• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: disk:// and help:// security problems
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: disk:// and help:// security problems


  • Subject: Re: disk:// and help:// security problems
  • From: Charles Srstka <email@hidden>
  • Date: Sun, 23 May 2004 13:16:25 -0500

On May 23, 2004, at 7:45 AM, Izidor Jerebic wrote:

Well, the above is not all...
The URI schemes mixed with LaunchServices is *extremely* dangerous. See:

<http://daringfireball.net/2004/05/unsafe_uri_handlers>

and especially

<http://www.unsanity.com/haxies/pa/whitepaper>

Not only that, it's also possible to create an app with a creator code of 'GFTM' and set it up to recognize the tn3270: protocol. Since the default settings already specify an app with creator code 'GFTM' as the helper app for tn3270:, this exploit could conceivably still work even if Apple fixed the problem of LaunchServices automatically registering protocols for helper apps.

Charles
_______________________________________________
cocoa-dev mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/cocoa-dev
Do not post admin requests to the list. They will be ignored.


References: 
 >disk:// and help:// security problems (From: "Michael Rothwell" <email@hidden>)
 >Re: disk:// and help:// security problems (From: Michael Rothwell <email@hidden>)
 >Re: disk:// and help:// security problems (From: Charles Srstka <email@hidden>)
 >Re: disk:// and help:// security problems (From: Chilton Webb <email@hidden>)
 >Re: disk:// and help:// security problems (From: Charles Srstka <email@hidden>)
 >Re: disk:// and help:// security problems (From: Izidor Jerebic <email@hidden>)

  • Prev by Date: [Moderator] Re: OT: An idea for Apple, and Developers
  • Next by Date: Re: accessing binding values
  • Previous by thread: Re: disk:// and help:// security problems
  • Next by thread: Re: disk:// and help:// security problems
  • Index(es):
    • Date
    • Thread