a Nasty Exploit Could Steal Your Address Book
Unread 07-22-2010, 11:11 AM   #1
VortexUser
Obsessive iPhone Disorder
 
VortexUser's Avatar
 
VortexUser is offline
Join Date: Jan 2010
Device: iPhone 4
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: AT&T
OS: Mac OS X
Location: PA
Posts: 481
Thanks: 68
Thanked 620 Times in 102 Posts
Icon4 Turn Off Your Safari AutoFill, a Nasty Exploit Could Steal Your Address Book

Via Gizmodo


The web's full of vulnerabilities, but this exploit, which allows code to quietly yank your Mac's Address Book with Safari's AutoFill, seems bad enough that you should probably just stop what you're doing and disable AutoFill, just to be safe.

9to5Mac is bringing attention to the exploit, which was exposed and covered in detail by Jeremiah Grossman:

These fields are AutoFill'ed using data from the users personal record in the local operating system address book. Again it is important to emphasize this feature works even though a user never entered this data on any website. Also this behavior should not be confused with normal auto-complete data a Web browser may remember after its typed into a form.

All a malicious website would have to do to surreptitiously extract Address Book card data from Safari is dynamically create form text fields with the aforementioned names, probably invisibly, and then simulate A-Z keystroke events using JavaScript. When data is populated, that is AutoFill'ed, it can be accessed and sent to the attacker.

As shown in the proof-of-concept code (graciously hosted by Robert "RSnake" Hansen), the entire process takes mere seconds and represents a major breach in online privacy. This attack could be further leveraged in multistage attacks including email spam, (spear) phishing, stalking, and even blackmail if a user is de-anonymized while visiting objectionable online material.




more info Via 9to5Mac

Websites can now steal your Safari browser autofill information including Name, Address, Email, Credit Card etc. without a mention using a very simple exploit detailled by Jeremiah Grossman.
If you want to see how it works, check out this page in Safari with your autofill on (note you could be giving up that informaton to that website and any others you go to with that on).

Very scary. Even more scary? This vulnerability has been known about for a year...and it could have been embedded into online advertising on an otherwise normal website. Older versions of IE (6 and 7) are also susceptible according to the Register.

Grossman informed Apple about the exploit over a month ago but hasn't received a response.

I figured Apple might appreciate a vulnerability disclosure prior to public discussion, which I did on June 17, 2010 complete with technical detail. A gleeful auto-response came shortly after, to which I replied asking if Apple was already aware of the issue. I received no response after that, human or robot. I have no idea when or if Apple plans to fix the issue, or even if they are aware, but thankfully Safari users only need to disable AutoFill web forms to protect themselves.

As this is now officially in the wild, either switch off autofill or switch to another browser until it is fixed.




Follow me on.... FaceBook | Twitter | Aim:Pwnmetheus | Skype:Pwnmetheus



hit that Mutha Fukin thanks button
  Reply With Quote
The Following 2 Users Say Thank You to VortexUser For This Useful Post:
just1n (07-28-2010), keeyo (07-28-2010)

 
Unread 07-22-2010, 11:28 AM   #2
Clatchy
iPhoneaholic
 
Clatchy's Avatar
 
Clatchy is offline
Join Date: Apr 2010
Device: iPad
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: Other
OS: Mac OS X
Location: England - Middlesbrough
Posts: 149
Thanks: 212
Thanked 23 Times in 15 Posts
Why I use Google Chrome.

Need help with anything, dont hesitate to drop me a message.
  Reply With Quote

 
Unread 07-22-2010, 11:32 AM   #3
VortexUser
Obsessive iPhone Disorder
 
VortexUser's Avatar
 
VortexUser is offline
Join Date: Jan 2010
Device: iPhone 4
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: AT&T
OS: Mac OS X
Location: PA
Posts: 481
Thanks: 68
Thanked 620 Times in 102 Posts
this is for those that use Safari. i do not know if Chrome has the same similar exploit.




Follow me on.... FaceBook | Twitter | Aim:Pwnmetheus | Skype:Pwnmetheus



hit that Mutha Fukin thanks button
  Reply With Quote

 
Unread 07-22-2010, 11:44 AM   #4
psychozev69
Obsessive iPhone Disorder
 
psychozev69's Avatar
 
psychozev69 is offline
Join Date: Feb 2010
Device: iPhone 3G
iOS Version: 3.1.2
iTunes Version: iTunes 9
Carrier: AT&T
OS: Windows 7
Location: TN
Posts: 316
Thanks: 297
Thanked 201 Times in 69 Posts
well, I have always used IE, and it may be slower than all the other options, but has better security than the others. If you know what you are doing and how to set it up properly, then it will protect you from the average exploits. No one is ever 100% secure.

Quote:
Benjamin Franklin:
People willing to trade their freedom for temporary security deserve neither and will lose both.
  • OS: Windows 7 Ultimate/32bit
  • Motherboard: Asus P5B-Deluxe+WiFi
  • CPU: Intelฎ Core 2 Duo E6400/Conroe-2M(50% Overclock@3.20GHz)
  • RAM: (4)Corsair XMS2/(2)1Gb+(2)512MB DDR2(50% Overclock/4-4-4-12@400MHz)
  • HDD: (2)WDC WD2500KS SATA/Total=464GB@7,200rpm
  • Video: NVIDIA GeForce GTS 250 (512Mb)






Click it if I helped.

  Reply With Quote

 
Unread 07-28-2010, 05:32 AM   #5
just1n
n00b
 
just1n is offline
Join Date: Jul 2010
Device: iPhone 4
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: T-Mobile
OS: Windows 7
Location: Netherlands
Posts: 6
Thanks: 6
Thanked 0 Times in 0 Posts
whoa thank you. I personally uses Firefox but my dad is fond of Safari. Better tell him about this before it's too late if it isn't already
  Reply With Quote

 
Unread 07-28-2010, 07:32 AM   #6
VortexUser
Obsessive iPhone Disorder
 
VortexUser's Avatar
 
VortexUser is offline
Join Date: Jan 2010
Device: iPhone 4
iOS Version: 4.2
iTunes Version: iTunes 10
Carrier: AT&T
OS: Mac OS X
Location: PA
Posts: 481
Thanks: 68
Thanked 620 Times in 102 Posts
no problem hope he dosnt get cought up in that




Follow me on.... FaceBook | Twitter | Aim:Pwnmetheus | Skype:Pwnmetheus



hit that Mutha Fukin thanks button
  Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On




All times are GMT -7. The time now is 06:04 PM.

Copyright ฉ 2009 ––––•(SiNfulSS)•–––- Shot Caller @ SiNfuL iPhone