Re: Apple Safari on MacOSX may reveal user's saved passwords

看板Bugtraq作者時間18年前 (2007/05/17 00:10), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/11 (看更多)
Injecting Javascript into a browser like this does *not* require that the attacker be on the local console. To run Applescript while logged inremotely using ssh, you can use the 'osascript' utility. It works for: the same user using ssh as is on the console; the root user using ssh (or someone who can sudo) can inject Javascript into the console user's browser; a different non-root user on the console can do it too That last one is particularly worrying, although I've not taken the time to figure out precisely what works and what doesn't. My test was to simply open a Terminal and 'su - foo' before using osascript, but it might, for instance, be exploitable by a setuid application. At first glance, Firefox doesn't seem to be vulnerable (although I'm far from being an Applescript expert) to exactly this attack, but it does expose at least *some* functionality to Applescript. -- David Cantrell
文章代碼(AID): #16IoqI00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 3 之 11 篇):
文章代碼(AID): #16IoqI00 (Bugtraq)