| May 2004 | ||||||
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
| 1 | ||||||
| 2 | 3 | 4 | 5 | 6 | 7 | 8 |
| 9 | 10 | 11 | 12 | 13 | 14 | 15 |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 | 25 | 26 | 27 | 28 | 29 |
| 30 | 31 | |||||
| Apr Jun | ||||||
You can read about it on Jay Allen’s site (which is where I heard about it). Essentially, Mac browsers (including Safari, Mozilla, and Firefox) are all designed to launch the Help Viewer program when the help: protocol is invoked in a web link. Unfortunately, the Help Viewer program, in turn, is able to run scripts. What this means is that a malicious user can set up a page with an automatic redirect that runs a dangerous script. More details for the tech-minded can be found on this MacNN thread. And if you want a terrifying (but harmless) example of this, go to http://bronosky.com/pub/AppleScript.htm. It will launch Terminal and run a harmless du command—but it’s scary as hell to see that Terminal window launch and files start scrolling. (There’s also an advisory on the Secunia site, but it offers no helpful suggestions; just verifies the seriousness of the problem.)
If, like me, you just want to know how to fix this fast (since Apple has apparently known about this since February and hasn’t fixed it, it wouldn’t be wise to wait for their patch), here’s the approach to use.
- Download the freeware tool MoreInternet.
- From the disk image, run “install prefpane,” which will put the MoreInternet preference panel into your System Preferences panel.
- Open the MoreInternet panel, and select the help: protocol.
- Change the application it launches from the Help Viewer (which has the script-running vulnerability) to something benign.
(I used TextEdit.)I used Chess, which, unlike TextEdit, gives me a clear visual cue that a page tried to invoke the help: protocol. - Make sure it worked by going to the scary but harmless example.
Update: In my comments, Jay Allen points out that you should repeat steps 3 and 4 for the disk: protocol, as well.[mamamusings]
'Nuff Said.
It appears that this is Panther-specific
8:01:10 PM
Discuss: []
Scientists endorse Atkins diet
A low carbohydrate, high protein Atkins style diet is the best way to lose the most weight, according to US scientists. [BBC News]
So, all my life, people have been asking me if I had a fast/high metabolism, and I shoulda just told them I was an Atkins early adopter. :)
2:39:27 PM